Threat Detection Engineer

1 month ago


Canberra, Australia Softtest pays pty ltd Full time

Please respond to the job if you are an Australian Citizen and residing in Australia.

  • Contract start 01 April 2023 To 12 months, 2 x 12 months extensions.
  • Australian Citizen, ability to obtain Baseline Clearance, Canberra role.

Send your responses to jobs@softtestpays.com

Overview

The Department of Industry, Science and Resources (DISR) strives to encourage the sustainable growth of Australian industries including the delivery of a national innovation system to drive knowledge creation, international competitiveness and greater productivity. Our staff are committed to developing policies and delivering programs, in partnership with stakeholders, to provide lasting economic benefits based on principles of social justice and equity for all Australians.

The CIO Group provides a range of enabling services and operational delivery support to the Department and to Australian businesses, and is seeking to engage a Threat Detection Engineer (TDE) to drive the detection engineering practice in its Security Operations Centre (SOC).

The TDE will be responsible for the research, development, testing and maintenance of use cases and detection rules, including manual threat hunts. They are to co-ordinate with Cyber Defence Analysts in developing situational awareness through the integration and maintenance of the SIEM, SOAR and EDR. As part of the detection engineering lifecycle the TDE is expected to work in an ITIL and Agile environment. The Threat Detection Engineer is also responsible for providing high-level technical assistance to infrastructure and architecture staff on risk and vulnerability reduction by means of the detection capability of the SOC.

Key Responsibilities:

  • Create threat models and preform threat hunts to inform the detection engineering strategy
  • Develop use cases based off threat models, system risks, vulnerabilities, intelligence, incident reports and industry frameworks
  • Develop the detection rule syntax associated with use cases within the SIEM and EDR technologies
  • Develop playbooks for alert validation by understanding the context in which the detection rule is designed
  • Collaborate with Cyber Defence Analysts for detection rule tuning
  • Maintain the threat intelligence integrations across the SOC technology stack
  • Assist in the identification of content shortfalls across the detection engineering practice
  • Assist with incident response at that direction of the incident manager
  • Conduct in-depth research and analysis for new detection content
  • Assist in the onboarding of new data sources to meet requirements of use cases
  • Provide evaluation and feedback necessary for improving intelligence production and reporting
  • Provide support to designated exercises, planning activities, and time sensitive operations

Every application requires to address selection criteria as part of application submission

Essential Criteria

Demonstratable experience in content development with at least 2 SIEM technologies (Splunk, Elastic, Q-Radar, MS Sentinel)

Experience in a detection engineering practice

An understanding of the sigma detection rule syntax

Experience with SOAR technologies and playbook development

Experience with EDR technologies (Carbon Black, CrowdStrike, Defender ATP)

A thorough understanding of the cyber threat intelligence lifecycle

Knowledge of scripting languages (Bash, Python)

Strong organisational and teamwork skills.

Professional Certifications, such as GIAC

Minimum 5 years of cyber security operations experience



  • Canberra, Australia Australian Signals Directorate Full time

    **The Role** Technical Threats and Visibility Branch is seeking Malware, Intrusion and Threat Hunter Analysts to join teams responsible for analysing network traffic and host activity to identify anomalous behaviour, and reverse engineering malware. The teams develop and mature detection capabilities and analytical tradecraft to further the ACSC’s...


  • Canberra, Australia Hughes and Jones Consulting Full time

    Australia's leading cyber security intelligence consultancy continuing to expand cyber security operations, threat analytics, security integration and engineering capability for large enterprise projects. Fast-paced dynamic environment offering excellent career advancement opportunities and training structure to support ongoing certification and further...


  • Canberra, Australia Hughes and Jones Consulting Full time

    Australia's leading cyber security intelligence consultancy continuing to expand cyber security operations, threat analytics, security integration and engineering capability for Government and Defence projects. Fast-paced dynamic environment offering excellent career advancement opportunities and training structure to support ongoing certification and...


  • Canberra, Australia CyberCX Full time

    Based on-site in Canberra (not remote) - Must be a United States citizen - Deliver a patented new approach to cybersecurity **About the company** CyberCX is joining forces with one of the most exciting cyber security companies from the United States to deliver projects for the Australian market. You will be trained to deliver a patented, groundbreaking...


  • Canberra, Australia National Health Funding Body Full time

    **Job Reference Number **23-ITDIV-16998 **Classification **Executive Level 1 **Job Title **Cyber Security **Division **Information Technology Division **Branch **Cyber and Protective Security Branch **Section **Cyber Security Section **Applications open date **Friday 24 March 2023 **Applications closing date **Sunday 9 April 2023 **Employment type...


  • Canberra, Australia CyberCX Full time

    Must be based in Canberra (not remote) - Must be a United States citizen **About the company** CyberCX is joining forces with one of the most exciting cyber security companies from the United States to deliver projects for the Australian market. You will be trained to deliver a patented, groundbreaking new approach to cybersecurity that identifies, stops,...


  • Canberra, Australia Xero Full time

    Xero is a beautiful, easy-to-use platform that helps small businesses and their accounting and bookkeeping advisors grow and thrive. At Xero, our purpose is to make life better for people in small business, their advisors, and communities around the world. This purpose sits at the centre of everything we do. We support our people to do the best work of...


