Cybersecurity Engineer
Summary
Hands-on cybersecurity engineer building threat detection capabilities for enterprise environments using DevSecOps, Detection-as-Code, SIEM, SOAR, EDR, NDR, and cybersecurity data engineering.
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Cybersecurity Engineer based in Australia.
This is a hands-on cybersecurity engineering role focused on building modern, high-fidelity threat detection capabilities for enterprise environments.
You’ll work directly with customer teams to design and improve security monitoring across cloud, IT, and OT environments.
The role combines DevSecOps, Detection-as-Code, SIEM, SOAR, EDR, NDR, and cybersecurity data engineering.
You’ll turn real-time security data into actionable detections, automated response workflows, and measurable improvements in security posture.
You’ll also help customers close detection gaps, strengthen operational processes, and adapt their defenses to emerging threats.
Working in a collaborative, engineering-led environment, you’ll have significant autonomy to solve complex problems and influence security strategy.
This is an opportunity to make a tangible impact while working at the forefront of cybersecurity detection and automation.
Accountabilities
- Design, develop, and optimize threat detection capabilities using SIEM, SOAR, EDR, NDR, real-time streaming, and related cybersecurity technologies.
- Build detection rules, correlation logic, enrichment pipelines, and automated workflows that improve threat detection accuracy and alert fidelity.
- Develop automation playbooks supporting incident triage, investigation, and response.
- Design and maintain cybersecurity data solutions, including data onboarding, normalization, enrichment, SOPs, system maintenance, compliance, and recoverability.
- Align detection content with customer-specific security use cases and provide meaningful metrics on threats affecting their environments.
- Partner closely with customer Cybersecurity Operations Center, Incident Response, IT, and Operational Technology teams to identify gaps and ensure detections are actionable.
- Develop dashboards and data exploration capabilities that help cybersecurity, IT, and OT teams understand and respond to security events.
- Integrate diverse IT, OT, and business applications into security monitoring and SIEM environments.
- Monitor emerging cybersecurity threats, attack techniques, and industry developments, continuously adapting detection strategies and security frameworks.
- Document, communicate, and operationalize cybersecurity technologies, processes, and detection strategies across customer organizations.
- Contribute to the evolution of cybersecurity services and help identify opportunities to improve security monitoring programs and customer outcomes.
- 6+ years of professional cybersecurity experience, particularly across log streaming, cybersecurity data lakes or warehouses, SOAR, SIEM engineering and operations, threat detection, or security data engineering.
- Strong understanding of SIEM architecture, administration, engineering, and operational processes, including integrating data from diverse IT, OT, and business systems.
- Hands-on experience with cybersecurity data engineering, statistical analysis, threat detection development, or related data-driven security practices.
- Practical programming experience with Python, SQL, and Apache Spark.
- Solid knowledge of common attack techniques and how they translate into practical detection strategies.
- Strong cloud, cybersecurity, SIEM, and data engineering fundamentals, with an understanding of modern DevSecOps and Detection-as-Code approaches.
- Bachelor’s degree in Management Information Systems, Computer Science, or a related technical discipline.
- Demonstrated ability to document, socialize, and operationalize cybersecurity technologies, processes, and frameworks.
- Strong written and verbal communication skills, with the ability to explain complex technical concepts to stakeholders with varying levels of technical expertise.
- Proven ability to collaborate across cybersecurity, IT, OT, engineering, and customer teams while building trusted cross-functional relationships.
- Self-driven, entrepreneurial, and comfortable taking ownership in a fast-paced environment with limited bureaucracy.
- Genuine enthusiasm for cybersecurity and a commitment to continuously learning about emerging threats, technologies, tools, and best practices.
- Experience with platforms such as Databricks, Cribl, Tines, or other cybersecurity lakehouse technologies is a plus.
- 100% remote work from Australia.
- Opportunity to work directly with enterprise customers on complex cybersecurity challenges.
- Hands-on exposure to modern security technologies spanning SIEM, SOAR, EDR, NDR, real-time streaming, and security data platforms.
- High degree of autonomy and ownership in an engineering-led environment.
- Opportunity to contribute to the development and evolution of modern cybersecurity detection and monitoring services.
- Collaborative culture that encourages creativity, technical curiosity, open communication, and challenging conventional approaches.
- Exposure to diverse cybersecurity environments across cloud, enterprise IT, and operational technology.
- Opportunity to continuously develop expertise in emerging cybersecurity threats, detection engineering, automation, and DevSecOps.