Security Operations Lead — Detection, CTEM & AI Security
We’re hiring a Security Operations Lead to run detection engineering and continuous threat exposure management across our SOC and our customers’ environments.
This is a technical leadership role. You’ll still be hands on the tooling, but you’ll own how we detect, how we measure exposure, and how we report it to customers. You’ll set the standard the rest of the team works to.
Why now
The security problem is changing faster than it has in fifteen years.
AI agents are landing in production across Australian enterprises, usually faster than anyone can inventory them. They execute code, move data and act at machine speed with no human in the loop, and they look like legitimate activity to most tooling. CrowdStrike launched Falcon Guardian at Fal.Con this month to address exactly this, and we’re one of the partners taking it to market in Australia.
At the same time, our customers have moved past “how many criticals do we have.” They want continuous exposure management: what’s actually reachable, what’s actually exploitable, what actually matters this week.
We need someone who can build both capabilities and explain them to a board.
What you’ll own
• Detection engineering. Coverage, signal quality, and false positive reduction across Falcon Next-Gen SIEM. You set the content standard and review what the team ships.
• CTEM and vulnerability programs, end to end. Scoping, discovery, prioritisation by real exploitability, remediation tracking, and the reporting customers actually read.
• Agentic and AI exposure. Standing up our AI Detection and Response practice, starting with agent discovery. Most customers cannot tell you what’s running today.
• Automation. SOAR workflows in Falcon Fusion that measurably reduce analyst effort.
• The team. Mentoring L1/L2 analysts, lifting investigation quality, and being the escalation point on serious incidents.
• The customer relationship. Running technical reviews, presenting findings to executive stakeholders, and being the person a CISO wants in the room.
What you’ll bring
Non-negotiable:
• Current CrowdStrike certification — CCFA, CCFR or CCSE. We won’t consider applications without one.
• Deep hands-on Falcon platform experience: Next-Gen SIEM, EDR, Fusion.
• Demonstrated ownership of a CTEM or vulnerability management program from detection through to executive reporting.
• Exceptional written and spoken English, with genuine consulting presence. You’ll be presenting to CIOs and CISOs and writing reports that go to boards.
• 6+ years in security operations, with time at L3 or lead level.
Strongly valued:
• Netskope SSE, ExtraHop, Proofpoint, Abnormal Security.
• MSSP, MDR or multi-tenant SOC background.
• Scripting for automation: Python or PowerShell.
• Identity and cloud depth: Entra ID, Active Directory, AWS or Azure.
• Australian Government NV1 clearance or eligibility.
We’re less interested in the length of your certification list than in whether you can explain a detection decision and defend it.
Why Secure Agility
• Direct working relationship with CrowdStrike Australia, including a named TAM. You’ll be close to the product roadmap, not two steps removed from it.
• Genuine influence over how our SOC operates. This role is being created because we want it changed, not maintained.
• Hands-on leadership team. MD, CIO and Principal Cyber Advisor all work the problem with you.
• Vendor certifications fully funded.
• Australian-owned, Sydney-based, with deep public sector and enterprise relationships.
How to apply
Please attach your CV and a concise 1–2 page SOC Experience Summary covering two significant security incidents, investigations, or SOC initiatives you have been directly involved in