Security Engineer - Microsoft Sentinel / SIEM
Summary
A hands-on Security Engineer role building and running the SIEM capability in Microsoft Sentinel within a classified Azure environment for an organisation working in national security and defence. Day to day involves detection engineering, KQL threat hunting, alert tuning, automation playbooks and incident response support.
Salary: $140,000-$180,000 + superannuation
An established international organisation operating across national security, defence and advanced technology is seeking an experienced Security Engineer to strengthen its Australian cyber security capability.This is a hands-on role focused on Microsoft Sentinel, security monitoring and detection engineering within a classified Azure environment. You will help design, implement and continuously improve the organisation’s SIEM capability, increasing visibility, strengthening threat detection and supporting effective incident response.
The Role
Working closely with security operations, infrastructure and application teams, you will:
- Administer, configure and maintain Microsoft Sentinel and Azure security-monitoring platforms
- Design and improve SIEM use cases, analytics rules and detection logic
- Tune alerts to improve detection quality and reduce false positives
- Develop automated response playbooks using Azure Logic Apps and Sentinel automation
- Conduct threat hunting using KQL, Microsoft Sentinel and threat-intelligence sources
- Investigate security alerts and support cyber incident response
- Build dashboards, workbooks and operational security reporting
- Integrate new data sources across cloud, infrastructure, network and third-party platforms
- Map detection capabilities against MITRE ATT&CK
- Identify gaps in monitoring and improve detection coverage
- Support security audits, assessments and compliance activities
You will bring:
- At least five years’ experience across cyber security, security operations, detection engineering or SIEM administration
- Strong hands-on experience with Microsoft Sentinel
- Advanced Azure Log Analytics and Kusto Query Language skills
- Experience developing analytics rules, workbooks, watchlists, data connectors and SIEM use cases
- Demonstrated experience onboarding and integrating complex log sources
- Strong knowledge of threat detection, security monitoring and incident response
- Experience with security automation, orchestration and response principles
- Knowledge of MITRE ATT&CK and its application to threat hunting and detection engineering
- The ability to analyse complex security events and convert findings into practical improvements
- The ability to obtain and maintain an Australian Government security clearance
Experience across the broader Microsoft security ecosystem—including Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Cloud and Entra ID-will also be advantageous.
Relevant certifications may include SC-200, SC-100, AZ-500, AZ-104, Security+, CCSP, GCDA or GCIA; however, practical experience will be the primary consideration.
What’s on Offer
- Salary between $140,000 and $180,000 plus superannuation
- Permanent position with hybrid working
- Annual incentive plan
- Private health insurance
- Generous annual leave
- Paid parental leave
- Life, disability and income-protection insurance
- Employee assistance program
- Novated vehicle leasing
- The opportunity to help shape a growing Australian cyber security capability