Senior SOC Analyst / Detection Engineer
Summary
Senior SOC Analyst / Detection Engineer investigates real security incidents, builds and tunes detections, automates workflows, and hunts threats using CrowdStrike Falcon SIEM/EDR and SOAR tools.
Secure Agility is an Australian, Sydney-based IT managed services and cybersecurity provider. We help Australian organisations expose risk, prevent threats, detect incidents, and respond quickly — and we run the cloud, infrastructure, and networks that keep them operating.
We deliver outcomes across:
Cyber Security (GRC, SOC, IR, Penetration Testing)
Cloud & Infrastructure (AWS, Azure, private cloud, hybrid, Kubernetes)
AI & IoT (edge, automation, data integration)
Digital Advisory & Managed Services
Telco & Secure Hosting
The Opportunity - Go beyond monitoring alerts
Secure Agility is looking for a Senior SOC Analyst / Detection Engineer to join our Security Operations Centre in Sydney.
This is a hands-on security role for someone who wants more than sitting in a queue processing alerts.
You'll work across multiple customer environments, investigate real security incidents, engineer and tune detections, build automation, hunt for threats and help improve the security platforms and services our customers rely on.
CrowdStrike Falcon Next-Gen SIEM and Falcon EDR are at the heart of the role, but your exposure will extend across identity, cloud, network, email, vulnerability management and other security technologies.
Just as importantly, you'll have the opportunity to influence how we do things. If a detection can be better, a process can be automated or a customer's security capability can be improved, we want you to help make it happen.
What you'll do
You'll work across the day-to-day operation and continuous improvement of Secure Agility's multi-tenant SOC and dedicated customer security environments.
Your responsibilities will include:
Monitoring, investigating and responding to security events and incidents across multiple customer environments
Analysing telemetry across endpoint, identity, network, cloud and email sources
Performing incident triage, investigation, response, escalation and proactive threat hunting
Operating and administering CrowdStrike Falcon Next-Gen SIEM environments
Building, testing and tuning detection content to improve coverage, signal quality and reduce false positives
Managing security telemetry, integrations, data sources and ingestion issues
Building and optimising SOAR workflows using CrowdStrike Falcon Fusion
Investigating endpoint threats using Falcon EDR and supporting containment and remediation
Operating vulnerability management services using Tenable and other supported platforms
Monitoring the health and effectiveness of customer security platforms and integrations
Troubleshooting complex platform, telemetry and integration issues
Identifying opportunities to automate SOC processes and improve operational efficiency
Communicating security findings, incidents and recommended actions directly to customers
Contributing to security implementations, migrations and Professional Services projects
What you'll bring (must-haves)
You'll have demonstrated experience working in a SOC, MDR or security operations environment and strong hands-on security investigation skills.
We're particularly interested in:
4+ years in SOC, security operations, or detection engineering at L2/L3
Strong hands-on experience with CrowdStrike Falcon Next-Gen SIEM, including investigation, administration and detection tuning
Strong hands-on experience with CrowdStrike Falcon EDR and incident investigation
Experience developing, tuning and maintaining SIEM detection content
Experience building SOAR workflows, preferably using CrowdStrike Falcon Fusion
Experience with Tenable or another enterprise vulnerability management platform
Experience managing security telemetry, integrations and log ingestion
Strong understanding of endpoint, identity, network, cloud and email security
Understanding of common attacker techniques and incident response methodologies
Working knowledge of MITRE ATT&CK and its application to detection and security monitoring
Understanding of Windows, Active Directory, Entra ID and cloud environments
Strong analytical and troubleshooting skills
The ability to manage competing priorities across multiple customer environments
Strong written and verbal communication skills, including the ability to explain technical security issues clearly to customers
Highly valued
Broader CrowdStrike Falcon platform experience
Experience working in an MSSP, MDR, managed services or multi-tenant SOC
Experience integrating security telemetry using Syslog, CEF or APIs
Python, PowerShell or other scripting and automation capability
AWS or Microsoft Azure security experience
Experience with Netskope, Proofpoint, Mimecast, Abnormal Security, ExtraHop, Airlock Digital or Arctic Wolf
Experience contributing to customer-facing security implementations or Professional Services engagements
An existing Australian Government NV1 or higher security clearance
Certifications: CrowdStrike CCFA/CCFR/CCSE, Microsoft SC-200, GIAC GCDA/GCIA, Security+, CySA+
Why join Secure Agility
Work with a respected Australian technology services business with deep public-sector and enterprise relationships
Exposure to enterprise-scale customer environments and current-generation tooling not single-environment legacy SIEM work
Direct working relationship with CrowdStrike Australia, including a named TAM and active partner engagement
Senior team that does the work alongside you, not above you. Hands-on leadership across MD, CIO, Security Practice Lead, and Principal Cyber Advisor
Genuine growth paths into detection engineering lead, threat hunting, or security advisory tracks
Be involved in shaping how we continue to build and operate our SOC model, not just executing inside it
Professional development budget vendor certifications fully funded
Collaborative team culture and flexible hybrid working from Sydney CBD
What success looks like
You'll know you're succeeding when:
Security incidents are investigated thoroughly and responded to within agreed service levels
Customers receive clear, timely and technically sound security advice
Detections generate better security signals with less unnecessary noise
Automation reduces repetitive analyst effort and improves response consistency
Security platforms, telemetry and integrations remain healthy and effective
Vulnerability management produces meaningful, actionable information for customers
You're continually finding ways to improve our SOC capability and our customers' security outcomes
You're sharing knowledge and helping develop the capability of the wider team
How to apply
Please attach your CV and a concise 1–2 page SOC Experience Summary covering two significant security incidents, investigations, or SOC initiatives you have been directly involved in