  • Canberra, Australia Effective People Full time

    **14th June, 2023**: **Cyber Security Specialist** **NV1 clearance required prior to commencement** **12 months initially** **$120 - $150 per hour inc super** **Canberra CBD (onsite)** **ID: 1088704** **_WHY CHOOSE EFFECTIVE PEOPLE?_** - _We pay fortnightly with in-house payroll_ - _Salary packaging & bank your hours_ - _Novated leasing, corporate discounts...


  • Canberra, Australia Online 89 Full time

    Canberra - 12 months (to 30/6/2024) with 2×12 month extension options - Must be an Australian citizen - Must be able to obtain an NV1 security clearance - Anticipated start date Monday 10/7/2023 Role Description Your duties will include, but are not limited to: - Collaborate with cross-functional teams to integrate security measures into the design and...


  • Canberra, Australia Paxus Australia Pty Ltd Full time

    Posted 20 April 2023 - SalaryNegotiable - LocationCanberra - Job type Contract - DisciplineSecurity + Cyber Security - ReferenceBBBH261107_1681977610 **Job description**: **Cyber Security Officer** - 2 years fixed term contract - Nv1 Security clearance preferred - Australian Citizen **About the role** As the Cyber Operations Officer, you will work as part...


  • Canberra, Australia Exclaim IT Pty Ltd Full time

    **Competitive hourly market rates**: - Initial 12-month contract with 2 possible 12-month extensions - Working onsite from ACT, NSW or VIC - An exciting Federal Government opportunity **Location**:Canberra, Australian Capital Territory - Australia **Work type**:Contract **Date Posted**:14 June, 2023 **Reference**:#15796 **About the role** **Key...


  • Canberra, Australia Talent International Full time

    **Job Details**: **Location** Canberra **Salary** AU$81127 - AU$101260.00 per annum + + Super **Ref** BBBH100785_1681455538 **Contact** Jaela Smith **Posted** about 2 hours ago - **2 year fixed term contract**: - ** $82,127 - $101,260 p/a + super**: - ** Must be an Australian Citizen** **Our Client** Our client is a government-owned organisation...


  • Canberra, Australia Gateway Synergy Recruitment Full time

    Experience as a technical Cyber Security Specialist or similar role - ACT/NSW/VIC based, flexible arrangement possible, day rate $1000-2000 - Can obtain NV1, 12 months contract with a possible 2 x 12 months extension **The Role** Outstanding opportunity for a driven professional to join a government department in an IT capacity. A passionate, driven...


  • Canberra, Australia Federal Government Full time

    **Cyber Security Bundle Lead** **Abou the role** To support the ICT Sourcing Program, the Cyber Security Bundle Lead will contribute to the Department’s future Cyber Security approach, ensuring that the requirements identified in any sourcing transaction align with the Departments ICT and Cyber Security strategy and direction. The Cyber Security Bundle...


  • Canberra, Australia Department of Finance Full time

    Business Enabling Services Group / ICT Division / Governance and Procurement Branch - APS 5 ($85,836 - $96,313), APS 6 ($94,434 - $115,254) | Ongoing | Full-time & Part-time - Canberra, ACT **ABOUT THE BRANCH** The Governance and Procurement Branch (GPB) consists of the GPB Strategy and Governance, the Chief Architect, the IT Security Team and the Central...

  • Vulnerability Analyst

    1 month ago


    Canberra, Australia HiTech Personnel Full time

    **Reference #**: - JF/ST0033**Title**: - Vulnerability Analyst / cyber / software / Fed Govt**Category**: - ICT**Location**: - ACT**Work Type**: - Contract**Remuneration**: - $Neg**Term**: - 12 months**Description**: - High Profile Federal Government Department! - Initial 12 month contract with 2 x 12 month extension options! - Rewarding hourly rate!...


  • Canberra, Australia FinXL Full time

    **Job details**: - Posted 15 June 2023 - SalaryNegotiable - LocationCanberra - Job type Contract - DisciplineTelecommunications - ReferenceCR/022657_1686811658 **Job description**: **12 month initial contract with long-term extension options** **Canberra (ACT) Location** FinXL IT Professional Services is an established innovative Australian company...


  • Canberra, Australia CYOS Solutions Full time

    **Application closing date**: Thursday, 27 July 2023 - 11:59pm, Canberra time (in Canberra) **Estimated start date**: Monday, 21 August 2023 **Location of work**: ACT **Length of contract**: 5 Months **Contract extensions**: 2 x 6 months **Security clearance**: Must have Baseline **Rates**: $110 - $150 per hour (inc. super) The Security Expert will...


  • Canberra, Australia Australian Government Department of Defence Full time

    The Role As a Technical Intelligence Analyst focussing on guided weapons, you will use your unique technical expertise to analyse and report on weapon systems and defence technologies that may pose threats to Australian forces.  You will access and analyse a broad range of information sources, collaborate with other specialists, and use your research...


  • Canberra, Australia Australian Government Department of Defence Full time

    The Role As a Technical Intelligence Analyst focussing on guided weapons, you will use your unique technical expertise to analyse and report on weapon systems and defence technologies that may pose threats to Australian forces. You will access and analyse a broad range of information sources, collaborate with other specialists, and use your research and...