Enter a job title or keyword

SOC Detection Specialist


Job Location:

Canberra - Australia

Monthly Salary: AUD 1 - 1
Experience Required: 4-5years
Posted: 21 September 2026 (12 hours ago)
Application Deadline: 19 December 2026
Vacancies: 1 Vacancy

Job Summary

This is a remote position.

Location: Canberra Australian Capital Territory (ACT)
Security Clearance: Baseline Clearance
Threat Detection Engineering
  • SIEM use case development and detection content creation
  • Detection rule development and tuning
  • EDR detection engineering
  • SOAR playbook development
  • Alert validation processes
Threat Modelling
  • STRIDE
  • MITRE ATT&CK
  • Attack path analysis
  • Detection coverage assessment
  • Gap analysis
Threat Intelligence
  • Threat intelligence integration and management
  • Research into emerging threats
  • Intelligence sharing across infrastructure and architecture teams
Security Operations
  • SOC operations
  • Incident response support
  • Detection engineering lifecycle management
  • Data source onboarding
  • ITIL and Agile environments
AI Security (Important New Requirement)

The RFQ specifically calls for experience in:

  • AI threat modelling
  • Prompt injection detection
  • AI model abuse detection
  • AI-related data leakage monitoring
  • Adversarial AI activity detection
  • Security monitoring of AI platforms services and agents

A strong candidate would typically have:

  • 5 years in SOC Detection Engineering Threat Hunting or Cyber Security Operations
  • Hands-on experience with platforms such as:
    • Microsoft Sentinel
    • Microsoft Defender XDR
    • Splunk
    • QRadar
    • CrowdStrike
    • Palo Alto Cortex XDR
  • Experience developing KQL SPL Sigma YARA or similar detection content
  • Strong understanding of MITRE ATT&CK
  • Experience integrating threat intelligence feeds
  • Good documentation and stakeholder engagement skills
Evaluation Themes to Address in a Submission

When preparing a candidate response focus on evidence demonstrating:

  1. Development of threat detection use cases and rules.
  2. SIEM/EDR content engineering and tuning.
  3. Threat modelling expertise using STRIDE and ATT&CK.
  4. Threat intelligence integration and analysis.
  5. Experience supporting incident response activities.
  6. Security monitoring of cloud and on-premises environments.
  7. AI security and emerging threat detection capabilities.
  8. Working within Agile and ITIL environments.


Requirements
Essential criteria
  • 1.Detection Engineering and SIEM Expertise - Demonstrated experience developing detection content across at least two enterprise SIEM platforms (e.g. Splunk Microsoft Sentinel QRadar Elastic).

  • 2.Threat Detection and Response Capability - Experience developing and implementing detections across SIEM SOAR and EDR platforms including incident response automation and playbook development.

  • 3.Threat Modelling and Threat Intelligence - Practical experience conducting threat modelling using recognised methodologies (e.g. STRIDE PASTA ATT&CK) and translating outcomes into detection and monitoring requirements supported by a strong understanding of the cyber threat intelligence lifecycle.

  • 4.AI Security Monitoring - Experience identifying assessing and developing monitoring controls for AI-related security risks including enterprise AI platforms such as Microsoft Copilot or Azure AI.

  • 5.Cyber Security Operations Experience - Minimum five years experience in cyber security operations supported by strong organisational communication and stakeholder engagement skills.

Desirable criteria
  • 1.Sigma Rule Development - Experience developing or using Sigma detection rules and translating detections between security platforms.

  • 2.Advanced AI Security Knowledge - Familiarity with AI security frameworks and guidance including ASD/ACSC NIST MITRE ATLAS and OWASP LLM Top 10. Relevant industry certifications such as GIAC SANS CISSP GCIA GCIH or equivalent cyber security qualifications.

  • 3.EDR Platform Expertise - Experience with enterprise EDR technologies such as CrowdStrike Microsoft Defender for Endpoint and Carbon Black.

  • 4.Automation and Scripting - Proficiency in scripting languages such as Python and Bash to support detection engineering and security automation activities.


LH-07702

Benefits



Required Skills:

SOC Detection Specialist


Required Education:

SOC Detection Specialist