We are engaged with a market leader who are investing Millions into a large scale transformation across Cyber Security. As part of their growth and renewed strategy, they have an opening for a platform engineer to come and own, manage and further build out their SIEM tool, Palo Alto Cortex XSIAM.
This role is for the engineers who would rather build and own the platform than sit on the alert queue. The mandate here is do it once, do it right.
To be clear, this is not a SOC role. You will not be triaging alerts or running incidents. You will be making sure the platform itself is doing its job.
What the role looks like:
- Owning a modern SIEM and SOAR platform (Cortex XSIAM) across cloud and on premise components
- Onboarding new log sources and making sure data is parsed, normalised and modelled correctly
- Building custom parsers and normalisation packs for applications that do not come with them out of the box, using existing pipelines and an SDK
- Keeping integrations and platform components healthy, current and well documented
- Working through requests from Cyber Defence, Threat Intel and other teams, from build through to sign off
- Helping answer questions like "is this application fully covered from a logging point of view?
What a good fit looks like:
- Solid hands on experience engineering and supporting an enterprise SIEM platform (Ideally XSIAM or similar)
- Experience with Cortex XSIAM is ideal; Google SecOps (Chronicle) or Microsoft Sentinel with real normalisation or parser work is equally worth a conversation
- A good understanding of how data normalisation works and why it matters for detection
- Comfortable with pipelines, APIs and some scripting; Python is a bonus
- A explicit preference for engineering and platform ownership over SOC analysis
- Managed service or consulting backgrounds are very welcome, as long as you have delivered platform work end to end
Why this role:
- A genuinely new function, built with senior engineers and a hands on leader who is hiring strong talent
- A flat team structure and a real say in how the platform is run
- Adaptable hybrid; three days in the office, and you choose which three
- Joining at the start of a significant internal refresh, with investment behind it
If you have been doing this kind of work and want to own a platform properly, we would love to hear from you. Apply here or reach out to Craig directly at
[email protected] for a confidential chat.
📌 Senior Platform Security Engineer (SIEM) (Sydney)
🏢 The Decipher Bureau
📍 Sydney