Cyber Threat Detection Engineer at Decipher Bureau
Victoria, Victoria, Australia -
Full Time


Start Date

Immediate

Expiry Date

27 Nov, 26

Salary

0.0

Posted On

29 Aug, 26

Experience

0 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

Yes

Skills

Industry

Information Services

Description

Guess Who's back with a brand new hack


Calling all Threat Detection & Response Engineers, if you are looking for a bigger playground, more complex threats and the chance to build detections at genuine enterprise scale, this one’s worth a look.


You’ll be joining a global cyber defence team focused on engineering the detections that identify attacker behaviour across a large, complex enterprise environment.


The core of the role is hands-on detection engineering: researching threats, developing detection logic, tuning existing content and improving coverage across endpoint, identity, cloud and network telemetry.


What you’ll be doing

  • Building and tuning detections within Splunk Enterprise Security
  • Developing SPL queries and improving detection fidelity
  • Translating MITRE ATT&CK techniques into practical detection logic
  • Threat hunting across endpoint, identity, cloud and network telemetry
  • Investigating live incidents and turning findings into new or improved detections
  • Building detection content using Git and YAML
  • Working with detection-as-code and CI/CD pipelines
  • Testing detections against simulated attack activity
  • Supporting the evolution from Splunk to a new platform
  • Collaborating with threat intelligence, incident response and engineering teams globally


What we’re looking for


Ideally, you’ll already be working within detection engineering, threat detection or an advanced security operations environment.


You’ll bring:

  • Strong Splunk and SPL experience
  • Hands-on experience building and tuning security detections
  • Strong understanding of MITRE ATT&CK
  • Experience investigating real-world security incidents
  • Exposure to EDR, cloud, identity and network security telemetry
  • Understanding of Git, YAML and version-controlled workflows


Experience with detection-as-code, CI/CD, SOAR, Python or security automation would be highly regarded.


Most importantly, this role needs someone who understands both how attackers behave and how to engineer reliable detections to identify them.


Why consider it?

  • Work on genuine detection engineering rather than alert monitoring
  • Build detections at enterprise scale
  • Work with Splunk while gaining exposure to new technology
  • Develop detection-as-code and security automation experience
  • Work closely with threat intelligence, threat hunting and incident response specialists


The role is Sydney-based with three days per week in the office. Occasional weekend support may be required for major incidents or upgrades, with time in lieu provided.


  • If you’re already building rules, improving queries and looking for better ways to detect attacker behaviour, this is an opportunity to make detection engineering the core of your role.
Responsibilities
Loading...