PowerData Group Consulting
SOC Detection Specialist
Publicado 21 sept 2026
Este empleo está publicado en EN
This is a remote position.
Location: Canberra, Australian Capital Territory (ACT)
Security Clearance: Baseline Clearance
Threat Detection Engineering
- SIEM use case development and detection content creation
- Detection rule development and tuning
- EDR detection engineering
- SOAR playbook development
- Alert validation processes
- STRIDE
- MITRE ATT&CK
- Attack path analysis
- Detection coverage assessment
- Gap analysis
- Threat intelligence integration and management
- Research into emerging threats
- Intelligence sharing across infrastructure and architecture teams
- SOC operations
- Incident response support
- Detection engineering lifecycle management
- Data source onboarding
- ITIL and Agile environments
The RFQ specifically calls for experience in:
- AI threat modelling
- Prompt injection detection
- AI model abuse detection
- AI-related data leakage monitoring
- Adversarial AI activity detection
- Security monitoring of AI platforms, services and agents
A strong candidate would typically have:
- 5+ years in SOC, Detection Engineering, Threat Hunting, or Cyber Security Operations
- Hands-on experience with platforms such as:
- Microsoft Sentinel
- Microsoft Defender XDR
- Splunk
- QRadar
- CrowdStrike
- Palo Alto Cortex XDR
- Microsoft Sentinel
- Experience developing KQL, SPL, Sigma, YARA, or similar detection content
- Strong understanding of MITRE ATT&CK
- Experience integrating threat intelligence feeds
- Good documentation and stakeholder engagement skills
Evaluation Themes to Address in a Submission
When preparing a candidate response, focus on evidence demonstrating:
- Development of threat detection use cases and rules.
- SIEM/EDR content engineering and tuning.
- Threat modelling expertise using STRIDE and ATT&CK.
- Threat intelligence integration and analysis.
- Experience supporting incident response activities.
- Security monitoring of cloud and on-premises environments.
- AI security and emerging threat detection capabilities.
- Working within Agile and ITIL environments.
Requirements
Essential criteria
-
1.Detection Engineering and SIEM Expertise - Demonstrated experience developing detection content across at least two enterprise SIEM platforms (e.g. Splunk, Microsoft Sentinel, QRadar, Elastic).
-
2.Threat Detection and Response Capability - Experience developing and implementing detections across SIEM, SOAR and EDR platforms, including incident response automation and playbook development.
-
3.Threat Modelling and Threat Intelligence - Practical experience conducting threat modelling using recognised methodologies (e.g. STRIDE, PASTA, ATT&CK) and translating outcomes into detection and monitoring requirements, supported by a strong understanding of the cyber threat intelligence lifecycle.
-
4.AI Security Monitoring - Experience identifying, assessing and developing monitoring controls for AI-related security risks, including enterprise AI platforms such as Microsoft Copilot or Azure AI.
-
5.Cyber Security Operations Experience - Minimum five years' experience in cyber security operations, supported by strong organisational, communication and stakeholder engagement skills.
Desirable criteria
-
1.Sigma Rule Development - Experience developing or using Sigma detection rules and translating detections between security platforms.
-
2.Advanced AI Security Knowledge - Familiarity with AI security frameworks and guidance, including ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10. Relevant industry certifications such as GIAC, SANS, CISSP, GCIA, GCIH or equivalent cyber security qualifications.
-
3.EDR Platform Expertise - Experience with enterprise EDR technologies such as CrowdStrike, Microsoft Defender for Endpoint and Carbon Black.
-
4.Automation and Scripting - Proficiency in scripting languages such as Python and Bash to support detection engineering and security automation activities.
LH-07702
Benefits
\Resumen del puesto
Tipo de empleo
Tiempo completo
Habilidades requeridas
Empleos similares
Systems Engineer
PowerData Group Consulting
APS5 Test Analysts (Functional Automation Tester)
SoftLabs
EL1 Senior Cloud Architect / Cloud Engineer
SoftLabs
EL1 Senior Power Platform Software Engineer (Developer)
SoftLabs
Test Analyst ( NV1 Clearance )
XPT Software Australia Pty Ltd
Senior Cloud Architect ( NV1 Clearance )
XPT Software Australia Pty Ltd