Description de l’emploi
This is a remote position. Location:Canberra, Australian Capital Territory (ACT) Security Clearance:Baseline Clearance
Threat Detection Engineering
• SIEM use case development and detection content creation
• Detection rule development and tuning
• EDR detection engineering
• SOAR playbook development
• Alert validation processes
Threat Modelling
• STRIDE
• MITRE ATT&CK
• Attack path analysis
• Detection coverage assessment
• Gap analysis
Threat Intelligence
• Threat intelligence integration and management
• Research into emerging threats
• Intelligence sharing across infrastructure and architecture teams
Security Operations
• SOC operations
• Incident response support
• Detection engineering lifecycle management
• Data source onboarding
• ITIL and Agile environments
AI Security (Important New Requirement)
The RFQ specifically calls for experience in:
• AI threat modelling
• Prompt injection detection
• AI model abuse detection
• AI-related data leakage monitoring
• Adversarial AI activity detection
• Security monitoring of AI platforms, services and agents
A strong candidate would typically have:
• 5+ years in SOC, Detection Engineering, Threat Hunting, or Cyber Security Operations
• Hands-on experience with platforms such as:
• Microsoft Sentinel
• Microsoft Defender XDR
• Splunk
• QRadar
• CrowdStrike
• Palo Alto Cortex XDR
• Experience developing KQL, SPL, Sigma, YARA, or similar detection content
• Strong understanding of MITRE ATT&CK
• Experience integrating threat intelligence feeds
• Good documentation and stakeholder engagement skills
Evaluation Themes to Address in a Submission
When preparing a candidate response, focus on evidence demonstrating:
• Development of threat detection use cases and rules.
• SIEM/EDR content engineering and tuning.
• Threat modelling expertise using STRIDE and ATT&CK.
• Threat intelligence integration and analysis.
• Experience supporting incident response activities.
• Security monitoring of cloud and on-premises environments.
• AI security and emerging threat detection capabilities.
• Working within Agile and ITIL environments.
Requirements
Essential criteria
• 1.Detection Engineering and SIEM Expertise - Demonstrated experience developing detection content across at least two enterprise SIEM platforms (e.g. Splunk, Microsoft Sentinel, QRadar, Elastic).
• 2.Threat Detection and Response Capability - Experience developing and implementing detections across SIEM, SOAR and EDR platforms, including incident response automation and playbook development.
• 3.Threat Modelling and Threat Intelligence - Practical experience conducting threat modelling using recognised methodologies (e.g. STRIDE, PASTA, ATT&CK) and translating outcomes into detection and monitoring requirements, supported by a strong understanding of the cyber threat intelligence lifecycle.
• 4.AI Security Monitoring - Experience identifying, assessing and developing monitoring controls for AI-related security risks, including enterprise AI platforms such as Microsoft Copilot or Azure AI.
• 5.Cyber Security Operations Experience - Minimum five years' experience in cyber security operations, supported by strong organisational, communication and stakeholder engagement skills.
Desirable criteria
• 1.Sigma Rule Development - Experience developing or using Sigma detection rules and translating detections between security platforms.
• 2.Advanced AI Security Knowledge - Familiarity with AI security frameworks and guidance, including ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10. Relevant industry certifications such as GIAC, SANS, CISSP, GCIA, GCIH or equivalent cyber security qualifications.
• 3.EDR Platform Expertise - Experience with enterprise EDR technologies such as CrowdStrike, Microsoft Defender for Endpoint and Carbon Black.
• 4.Automation and Scripting - Proficiency in scripting languages such as Python and Bash to support detection engineering and security automation activities.
LH-07702
Benefits
\
Originally posted on Himalayas