Talent.com
PowerData Group Consulting
SOC Detection SpecialistPowerData Group Consulting • Canberra, ACT, au
SOC Detection Specialist

SOC Detection Specialist

PowerData Group Consulting • Canberra, ACT, au
5 days ago
Job type
  • Quick Apply
Job description

Job Description

This is a remote position.

Location: Canberra, Australian Capital Territory (ACT) (remote considered)
Security Clearance: Baseline Clearance

Threat Detection Engineering

  • SIEM use case development and detection content creation
  • Detection rule development and tuning
  • EDR detection engineering
  • SOAR playbook development
  • Alert validation processes

Threat Modelling

  • STRIDE
  • MITRE ATT&CK
  • Attack path analysis
  • Detection coverage assessment
  • Gap analysis

Threat Intelligence

  • Threat intelligence integration and management
  • Research into emerging threats
  • Intelligence sharing across infrastructure and architecture teams

Security Operations

  • SOC operations
  • Incident response support
  • Detection engineering lifecycle management
  • Data source onboarding
  • ITIL and Agile environments

AI Security (Important New Requirement)

The RFQ specifically calls for experience in:

  • AI threat modelling
  • Prompt injection detection
  • AI model abuse detection
  • AI-related data leakage monitoring
  • Adversarial AI activity detection
  • Security monitoring of AI platforms, services and agents

A strong candidate would typically have:

  • 5+ years in SOC, Detection Engineering, Threat Hunting, or Cyber Security Operations
  • Hands-on experience with platforms such as:
    • Microsoft Sentinel
    • Microsoft Defender XDR
    • Splunk
    • QRadar
    • CrowdStrike
    • Palo Alto Cortex XDR
  • Experience developing KQL, SPL, Sigma, YARA, or similar detection content
  • Strong understanding of MITRE ATT&CK
  • Experience integrating threat intelligence feeds
  • Good documentation and stakeholder engagement skills

Evaluation Themes to Address in a Submission

When preparing a candidate response, focus on evidence demonstrating:

  1. Development of threat detection use cases and rules.
  2. SIEM/EDR content engineering and tuning.
  3. Threat modelling expertise using STRIDE and ATT&CK.
  4. Threat intelligence integration and analysis.
  5. Experience supporting incident response activities.
  6. Security monitoring of cloud and on-premises environments.
  7. AI security and emerging threat detection capabilities.
  8. Working within Agile and ITIL environments.


Requirements

Essential criteria

  • 1.Detection Engineering and SIEM Expertise - Demonstrated experience developing detection content across at least two enterprise SIEM platforms (e.g. Splunk, Microsoft Sentinel, QRadar, Elastic).

  • 2.Threat Detection and Response Capability - Experience developing and implementing detections across SIEM, SOAR and EDR platforms, including incident response automation and playbook development.

  • 3.Threat Modelling and Threat Intelligence - Practical experience conducting threat modelling using recognised methodologies (e.g. STRIDE, PASTA, ATT&CK) and translating outcomes into detection and monitoring requirements, supported by a strong understanding of the cyber threat intelligence lifecycle.

  • 4.AI Security Monitoring - Experience identifying, assessing and developing monitoring controls for AI-related security risks, including enterprise AI platforms such as Microsoft Copilot or Azure AI.

  • 5.Cyber Security Operations Experience - Minimum five years' experience in cyber security operations, supported by strong organisational, communication and stakeholder engagement skills.

Desirable criteria

  • 1.Sigma Rule Development - Experience developing or using Sigma detection rules and translating detections between security platforms.

  • 2.Advanced AI Security Knowledge - Familiarity with AI security frameworks and guidance, including ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10. Relevant industry certifications such as GIAC, SANS, CISSP, GCIA, GCIH or equivalent cyber security qualifications.

  • 3.EDR Platform Expertise - Experience with enterprise EDR technologies such as CrowdStrike, Microsoft Defender for Endpoint and Carbon Black.

  • 4.Automation and Scripting - Proficiency in scripting languages such as Python and Bash to support detection engineering and security automation activities.


LH-07702


Benefits

\



Requirements
SOC Detection Specialist

Create a job alert for this search

SOC Detection Specialist • Canberra, ACT, au

Similar jobs

1 Lead Security Architect - Strategic Architecture Advisory, Risk Assessments - Fed Govt!

HiTech GroupACT, AU

High-profile Federal Government cyber security program.Initial 12 month contract + 2 year extension options.Rewarding hourly rates $$ supporting critical national security capabilities .We are seek... Show more

Senior Cyber Threat Analysts

Infinite ConsultingACT, AU

Long term Contract role – Federal Govt.Australian Citizenship with NV2 Clearance.A high‑profile Federal Government program is seeking multiple experienced.These roles involve analysing cyber intrus... Show more

Cyber Security Advisor - Infinite Consulting

Infinite ConsultingCanberra, ACT, AU

Long term Contract role – Federal Govt.Australian Citizenship with NV1 Clearance.A high‑performing Federal Government cyber security team is seeking an experienced.You will lead security risk asses... Show more

Security Officer

Wilson SecurityACT, AU

As one of the largest providers of security services in Australia and New Zealand, our valued employees are supported by a highly experienced management team, industry-leading expertise and a stron... Show more

3 Senior Security Systems Engineers

Infinite ConsultingACT, AU

Senior Security Systems Engineers– NV1 Cleared.Australian Citizens with current NV1 clearance.Senior Security Systems Engineers.We are seeking a highly skilled Security Systems Engineer to act as a... Show more

Security Technician

Allan Hall Business AdvisorsACT, AU

Install and commission advanced electronic security systems as part of a team.Benefit from flexibility and mentoring programs that grow your career.Join a leader in security for Defence, government... Show more

Lead Security Analyst Cyber Threat Analysts - Intelligence - Fed Govt

HiTech GroupACT, AU

Exciting opportunity within a leading Federal Government Agency.A leading Federal Government organisation is seeking.Lead Security Analyst Cyber Threat Analysts.These roles will play a critical par... Show more

Security Officer

Wilson GroupACT, AU

As one of the largest providers of security services in Australia and New Zealand, our valued employees are supported by a highly experienced management team, industry-leading expertise and a stron... Show more