Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs

Jobs by Experience

drjobs

1 - 0 years

Job Location

drjobs

Mersa Matruh - Egypt

Monthly Salary

drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Nationality

Any Nationality

Gender

Male

Vacancy

1 Vacancy

Job Description

Req ID : 2452651

The Department of Industry, Science and Resources (DISR) strives to encourage the sustainable growth of Australian industries including the delivery of a national innovation system to drive knowledge creation, international competitiveness and greater productivity. Our staff are committed to developing policies and delivering programs, in partnership with stakeholders, to provide lasting economic benefits based on principles of social justice and equity for all Australians.


The CIO Group provides a range of enabling services and operational delivery support to the Department and to Australian businesses, and is seeking to engage a Threat Detection Engineer (TDE) to drive the detection engineering practice in its Security Operations Centre (SOC).


The TDE will be responsible for the research, development, testing and maintenance of use cases and detection rules, including manual threat hunts. They are to co-ordinate with Cyber Defence Analysts in developing situational awareness through the integration and maintenance of the SIEM, SOAR and EDR. As part of the detection engineering lifecycle the TDE is expected to work in an ITIL and Agile environment. The Threat Detection Engineer is also responsible for providing high-level technical assistance to infrastructure and architecture staff on risk and vulnerability reduction by means of the detection capability of the SOC.


Key Responsibilities:

  • Create threat models and preform threat hunts to inform the detection engineering strategy
  • Develop use cases based off threat models, system risks, vulnerabilities, intelligence, incident reports and industry frameworks
  • Develop the detection rule syntax associated with use cases within the SIEM and EDR technologies
  • Develop playbooks for alert validation by understanding the context in which the detection rule is designed
  • Collaborate with Cyber Defence Analysts for detection rule tuning
  • Maintain the threat intelligence integrations across the SOC technology stack
  • Assist in the identification of content shortfalls across the detection engineering practice
  • Assist with incident response at that direction of the incident manager
  • Conduct in-depth research and analysis for new detection content
  • Assist in the onboarding of new data sources to meet requirements of use cases
  • Provide evaluation and feedback necessary for improving intelligence production and reporting
  • Provide support to designated exercises, planning activities, and time sensitive operations


Requirements

  • Demonstrated experience in content development with at least 2 SIEM technologies (Splunk, Elastic, Q-Radar, MS Sentinel)
  • Experience in a detection engineering practice
  • Understanding of the sigma detection rule syntax
  • Experience with SOAR (Security Orchestration, Automation, and Response) technologies and playbook development
  • Experience with EDR (Endpoint Detection and Response) technologies (Carbon Black, CrowdStrike, Defender ATP)
  • Thorough understanding of the cyber threat intelligence lifecycle
  • Knowledge of scripting languages (Bash, Python)
  • Strong organizational and teamwork skills
  • Professional Certifications, such as GIAC
  • Minimum 5 years of cyber security operations experience


Essential criteria 1.Demonstrated experience in transformational programs, guiding and driving product owners/business SME to develop user journey, business features, streamline business processes and consolidate common services/data to deliver business change to deliver contemporary customer experience. 2.A proven track record in working in Agile environment to develop requirements artefacts for complex IT systems including websites and mobile applications. 3.Experience working with complex IT systems, including a sound understanding of system interoperability, database structures and data flows between systems. 4.Demonstrated experience coordinating and leading consultation with internal and external consultants to elicit user and business requirements. 5.Proven ability in development of high-quality BA artefacts as required. Desirable criteria 1.Previous experience working on the Department s Employment and Workplace Relations IT systems or experience in a Government Agency is highly desired. 2.Experience using Azure DevOps for Agile Methodology.

Employment Type

Full Time

Department / Functional Area

Data Entry / Operations / Back Office Processing

Key Skills

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.