DO

Detection Engineer / Security Analyst — Managed SIEM (Splunk)

Salary
A$130K–A$160K
Hiring from
Australia
Work type
Hybrid
Posted
Is this job info correct?

521,761 remote jobs, straight from company career pages

100% free · New jobs every hour

Show job description

The work

We run a 24x7 managed SIEM for Australian clients based on Splunk Enterprise Security, and built on ISO 27001 and PCI DSS-compliant infrastructure. We've done it for 15 years, with consistent innovations and optimisations, and we'd like your help to help us continue to improve.


Your typical week is roughly half managed SIEM and detection engineering, a third configuration hardening, assessment, threat hunting and purple team, and the remainder keeping our own ISMS and infrastructure in good shape.


You'll onboard client data sources, even the messy ones that don't come with a tidy plugin. You'll write the transforms yourself and (if needs be) normalise to CIM. You'll write detection content in SPL from a blank page, map it to ATT&CK, and tune correlation searches to keep false positives under control without losing important insights. You'll triage notable events against our SLA, decide whether something is malicious, and be confident you can defend your decisions.


When you're not doing SIEM work you'll be helping with other security-engineering work. For example, you'll keep Splunk healthy on Linux in AWS and diagnose ingestion faults across lots of log sources including CloudTrail, CrowdStrike Falcon, M365 and Azure, and custom log sources. And you'll review client M365, Entra ID, Windows and AWS configurations against CIS Benchmarks and the Essential Eight, confirming all findings with evidence.


What we offer

$130K–$160K package reviewed annually. Sponsored certifications with agreed costs and study time during work hours; we'll agree on the details but likely certs will focus on Splunk, AWS, CrowdStrike, SC-200, BSCP, or ISO 27001. Every client deliverable is peer reviewed, so you'll get room to make decisions, but you won't be left alone with them. Hybrid working after probation, and a shared after-hours on-call roster. You'll report directly to the director in a small team of specialists, working with clients who've stayed with us for ten and twenty years.


What you'll bring

At least 3 years in infosec, with hands-on in a SIEM, SOC, MSSP or security engineering role. Splunk experience is preferred but genuine depth in Sentinel, Elastic or QRadar counts; SPL is learnable if the fundamentals are there.


Note: The one thing we can't teach at the pace we need is Microsoft log analysis, because that's what most of our clients run, and we need those skills today. You should be able to read Windows security event logs on day one, and understand what happened; treat Active Directory as an attack surface rather than an org chart; review and develop Entra ID sign-in and audit logs; understand and work with Conditional Access Policies; and navigate Azure activity logs and resource RBAC.


We also look for comfort on a Linux command line and enough Bash, PowerShell or Python skills to keep you from doing the boring things twice.


We feel that using AI to conduct job-application reviews and interviews is insulting to the candidate, and so we will conduct our reviews and interviews in person, human-to-human. In exchange, we'll ask you to agree to take part in our job interviews and testing exercises without LLM assistance. You can of course use AI tooling (according to our policy) while you're at work, but we want to talk to you now, not Claude or one of his mates.


How to apply

First up, be sure that you have the right to work in Australia, that you can be in Brisbane in four weeks time, that you're willing to undergo background and national criminal history checks, and that you have three, reputable referees.


All good? Then apply here with your CV. That's all we need to start.


Shortlisted candidates will be asked to do a short practical exercise and draft a simple report. If that goes well, we'll arrange a more detailed technical conversation about your skills, goals, and the work you've actually done.


Questions before you apply? Message https://www.linkedin.com/in/tim-redhead-dotsec/ directly.


We look forward to hearing from you.

Similar jobs

Apply on LinkedIn