Cyber Security Engineer - Detection Engineering (Microsoft Sentinel)
Summary
Detection engineering role at a large Australian critical infrastructure operator in North Sydney: build and tune Microsoft Sentinel analytics rules and Defender custom detections, write KQL for threat hunting and coverage analysis, and own the detection logic a managed SOC operates. Hybrid, three days onsite; AU citizens/PRs only.
Salary: Yes
About the RoleOur client is one of Australia's largest private operators in critical infrastructure, based in North Sydney. They're growing out their internal security function and looking for a Cyber Security Engineer to build and own their Microsoft Sentinel and Defender detection capability.
This is an engineering role, not a SOC or triage position. The organisation runs a managed SOC for alert monitoring and response, so this role sits above that, writing and tuning detection logic, developing analytical rules, and improving platform coverage across Sentinel and Defender.
What You'll Do
- Design, build and tune Microsoft Sentinel analytics rules and Defender custom detections
- Write and maintain KQL queries for threat hunting, log coverage analysis and detection logic
- Improve platform coverage and reduce false positives across the Microsoft security stack
- Work closely with the managed SOC provider, owning the detection logic they operate against
- Translate purple team and red team findings into new or tuned detections
- Communicate detection and risk findings to internal technical stakeholders
- Hands-on experience building and tuning Sentinel analytics rules and/or Defender detections, not just responding to alerts
- Strong working knowledge of KQL
- Solid understanding of Windows log sources and how security telemetry actually reaches a SIEM
- Comfortable working directly with a managed SOC provider rather than running triage yourself
- Australian citizens or permanent residents only. We are unable to offer visa sponsorship for this role
- Based in Sydney and able to work onsite three days a week
- $160,000 base + superannuation + 20% performance-linked STIP
- Hybrid working, three days a week onsite in North Sydney
- The chance to build detection capability from the ground up at a genuine critical infrastructure operator