06 Oct
|
Hatchit Studios
|
Harman
06 Oct
Hatchit Studios
Harman
Job Description
Senior Cyber Threat Analyst / Threat Detection Engineer – Splunk n
Location: Canberra / Interstate candidates considered – Hybrid or remote arrangements subject to approval
n
Hours: Up to 40 hours per week
n
Security Requirement: Must be able to obtain Baseline Security Clearance
About the Opportunity n
Hatchit Studios is seeking an experienced Senior Cyber Threat Analyst / Threat Detection Engineer for a long-term labour hire engagement within a Federal Government Security Operations Centre (SOC).
n
This is a hands-on threat detection engineering role focused on researching, developing, testing and maintaining detection use cases, rules and SIEM correlation logic across the SOC technology stack.
n
The environment primarily uses Splunk Cloud , with integrated SOAR capabilities, alongside Microsoft Sentinel for selected workloads and Microsoft Defender for Endpoint (MDE) for endpoint detection and response.
n
We are particularly interested in candidates with 5+ years' experience working within a cyber security operations centre and/or directly in threat detection engineering .
Key Responsibilities n
n
- Develop threat detection use cases based on threat models, system risks, vulnerabilities, threat intelligence, incidents and industry frameworks
n
- Develop and maintain SIEM correlation logic, detection rules and detection content
n
- Develop detections across SIEM, SOAR and EDR technologies
n
- Develop playbooks for alert validation and support incident response automation
n
- Develop and maintain threat models using recognised methodologies such as STRIDE, MITRE ATT&CK; and attack path analysis
n
- Identify detection opportunities and monitoring coverage gaps
n
- Research and analyse emerging threats to develop new detection content
n
- Assess emerging risks associated with AI platforms, services and agents
n
- Develop detection content addressing AI-related misuse, data leakage, prompt injection, model abuse and adversarial activity
n
- Maintain threat intelligence integrations across the SOC technology stack
n
- Collaborate with Cyber Defence Analysts to test, tune and improve detection rules
n
- Assist with incident response and onboarding recent security data sources
n
- Work with architecture and engineering teams to translate threat modelling outcomes into effective monitoring, detection and response capabilities
n
Skills & Experience Required nn
- 5+ years' experience in cyber security operations, SOC environments and/or threat detection engineering
n
- Strong hands-on experience developing SIEM detection rules, use cases and correlation logic
n
- Demonstrated detection engineering experience across at least two enterprise SIEM platforms , such as Splunk, Microsoft Sentinel, QRadar or Elastic
n
- Strong Splunk experience is highly regarded given the target environment
n
- Experience developing and implementing detections across SIEM, SOAR and EDR platforms
n
- Experience with incident response automation and security playbook development
n
- Practical threat modelling experience using STRIDE, PASTA, MITRE ATT&CK; or similar methodologies
n
- Strong understanding of the cyber threat intelligence lifecycle
n
- Experience identifying and developing monitoring controls for AI-related security risks , ideally involving Microsoft Copilot, Azure AI or similar enterprise AI platforms
n
- Strong communication, organisational and stakeholder engagement skills
n
Highly Desirable nn
- Experience with Splunk Cloud
n
- Experience with Microsoft Sentinel
n
- Experience with Microsoft Defender for Endpoint (MDE)
n
- Experience developing or using Sigma detection rules and translating detections between security platforms
n
- Familiarity with AI security frameworks and guidance including ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10
n
- Experience with enterprise EDR technologies such as CrowdStrike or Carbon Black
n
- Python and/or Bash scripting experience supporting detection engineering and security automation
n
- Relevant cyber security certifications such as GIAC, SANS, CISSP, GCIA, GCIH or equivalent
n
Why Apply? nn
- Initial 12-month contract with up to 24 months of extensions
n
- Work within an established Security Operations Centre
n
- Hands-on exposure to Splunk Cloud, Microsoft Sentinel and Microsoft Defender for Endpoint
n
- Work on contemporary detection engineering, threat intelligence and AI security challenges
n
- Hybrid working arrangements with interstate/remote candidates considered
n
#J-18808-Ljbffr
📌 Senior Threat Detection Engineer - Splunk / Sentinel / MDE (Harman)
🏢 Hatchit Studios
📍 Harman