03 Oct
|
Hatchit Studios
|
Canberra
03 Oct
Hatchit Studios
Canberra
Job Description
Senior Cyber Threat Analyst / Threat Detection Engineer – Splunk n
Location:
Canberra / Interstate candidates considered – Hybrid or remote arrangements subject to approval
n
Hours:
Up to 40 hours per week
n
Security Requirement:
Must be able to obtain Baseline Security Clearance
About the Opportunity n
Hatchit Studios is seeking an experienced
Senior Cyber Threat Analyst / Threat Detection Engineer
for a long-term labour hire engagement within a Federal Government Security Operations Centre (SOC).
n
This is a
hands-on threat detection engineering role
focused on researching, developing, testing and maintaining detection use cases, rules and SIEM correlation logic across the SOC technology stack.
n
The environment primarily uses
Splunk Cloud
, with integrated SOAR capabilities, alongside Microsoft Sentinel for selected workloads and Microsoft Defender for Endpoint (MDE) for endpoint detection and response.
n
We are particularly interested in candidates with
5+ years' experience working within a cyber security operations centre and/or directly in threat detection engineering
.
Key Responsibilities n
n
Develop threat detection use cases based on threat models, system risks, vulnerabilities, threat intelligence, incidents and industry frameworks
n
Develop and maintain
SIEM correlation logic, detection rules and detection content
n
Develop detections across
SIEM, SOAR and EDR
technologies
n
Develop playbooks for alert validation and support incident response automation
n
Develop and maintain threat models using recognised methodologies such as
STRIDE, MITRE ATT&CK; and attack path analysis
n
Identify detection opportunities and monitoring coverage gaps
n
Research and analyse emerging threats to develop recent detection content
n
Assess emerging risks associated with
AI platforms, services and agents
n
Develop detection content addressing AI-related misuse, data leakage, prompt injection, model abuse and adversarial activity
n
Maintain threat intelligence integrations across the SOC technology stack
n
Collaborate with Cyber Defence Analysts to test, tune and improve detection rules
n
Assist with incident response and onboarding new security data sources
n
Work with architecture and engineering teams to translate threat modelling outcomes into effective monitoring, detection and response capabilities
n
Skills & Experience Required n
n
5+ years' experience
in cyber security operations, SOC environments and/or threat detection engineering
n
Strong hands-on experience developing
SIEM detection rules, use cases and correlation logic
n
Demonstrated detection engineering experience across
at least two enterprise SIEM platforms
, such as Splunk, Microsoft Sentinel, QRadar or Elastic
n
Strong
Splunk
experience is highly regarded given the target environment
n
Experience developing and implementing detections across
SIEM, SOAR and EDR platforms
n
Experience with incident response automation and security playbook development
n
Practical threat modelling experience using
STRIDE, PASTA, MITRE ATT&CK;
or similar methodologies
n
Strong understanding of the
cyber threat intelligence lifecycle
n
Experience identifying and developing monitoring controls for
AI-related security risks
, ideally involving Microsoft Copilot, Azure AI or similar enterprise AI platforms
n
Strong communication, organisational and stakeholder engagement skills
n
Highly Desirable n
n
Experience with
Splunk Cloud
n
Experience with
Microsoft Sentinel
n
Experience with
Microsoft Defender for Endpoint (MDE)
n
Experience developing or using
Sigma detection rules
and translating detections between security platforms
n
Familiarity with AI security frameworks and guidance including
ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10
n
Experience with enterprise EDR technologies such as CrowdStrike or Carbon Black
n
Python and/or Bash
scripting experience supporting detection engineering and security automation
n
Relevant cyber security certifications such as
GIAC, SANS, CISSP, GCIA, GCIH or equivalent
n
Why Apply? n
n
Initial
12-month contract with up to 24 months of extensions
n
Work within an established
Security Operations Centre
n
Hands-on exposure to
Splunk Cloud, Microsoft Sentinel and Microsoft Defender for Endpoint
n
Work on contemporary detection engineering, threat intelligence and
AI security challenges
n
Hybrid working arrangements with interstate/remote candidates considered
n
#J-*****-Ljbffr
📌 Senior Threat Detection Engineer - Splunk / Sentinel / Mde (Canberra)
🏢 Hatchit Studios
📍 Canberra