29 Sep
|
RiseMe
|
Canberra
Job Description
This is a remote position. n
Location: Canberra, Australian Capital Territory (ACT)
n
Security Clearance: Baseline Clearance
Threat Detection Engineering n
n
- SIEM use case development and detection content creation
n
- Detection rule development and tuning
n
- EDR detection engineering
n
- SOAR playbook development
n
- Alert validation processes
n
Threat Modelling nn
- STRIDE
n
- MITRE ATT&CK;
n
- Attack path analysis
n
- Detection coverage assessment
n
- Gap analysis
n
Threat Intelligence nn
- Threat intelligence integration and management
n
- Research into emerging threats
n
- Intelligence sharing across infrastructure and architecture teams
n
Security Operations nn
- SOC operations
n
- Incident response support
n
- Detection engineering lifecycle management
n
- Data source onboarding
n
- ITIL and Agile environments
n
AI Security (Important New Requirement) n
The RFQ specifically calls for experience in:
n
n
- AI threat modelling
n
- Prompt injection detection
n
- AI model abuse detection
n
- AI-related data leakage monitoring
n
- Adversarial AI activity detection
n
- Security monitoring of AI platforms, services and agents
n
n
A strong candidate would typically have:
n
n
- 5+ years in SOC, Detection Engineering, Threat Hunting, or Cyber Security Operations
n
- Hands-on experience with platforms such as:n n
- Microsoft Sentinel
n
- Microsoft Defender XDR
n
- Splunk
n
- QRadar
n
- CrowdStrike
n
- Palo Alto Cortex XDR
n
n
- Experience developing KQL, SPL, Sigma, YARA, or similar detection content
n
- Robust understanding of MITRE ATT&CK;
n
- Experience integrating threat intelligence feeds
n
- Good documentation and stakeholder engagement skills
n
Evaluation Themes to Address in a Submission n
When preparing a candidate response, focus on evidence demonstrating:
n
n
1. Development of threat detection use cases and rules.
n
2. SIEM/EDR content engineering and tuning.
n
3. Threat modelling expertise using STRIDE and ATT&CK.;
n
4. Threat intelligence integration and analysis.
n
5.
Experience supporting incident response activities.
n
6. Security monitoring of cloud and on-premises environments.
n
7. AI security and emerging threat detection capabilities.
n
8. Working within Agile and ITIL environments.
n
Requirements Essential criteria nn
- 1.Detection Engineering and SIEM Expertise - Demonstrated experience developing detection content across at least two enterprise SIEM platforms (e.g. Splunk, Microsoft Sentinel, QRadar, Elastic).
n
- 2.Threat Detection and Response Capability - Experience developing and implementing detections across SIEM, SOAR and EDR platforms, including incident response automation and playbook development.
n
- 3.Threat Modelling and Threat Intelligence - Practical experience conducting threat modelling using recognised methodologies (e.g. STRIDE, PASTA, ATT&CK;) and translating outcomes into detection and monitoring requirements, supported by a strong understanding of the cyber threat intelligence lifecycle.
n
- 4.AI Security Monitoring - Experience identifying, assessing and developing monitoring controls for AI-related security risks, including enterprise AI platforms such as Microsoft Copilot or Azure AI.
n
- 5.Cyber Security Operations Experience - Minimum five years' experience in cyber security operations, supported by strong organisational, communication and stakeholder engagement skills.
n
Desirable criteria nn
- 1.Sigma Rule Development - Experience developing or using Sigma detection rules and translating detections between security platforms.
n
- 2.Advanced AI Security Knowledge - Familiarity with AI security frameworks and guidance, including ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10. Relevant industry certifications such as GIAC, SANS, CISSP, GCIA, GCIH or equivalent cyber security qualifications.
n
- 3.EDR Platform Expertise - Experience with enterprise EDR technologies such as CrowdStrike, Microsoft Defender for Endpoint and Carbon Black.
n
- 4.Automation and Scripting - Proficiency in scripting languages such as Python and Bash to support detection engineering and security automation activities.
n
n
LH-07702
n
#J-18808-Ljbffr
📌 SOC Detection Specialist (Canberra)
🏢 RiseMe
📍 Canberra