LH-07702
buyict×1Senior Cyber Threat Analyst
1 Senior Cyber Threat Analyst
3 agency ads are matched to this contract. Sign up free to see which agency is advertising it, why it matched, and the ad itself.
Sign up freeYour CVs matching this role
0Sign in to see which of your uploaded CVs match this role.
Candidate Search
Find candidates for this role externally, then cache them here.
Sign in to search candidates for this role.
Job description
Threat Detection Engineer develops and maintains the material required to detect threats and incidents across the SOC technology stack. The Threat Detection Engineer (TDE) is responsible for the research, development, testing and maintenance of use case and detection rules. They are to co-ordinate with Cyber Defence Analysts in developing detection content for use in the SIEM, SOAR and EDR platforms. As part of the detection engineering lifecycle the TDE is expected to work in an ITIL and Agile environment, developing process and engineering documentation. The TDE is also responsible for providing threat intelligence sharing to infrastructure and architecture teams in both Cloud and onpremise environments. Key duties and responsibilities This position is responsible for: Develop use cases based off threat models, system risks, vulnerabilities, intelligence, incident reports and industry frameworks Develop the detection rule syntax associated with use cases within the SIEM and EDR technologies Develop playbooks for alert validation by understanding the context in which the detection rule is designed Develop and maintain threat models using industry recognised methodologies such as STRIDE, ATT&CK and attack path analysis to identify detection opportunities and coverage gaps. Assess emerging threats associated with Artificial Intelligence (AI) platforms, services and agents, and develop detection content to identify AI-related misuse, data leakage, prompt injection, model abuse and adversarial activity. Collaborate with architecture and engineering teams to ensure threat modelling outcomes are translated into effective monitoring, detection and response capabilities. Maintain the threat intelligence integrations across the SOC technology stack Conduct in-depth research and analysis for new detection content Collaborate with Cyber Defence Analysts for detection rule tuning Assist with threat model development to inform the detection engineering strategy Assist in the identification of content shortfalls across the detection engineering practice Assist with incident response at that direction of the incident manager Assist in the onboarding of new data sources to meet requirements of use cases Provide evaluation and feedback necessary for improving intelligence production and reporting Provide support to designated exercises, planning activities, and time sensitive operations Criteria The buyer has specified that each candidate must provide a one page pitch to address all criteria specified. This is equal to 5000 characters. Essential criteria 1. Detection Engineering and SIEM Expertise - Demonstrated experience developing detection content across at least two enterprise SIEM platforms (e.g. Splunk, Microsoft Sentinel, QRadar, Elastic). 2. Threat Detection and Response Capability - Experience developing and implementing detections across SIEM, SOAR and EDR platforms, including incident response automation and playbook development. 3. Threat Modelling and Threat Intelligence - Practical experience conducting threat modelling using recognised methodologies (e.g. STRIDE, PASTA, ATT&CK) and translating outcomes into detection and monitoring requirements, supported by a strong understanding of the cyber threat intelligence lifecycle. 4. AI Security Monitoring - Experience identifying, assessing and developing monitoring controls for AI-related security risks, including enterprise AI platforms such as Microsoft Copilot or Azure AI. 5. Cyber Security Operations Experience - Minimum five years' experience in cyber security operations, supported by strong organisational, communication and stakeholder engagement skills. Desirable criteria 1. Sigma Rule Development - Experience developing or using Sigma detection rules and translating detections between security platforms. 2. Advanced AI Security Knowledge - Familiarity with AI security frameworks and guidance, including ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10. Relevant industry certifications such as GIAC, SANS, CISSP, GCIA, GCIH or equivalent cyber security qualifications. 3. EDR Platform Expertise - Experience with enterprise EDR technologies such as CrowdStrike, Microsoft Defender for Endpoint and Carbon Black. 4. Automation and Scripting - Proficiency in scripting languages such as Python and Bash to support detection engineering and security automation activities. Opportunity summary Sellers can submit Up to 2 candidates Number of sellers invited More than 10 Number of candidates submitted Fewer than 10 Send us feedback About Accessibility Privacy Terms of use Disclaimer and copyright An initiative of the Digital Transformation Agency The Australian Government acknowledges the Traditional Owners of Country throughout Australia and acknowledges their continuing connection to land, waters and community. We pay our respects to the people, the cultures and the Elders past and present. © Commonwealth of Australia
3 matches locked
Sign up to see which agency is advertising for this contract, the match evidence, and the ad itself.
Other open contracts for Department of Industry, Science and Resources
- LH-07878(Closed for Invites) Network ArchitectACTcloses in 2 days
- LH-07728(Closed for Invites) Senior .Net Full Stack Software Engineer (Developer)ACTcloses in 4 days
- LH-07776(Closed for invites) ServiceNow Developer Application DeveloperACTcloses in 4 days
- LH-07807Senior Cloud Architect / Cloud Engineercloses in 4 days
- LH-07839(Closed for Invites) Senior Business AnalystACTcloses in 4 days