Cyber Security Engineer
Job Summary:
Our client is seeking an experienced Cyber Security Advisor/SIEM-SOAR Technical Lead to support the delivery and enhancement of critical cyber security capabilities within a complex enterprise environment.
This role will focus on strengthening security monitoring, detection engineering, incident response capability, and automation across a diverse technology landscape. The successful candidate will provide expert cyber security guidance, contribute to continuous improvement initiatives, and play a key role in developing and maintaining Security Operations Centre (SOC) capabilities.
As part of an ongoing technology transformation program, our client is focused on:
- Modernising core technology platforms and business applications.
- Strengthening organisational cyber security maturity and resilience.
- Enhancing internal processes to support the adoption of emerging technologies.
- Driving continuous improvement across technology operations and service delivery.
- Building stronger partnerships across industry, academia, and the broader technology community to identify opportunities and address evolving challenges.
What’s in it for you?
- $1200/day rate
- Collaborative and high-performing team environment.
- Exposure to complex security operations and enterprise-scale cyber programs.
- Long-term opportunity to contribute to the growth and maturity of a critical cyber security capability.
What will you be doing?
- Designing and implementing the onboarding of log sources into enterprise SIEM platforms across cloud, on-premises, identity, endpoint, and network environments.
- Developing and maintaining log parsing, normalisation standards, and data quality controls.
- Building and enhancing SOAR workflows to automate alert triage, enrichment, containment, and response activities.
- Integrating SIEM and SOAR platforms with security and enterprise systems.
- Developing, tuning, and maintaining high-quality detection rules aligned to emerging threats, attack techniques, and organisational risk profiles.
- Creating and maintaining SOC operating procedures, playbooks, and automated response workflows.
- Continuously improving detection accuracy through alert tuning, enrichment, and optimisation activities.
- Supporting cyber incident response activities through log analysis, threat detection, and rapid development of detection content.
- Conducting detection gap assessments following security incidents and threat intelligence updates.
- Maintaining the health, performance, and configuration of SIEM and SOAR platforms.
- Developing dashboards, reporting capabilities, and platform monitoring solutions.
- Producing clear technical documentation, operational procedures, and knowledge transfer artefacts to support ongoing capability uplift.
- Establishing and reporting on key security operations metrics such as Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), alert quality, automation effectiveness, and MITRE ATT&CK coverage.
Skills and experience required to succeed in this role?
- Experience leading the implementation, administration, and optimisation of enterprise SIEM platforms.
- Strong experience designing and implementing SOAR capabilities and security automation workflows.
- Advanced capability in writing complex queries, detection rules, correlation logic, parsers, and analytics content.
- Proven experience developing and maintaining SOC playbooks, operational procedures, and incident response workflows.
- Demonstrated ability to integrate SIEM and SOAR platforms with a range of enterprise security and operational technologies.
- Experience tuning detection content to minimise false positives and improve alert quality and operational effectiveness.
- Strong analytical and problem-solving skills within complex cyber security environments.
- Excellent stakeholder engagement, communication, and documentation skills.
- Experience working within large-scale enterprise or government environments will be highly regarded.
- Work onsite in Canberra, ACT.
Clearance required?
- NV1 Clearance or above.
How to apply?
To apply and be considered for this role, please apply through the link in this add and share a current resume/CV for review. If suitable, you will be contacted for an initial screening and for us to share more information.
We are an inclusive employer committed to fostering a diverse and accessible workplace. We encourage applications from Aboriginal and Torres Strait Islander peoples, people with disabilities, LGBTQIA+ individuals, people of all ages, and those from culturally and linguistically diverse backgrounds.
