30 Sep
|
Secure Agility
|
Sydney
30 Sep
Secure Agility
Sydney
About Secure Agility
Secure Agility is an Australian technology services and cybersecurity provider delivering managed security, cloud, infrastructure, networking and digital services to enterprise and government customers.
Our cybersecurity capability spans:
- Managed Detection & Response
- Security Operations
- CrowdStrike Falcon
- Detection Engineering
- Vulnerability Management
- Identity Security
- SSE and SASE
- Penetration Testing
We operate across complex customer environments and are continuing to invest heavily in our managed security and SOC capability.
Job Summary
Senior hands-on Security Operations Lead responsible for detection engineering, CrowdStrike Falcon, Next-Gen SIEM, threat exposure management and technical leadership across enterprise and government customers.
The Chance
We are looking for a senior Security Operations Lead who can combine deep technical security operations experience with customer-facing consulting capability.
This is not a traditional SOC Manager position where you step away from the technology.
You will remain hands-on while taking technical ownership of how we detect threats, engineer security content, automate response, identify exposure and communicate risk to customers.
You will help set the technical standard for our SOC and act as an escalation point for analysts and customers.
The ideal candidate is likely to have built their career within a global Systems Integrator, MSSP, MDR provider, MSP, cybersecurity consultancy or large enterprise SOC.
You will
- Develop, test and improve detection use cases and content.
- Improve detection coverage,
signal quality and false-positive management.
- Lead complex investigations and support threat-hunting activities.
- Develop automation using Falcon Fusion, SOAR and platform integrations.
- Help customers prioritise vulnerabilities and exposures based on genuine business risk.
- Mentor SOC analysts and improve investigation standards and playbooks.
- Lead technical workshops and security operations reviews.
- Present technical findings and risk recommendations to senior stakeholders, including CIOs and CISOs.
- Help shape our approach to emerging security risks, including AI-related exposure.
What you’ll bring
You will typically have six or more years’ experience across security operations, detection engineering, threat hunting, incident response or related cyber defence disciplines, including experience at a senior, L3, lead or principal level.
You will also bring:
- Strong practical experience with SIEM, EDR/XDR and detection engineering.
- Experience developing and tuning detections—not simply responding to alerts.
- Robust incident investigation and threat-hunting capability.
- Experience translating vulnerability and exposure data into clear remediation priorities.
- Confidence working directly with customers and senior stakeholders.
- Strong written communication, consulting and report-writing skills.
- The ability to explain complex security issues clearly to technical and non-technical audiences.
Experience within an MSSP, MDR provider, systems integrator, MSP, cybersecurity consultancy or multi-customer SOC will be highly regarded.
Strong practical experience with CrowdStrike Falcon, particularly Falcon Next-Gen SIEM, EDR and Falcon Fusion, is important. CrowdStrike certifications such as CCFA, CCFR or CCSE will be highly regarded; however, certification support may be considered for exceptional candidates with strong practical experience.
Experience with technologies such as Netskope, ExtraHop, Proofpoint, Microsoft Sentinel, Splunk, Palo Alto Networks, Entra ID, AWS, Azure, SOAR, Python, PowerShell or API integrations will also be valued.
An Australian Government NV1 security clearance, or eligibility to obtain one, is highly regarded.
Why Join Secure Agility
- Remain hands-on while leading and mentoring others.
- Influence the future direction of our managed security capability.
- Work across complex enterprise and government environments.
- Build new detections, automation, processes and security services.
- Work closely with CrowdStrike and other strategic security vendors.
- Receive support for relevant technical development and certifications.
- Work directly with senior technical and business leaders.
#J-18808-Ljbffr
📌 Security Operations Lead (Sydney)
🏢 Secure Agility
📍 Sydney