Security SIEM Specialist and Detection Engineer
at BAE Systems
Canberra ACT 2601, Parkes, Australia -
Start Date | Expiry Date | Salary | Posted On | Experience | Skills | Telecommute | Sponsor Visa |
---|---|---|---|---|---|---|---|
Immediate | 07 May, 2025 | Not Specified | 07 Feb, 2025 | N/A | Good communication skills | No | No |
Required Visa Status:
Citizen | GC |
US Citizen | Student Visa |
H1B | CPT |
OPT | H4 Spouse of H1B |
GC Green Card |
Employment Type:
Full Time | Part Time |
Permanent | Independent - 1099 |
Contract – W2 | C2H Independent |
C2H W2 | Contract – Corp 2 Corp |
Contract to Hire – Corp 2 Corp |
Description:
BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments.
DIVISION OVERVIEW: CAPABILITIES
At BAE Systems Digital Intelligence, we pride ourselves in being a leader in the cyber defence industry, and Capabilities is the engine that keeps the business moving forward. It is the largest area of Digital Intelligence, containing our Engineering, Consulting and Project Management teams that design and implement the defence solutions and digital transformation projects that make us a globally recognised brand in both the public and private sector.
As a member of the Capabilities team, you will be creating and managing the solutions that earn us our place in an ever changing digital world. We all have a role to play in defending our clients, and this is yours
Responsibilities:
ROLE SUMMARY
We are looking for a talented and enthusiastic individual with excellent technical and client-facing skills to act a SIEM specialist who can design and deploy SIEM (Security Information and Event Management) / SOAR (Security Orchestration, Automation and Response) capabilities. They will also be responsible for working with clients to derive the security use cases across a range of platforms and systems to be monitored. These use cases will be based on appropriate MITRE frameworks and client defined insider, vulnerability, business, risk and policy enforcement requirements. The role will range from deploying new solutions and assessing existing capabilities to identify the exposure and coverage gaps.
This role is situated within our Government business, based in Canberra, with substantial time on client sites and will require a government security clearance at NV2 minimum, but candidates will be expected to undergo PV.
Find out more about our award winning Cyber Security solutions: http://www.baesystems.com/en/cybersecurity/solutions/by-business-objective/detect-and-monitor-for-cyber-attacks
WHAT YOU’LL BE DOING
- Oversee deployment / implementation activities ensuring that entry criteria are met, all planned activities are completed and that rollback plans are initiated where required.
- Identify use cases, plan development, deployment, testing and release into production.
- Produce, update and maintain corresponding playbooks for detection and automation content.
- Develop, test and deploy updated and new content across the monitored estate in liaison with the client.
- Maintain existing detection content to ensure it remains current and relevant to the monitored estate, and that false positives are kept to a minimum.
- Assess the effectiveness of new / updated rules and analytics to feed into future development activities.
- Review and approve all required documentation as part of a release or change including design, deployment, configuration and administration guides.
- Support attack, threat and exposure modelling to identify new attack paths and determine suitable detection content to detect path being exploited.
- Support threat hunting and content enrichment.
- Integrate solutions with vulnerability and asset and configuration management and other tools to enrich efficacy of the solution.
- Obtain authorisation for implementing releases and changes through the Change Management process.
- The strategic focus of the role is to ensure that the detection and monitoring technology remains optimised, current and tailored to the changing threat landscape, client risk position and technology in use.
- The role is a cyber technical specialist with deep knowledge of the Cyber Monitoring technologies and cyber threat tools, tactics, techniques and procedures.
REQUIREMENT SUMMARY
Min:N/AMax:5.0 year(s)
Information Technology/IT
IT Software - Network Administration / Security
Software Engineering
Graduate
Proficient
1
Canberra ACT 2601, Australia