Powerdatagroup logo

SOC Detection Specialist

Powerdatagroup
Posted 2 hours ago
AustraliaRemoteEngineering & Development
Is this job info correct?

Job Description

This is a remote position.

Location: Canberra, Australian Capital Territory (ACT)
Security Clearance: ​Baseline Clearance

Threat Detection Engineering

  • SIEM use case development and detection content creation
  • Detection rule development and tuning
  • EDR detection engineering
  • SOAR playbook development
  • Alert validation processes

Threat Modelling

  • STRIDE
  • MITRE ATT&CK
  • Attack path analysis
  • Detection coverage assessment
  • Gap analysis

Threat Intelligence

  • Threat intelligence integration and management
  • Research into emerging threats
  • Intelligence sharing across infrastructure and architecture teams

Security Operations

  • SOC operations
  • Incident response support
  • Detection engineering lifecycle management
  • Data source onboarding
  • ITIL and Agile environments

AI Security (Important New Requirement)

The RFQ specifically calls for experience in:

  • AI threat modelling
  • Prompt injection detection
  • AI model abuse detection
  • AI-related data leakage monitoring
  • Adversarial AI activity detection
  • Security monitoring of AI platforms, services and agents

A strong candidate would typically have:

  • 5+ years in SOC, Detection Engineering, Threat Hunting, or Cyber Security Operations
  • Hands-on experience with platforms such as:
    • Microsoft Sentinel
    • Microsoft Defender XDR
    • Splunk
    • QRadar
    • CrowdStrike
    • Palo Alto Cortex XDR
  • Experience developing KQL, SPL, Sigma, YARA, or similar detection content
  • Strong understanding of MITRE ATT&CK
  • Experience integrating threat intelligence feeds
  • Good documentation and stakeholder engagement skills

Evaluation Themes to Address in a Submission

When preparing a candidate response, focus on evidence demonstrating:

  1. Development of threat detection use cases and rules.
  2. SIEM/EDR content engineering and tuning.
  3. Threat modelling expertise using STRIDE and ATT&CK.
  4. Threat intelligence integration and analysis.
  5. Experience supporting incident response activities.
  6. Security monitoring of cloud and on-premises environments.
  7. AI security and emerging threat detection capabilities.
  8. Working within Agile and ITIL environments.


Requirements

Essential criteria

  • 1.Detection Engineering and SIEM Expertise - Demonstrated experience developing detection content across at least two enterprise SIEM platforms (e.g. Splunk, Microsoft Sentinel, QRadar, Elastic).

  • 2.Threat Detection and Response Capability - Experience developing and implementing detections across SIEM, SOAR and EDR platforms, including incident response automation and playbook development.

  • 3.Threat Modelling and Threat Intelligence - Practical experience conducting threat modelling using recognised methodologies (e.g. STRIDE, PASTA, ATT&CK) and translating outcomes into detection and monitoring requirements, supported by a strong understanding of the cyber threat intelligence lifecycle.

  • 4.AI Security Monitoring - Experience identifying, assessing and developing monitoring controls for AI-related security risks, including enterprise AI platforms such as Microsoft Copilot or Azure AI.

  • 5.Cyber Security Operations Experience - Minimum five years' experience in cyber security operations, supported by strong organisational, communication and stakeholder engagement skills.

Desirable criteria

  • 1.Sigma Rule Development - Experience developing or using Sigma detection rules and translating detections between security platforms.

  • 2.Advanced AI Security Knowledge - Familiarity with AI security frameworks and guidance, including ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10. Relevant industry certifications such as GIAC, SANS, CISSP, GCIA, GCIH or equivalent cyber security qualifications.

  • 3.EDR Platform Expertise - Experience with enterprise EDR technologies such as CrowdStrike, Microsoft Defender for Endpoint and Carbon Black.

  • 4.Automation and Scripting - Proficiency in scripting languages such as Python and Bash to support detection engineering and security automation activities.


LH-07702

Benefits

\

Similar jobs