This is not a traditional SOC analyst role.
You won’t be sitting in a queue closing alerts or following static playbooks. You’ll be engineering the detection logic behind a global cyber defence capability, researching attacker techniques, translating threats into code and building detections that operate effectively across a large, complex enterprise environment.
Working within a high-performing Cyber Threat Intelligence and Incident Response function, you’ll join a globally distributed detection engineering team with a follow-the-sun model.
The opportunity You’ll work through structured two-week sprints, taking threat scenarios from initial research through to production-ready detection. That could mean investigating a supply chain compromise, understanding how a technique presents across different telemetry sources and developing the Splunk logic required to detect it.
The environment is currently Splunk, giving you the opportunity to help evolve a modern, intelligence-led detection capability while working with SIEM, SOAR and detection-as-code practices.
Your responsibilities will include: - Researching attacker behaviours, vulnerabilities and MITRE ATT&CK techniques
- Designing and developing high-fidelity detections in Splunk Enterprise Security
- Investigating cyber incidents and converting lessons learned into improved detection coverage
- Threat hunting across endpoint, identity, cloud, network and authentication telemetry
- Writing, testing and maintaining detection content using YAML and Git-based workflows
- Pushing detection content through CI/CD pipelines using GitHub and Bitbucket/Stash
- Testing detections through synthetic attack scenarios
- Optimising SPL queries and log ingestion to improve performance and detection fidelity
- Working with service owners to understand data sources, logging coverage and pipeline limitations
- Collaborating with CTI, incident response and engineering teams across a follow-the-sun model
What you’ll bring
You’ll ideally have 3–5 years of experience across detection engineering, incident response, threat hunting or advanced security operations, with strong hands-on experience investigating real-world attacks.
We’re particularly interested in:
- Strong Splunk Enterprise Security and SPL query development experience
- Practical experience building, tuning and maintaining threat detections
- Knowledge of Google SecOps, Chronicle or another modern SIEM platform
- A strong understanding of MITRE ATT&CK and how attacker techniques appear in telemetry
- Experience investigating endpoint attacks, phishing, identity threats and cloud-based activity
- Knowledge of AWS and common enterprise security technologies, including EDR, firewalls and proxies
- An understanding of log pipelines, data quality and query-performance optimisation
- Experience using Git, YAML and version-controlled engineering workflows
- The ability to explain detection logic and investigation findings to technical stakeholders
Experience with CI/CD pipelines and detection-as-code practices will be highly regarded. Exposure to SOAR platforms, software development practices or AI-assisted coding tools would also be valuable.
Why consider it? - Engineer detections rather than simply respond to alerts
- Work with Splunk ES while supporting a migration
- Build detections through a genuine detection-as-code pipeline
- Work closely with threat intelligence, threat hunting and incident response specialists
- Join a mature, well-managed follow-the-sun operation
- Develop coverage across cloud, identity, endpoint and network threats
- Access extensive learning, development and employee benefits
The team operates in a hybrid model, with three days per week in the Sydney office. Some occasional weekend availability may be required to support significant incidents, although this is not a routine on-call-heavy environment.
If you’re currently working in security operations but increasingly find yourself building the rules, improving the queries and questioning why detections work the way they do, this could be the step into a dedicated detection engineering career.