Senior Threat Detection Engineer – Splunk / Sentinel / MDE
- Hiring from
- Australia
- Work type
- Hybrid
- Posted
- Sep 28, 2026
Senior Cyber Threat Analyst / Threat Detection Engineer – Splunk
📍 Location: Canberra / Interstate candidates considered – Hybrid or remote arrangements subject to approval
⏳ Contract Duration: 12 months + 2 x 12-month extension options
💼 Industry: Federal Government – Cyber Security
⏰ Hours: Up to 40 hours per week
🔒 Security Requirement: Must be able to obtain Baseline Security Clearance
About the Opportunity
Hatchit Studios is seeking an experienced Senior Cyber Threat Analyst / Threat Detection Engineer for a long-term labour hire engagement within a Federal Government Security Operations Centre (SOC).
This is a hands-on threat detection engineering role focused on researching, developing, testing and maintaining detection use cases, rules and SIEM correlation logic across the SOC technology stack.
The environment primarily uses Splunk Cloud, with integrated SOAR capabilities, alongside Microsoft Sentinel for selected workloads and Microsoft Defender for Endpoint (MDE) for endpoint detection and response.
We are particularly interested in candidates with 5+ years' experience working within a cyber security operations centre and/or directly in threat detection engineering.
Key Responsibilities
- Develop threat detection use cases based on threat models, system risks, vulnerabilities, threat intelligence, incidents and industry frameworks
- Develop and maintain SIEM correlation logic, detection rules and detection content
- Develop detections across SIEM, SOAR and EDR technologies
- Develop playbooks for alert validation and support incident response automation
- Develop and maintain threat models using recognised methodologies such as STRIDE, MITRE ATT&CK and attack path analysis
- Identify detection opportunities and monitoring coverage gaps
- Research and analyse emerging threats to develop new detection content
- Assess emerging risks associated with AI platforms, services and agents
- Develop detection content addressing AI-related misuse, data leakage, prompt injection, model abuse and adversarial activity
- Maintain threat intelligence integrations across the SOC technology stack
- Collaborate with Cyber Defence Analysts to test, tune and improve detection rules
- Assist with incident response and onboarding new security data sources
- Work with architecture and engineering teams to translate threat modelling outcomes into effective monitoring, detection and response capabilities
Skills & Experience Required
- 5+ years' experience in cyber security operations, SOC environments and/or threat detection engineering
- Strong hands-on experience developing SIEM detection rules, use cases and correlation logic
- Demonstrated detection engineering experience across at least two enterprise SIEM platforms, such as Splunk, Microsoft Sentinel, QRadar or Elastic
- Strong Splunk experience is highly regarded given the target environment
- Experience developing and implementing detections across SIEM, SOAR and EDR platforms
- Experience with incident response automation and security playbook development
- Practical threat modelling experience using STRIDE, PASTA, MITRE ATT&CK or similar methodologies
- Strong understanding of the cyber threat intelligence lifecycle
- Experience identifying and developing monitoring controls for AI-related security risks, ideally involving Microsoft Copilot, Azure AI or similar enterprise AI platforms
- Strong communication, organisational and stakeholder engagement skills
Highly Desirable
- Experience with Splunk Cloud
- Experience with Microsoft Sentinel
- Experience with Microsoft Defender for Endpoint (MDE)
- Experience developing or using Sigma detection rules and translating detections between security platforms
- Familiarity with AI security frameworks and guidance including ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10
- Experience with enterprise EDR technologies such as CrowdStrike or Carbon Black
- Python and/or Bash scripting experience supporting detection engineering and security automation
- Relevant cyber security certifications such as GIAC, SANS, CISSP, GCIA, GCIH or equivalent
Why Apply?
- Long-term Federal Government cyber security engagement
- Initial 12-month contract with up to 24 months of extensions
- Work within an established Security Operations Centre
- Hands-on exposure to Splunk Cloud, Microsoft Sentinel and Microsoft Defender for Endpoint
- Work on contemporary detection engineering, threat intelligence and AI security challenges
- Hybrid working arrangements with interstate/remote candidates considered
- Competitive contract rates