Threat Detection Engineer — Enterprise-Scale Splunk (Sydney)

Threat Detection Engineer — Enterprise-Scale Splunk (Sydney)

20 Sep
|
Decipher Bureau
|
Sydney

20 Sep

Decipher Bureau

Sydney

Calling all Threat Detection & Response Engineers, if you are looking for a bigger playground, more complex threats and the chance to build detections at genuine enterprise scale, this one's worth a look.You'll be joining a global cyber defence team focused on engineering the detections that identify attacker behaviour across a large, complex enterprise environment.The core of the role is hands-on detection engineering: researching threats, developing detection logic, tuning existing content and improving coverage across endpoint, identity, cloud and network telemetry.What you'll be doingBuilding and tuning detections within Splunk Enterprise SecurityDeveloping SPL queries and improving detection fidelityThreat hunting across endpoint, identity, cloud and network telemetryInvestigating live incidents and turning findings into new or improved detectionsBuilding detection content using Git and YAMLWorking with detection-as-code and CI/CD pipelinesTesting detections against simulated attack activitySupporting the evolution from Splunk to a new platformCollaborating with threat intelligence, incident response and engineering teams globallyWhat we're looking forIdeally, you'll already be working within detection engineering,



threat detection or an advanced security operations environment.You'll bring:Robust Splunk and SPL experienceHands-on experience building and tuning security detectionsStrong understanding of MITRE ATT&CKExperience; investigating real-world security incidentsExposure to EDR, cloud, identity and network security telemetryUnderstanding of Git, YAML and version-controlled workflowsExperience with detection-as-code, CI/CD, SOAR, Python or security automation would be highly regarded.Most importantly, this role needs someone who understands both how attackers behave and how to engineer reliable detections to identify them.Why consider it?
Work on genuine detection engineering rather than alert monitoringBuild detections at enterprise scaleWork with Splunk while gaining exposure to new technologyDevelop detection-as-code and security automation experienceWork closely with threat intelligence, threat hunting and incident response specialistsThe role is Sydney-based with three days per week in the office.
Occasional weekend support may be required for major incidents or upgrades, with time in lieu provided.If you're already building rules, improving queries and looking for better ways to detect attacker behaviour, this is an prospect to make detection engineering the core of your role.
#J-*****-Ljbffr

📌 Threat Detection Engineer — Enterprise-Scale Splunk (Sydney)
🏢 Decipher Bureau
📍 Sydney

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: threat detection engineer — enterprise-scale splunk (sydney) / sydney