02 Oct
|
Hatchit Studios
|
Canberra
02 Oct
Hatchit Studios
Canberra
Senior Cyber Threat Analyst / Threat Detection Engineer – Splunk
Location: Canberra / Interstate candidates considered – Hybrid or remote arrangements subject to approval
Hours: Up to 40 hours per week
Security Requirement: Must be able to obtain Baseline Security Clearance
About the Opportunity
Hatchit Studios is seeking an experienced Senior Cyber Threat Analyst / Threat Detection Engineer for a long-term labour hire engagement within a Federal Government Security Operations Centre (SOC).
This is a hands-on threat detection engineering role focused on researching, developing, testing and maintaining detection use cases, rules and SIEM correlation logic across the SOC technology stack.
The environment primarily uses Splunk Cloud , with integrated SOAR capabilities, alongside Microsoft Sentinel for selected workloads and Microsoft Defender for Endpoint (MDE) for endpoint detection and response.
We are particularly interested in candidates with 5+ years' experience working within a cyber security operations centre and/or directly in threat detection engineering .
Key Responsibilities
- Develop threat detection use cases based on threat models, system risks, vulnerabilities, threat intelligence, incidents and industry frameworks
- Develop and maintain SIEM correlation logic, detection rules and detection content
- Develop detections across SIEM, SOAR and EDR technologies
- Develop playbooks for alert validation and support incident response automation
- Develop and maintain threat models using recognised methodologies such as STRIDE, MITRE ATT&CK; and attack path analysis
- Identify detection opportunities and monitoring coverage gaps
- Research and analyse emerging threats to develop new detection content
- Assess emerging risks associated with AI platforms, services and agents
- Develop detection content addressing AI-related misuse, data leakage, prompt injection, model abuse and adversarial activity
- Maintain threat intelligence integrations across the SOC technology stack
- Collaborate with Cyber Defence Analysts to test, tune and improve detection rules
- Assist with incident response and onboarding new security data sources
- Work with architecture and engineering teams to translate threat modelling outcomes into effective monitoring, detection and response capabilities
Skills & Experience Required
- 5+ years' experience in cyber security operations, SOC environments and/or threat detection engineering
- Strong hands-on experience developing SIEM detection rules, use cases and correlation logic
- Demonstrated detection engineering experience across at least two enterprise SIEM platforms , such as Splunk, Microsoft Sentinel, QRadar or Elastic
- Strong Splunk experience is highly regarded given the target environment
- Experience developing and implementing detections across SIEM, SOAR and EDR platforms
- Experience with incident response automation and security playbook development
- Practical threat modelling experience using STRIDE, PASTA, MITRE ATT&CK; or similar methodologies
- Robust understanding of the cyber threat intelligence lifecycle
- Experience identifying and developing monitoring controls for AI-related security risks , ideally involving Microsoft Copilot, Azure AI or similar enterprise AI platforms
- Strong communication, organisational and stakeholder engagement skills
Highly Desirable
- Experience with Splunk Cloud
- Experience with Microsoft Sentinel
- Experience with Microsoft Defender for Endpoint (MDE)
- Experience developing or using Sigma detection rules and translating detections between security platforms
- Familiarity with AI security frameworks and guidance including ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10
- Experience with enterprise EDR technologies such as CrowdStrike or Carbon Black
- Python and/or Bash scripting experience supporting detection engineering and security automation
- Relevant cyber security certifications such as GIAC, SANS, CISSP, GCIA, GCIH or equivalent
Why Apply?
- Initial 12-month contract with up to 24 months of extensions
- Work within an established Security Operations Centre
- Hands-on exposure to Splunk Cloud, Microsoft Sentinel and Microsoft Defender for Endpoint
- Work on contemporary detection engineering, threat intelligence and AI security challenges
- Hybrid working arrangements with interstate/remote candidates considered
#J-18808-Ljbffr
📌 Senior Threat Detection Engineer – Splunk / Sentinel / MDE (Canberra)
🏢 Hatchit Studios
📍 Canberra