Live opening · Posted 11 days ago

Cyber Threat Investigator

Velan Consulting Pty Ltd · Australia (Remote)
Linkedin No
You are 11 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 11 days ago
CompanyVelan Consulting Pty Ltd
LocationAustralia (Remote)
Work modeNo
SourceLinkedin
Listed11 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
11 min from Linkedin publishing this role to us finding it
9 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
74,597 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Velan Consulting Pty Ltd - Direct supplier to both Federal and Private clients.
Senior Cyber Threat Analyst | Canberra - Hybrid | Australian Citizens with Baseline | Long-term Contract
About the team
The Chief Information Officer Division (CIO Division) is an exciting, fast-paced division that drives the digital agenda for the Department. Leading the delivery of the department’s digital offerings, the CIO Division partners with business areas and stakeholders to:
• Realise the digital policy objectives of the Department
• Define the Departments digital landscape
• Drive the innovation and transformation of its IT services.
The Cyber Security team is responsible for oversight and management of cyber security within the department. The team is made up of 4 streams including: Governance, Risk and Compliance, Security Operations Centre, Project Advisory and Assurance and Cyber Engagement.
Job specific role description:
Threat Detection Engineer develops and maintains the material required to detect threats and incidents across the SOC technology stack.
The Threat Detection Engineer (TDE) is responsible for the research, development, testing and maintenance of use case and detection rules. They are to co-ordinate with Cyber Defence Analysts in developing detection content for use in the SIEM, SOAR and EDR platforms.
As part of the detection engineering lifecycle the TDE is expected to work in an ITIL and Agile environment, developing process and engineering documentation. The TDE is also responsible for providing threat intelligence sharing to infrastructure and architecture teams in both Cloud and onpremise environments.
Key duties and responsibilities
This position is responsible for:
Develop use cases based off threat models, system risks, vulnerabilities, intelligence, incident reports and industry frameworks
Develop the detection rule syntax associated with use cases within the SIEM and EDR technologies
Develop playbooks for alert validation by understanding the context in which the detection rule is designed
Develop and maintain threat models using industry recognised methodologies such as STRIDE, ATT&CK and attack path analysis to identify detection opportunities and coverage gaps.
Assess emerging threats associated with Artificial Intelligence (AI) platforms, services and agents, and develop detection content to identify AI-related misuse, data leakage, prompt injection, model abuse and adversarial activity.
Collaborate with architecture and engineering teams to ensure threat modelling outcomes are translated into effective monitoring, detection and response capabilities.
Maintain the threat intelligence integrations across the SOC technology stack
Conduct in-depth research and analysis for new detection content
Collaborate with Cyber Defence Analysts for detection rule tuning
Assist with threat model development to inform the detection engineering strategy
Assist in the identification of content shortfalls across the detection engineering practice
Assist with incident response at that direction of the incident manager
Assist in the onboarding of new data sources to meet requirements of use cases
Provide evaluation and feedback necessary for improving intelligence production and reporting
Provide support to designated exercises, planning activities, and time sensitive operations
Essential criteria
1.Detection Engineering and SIEM Expertise - Demonstrated experience developing detection content across at least two enterprise SIEM platforms (e.g. Splunk, Microsoft Sentinel, QRadar, Elastic).
2.Threat Detection and Response Capability - Experience developing and implementing detections across SIEM, SOAR and EDR platforms, including incident response automation and playbook development.
3.Threat Modelling and Threat Intelligence - Practical experience conducting threat modelling using recognised methodologies (e.g. STRIDE, PASTA, ATT&CK) and translating outcomes into detection and monitoring requirements, supported by a strong understanding of the cyber threat intelligence lifecycle.
4.AI Security Monitoring - Experience identifying, assessing and developing monitoring controls for AI-related security risks, including enterprise AI platforms such as Microsoft Copilot or Azure AI.
5.Cyber Security Operations Experience - Minimum five years' experience in cyber security operations, supported by strong organisational, communication and stakeholder engagement skills.
Desirable criteria
1.Sigma Rule Development - Experience developing or using Sigma detection rules and translating detections between security platforms.
2.Advanced AI Security Knowledge - Familiarity with AI security frameworks and guidance, including ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10. Relevant industry certifications such as GIAC, SANS, CISSP, GCIA, GCIH or equivalent cyber security qualifications.
3.EDR Platform Expertise - Experience with enterprise EDR technologies such as CrowdStrike, Microsoft Defender for Endpoint and Carbon Black.
4.Automation and Scripting - Proficiency in scripting languages such as Python and Bash to support detection engineering and security automation activities.
Please email your cv in word format along with residency status, security clearance, location, availability details, role Preference, current & expected salary, reason for job change constraints if any - to : jobs@velanconsulting.com.au
Cheers,
Velan Consulting Recruitment Team

Work arrangement
No

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App