Skip to main content
AfterDuty

Cyber Security Engineer

Macquarie Technology Group · Canberra, Australian Capital Territory

Type
Full-time
Posted
3 days ago

Overview

Your incident response and investigative judgement apply to SOC triage, escalation, and evidence handling.

About this role

About Us

We’re growing, not slowing, here at Macquarie Technology Group because we’re passionate about doing things differently. We want to challenge the industry and look for better ways of doing things. As a team, Macquarie Government are hardworking, results and success focused. We also take the time to celebrate our success and make sure our people are doing work that makes a difference.

We believe that collaboration & team connection is key for success. This role will be based in Canberra on-site with one of our clients.

We require security clearance for this role you must be an Australian citizen to be eligible to obtain a security clearance or ideally already hold NV1 security clearance.

The Opportunity

We’re looking for a Security Engineer to join our growing security team in Canberra. This is a great opportunity for someone with hands-on SOC experience who is ready for more ownership, broader exposure, and the chance to build their capability in a high-performing SOC environment.

You’ll be working closely with experienced security professionals, building your Splunk capability, sharpening your incident response skills, and helping protect environments that genuinely matter. If you’re hungry to learn, humble in how you work, and smart in how you solve problems, this could be a brilliant next step.

What You'll Be Doing.

  • Monitoring, triaging, investigating, and responding to security alerts and incidents within our Security Operations Centre (SOC)
  • Onboarding and integrating new log sources into Splunk, including writing and tuning data inputs, parsing configurations, field extractions, and validating data quality
  • Developing, refining, and optimising Splunk searches, dashboards, alerts, and detection logic to improve threat detection capability
  • Investigating security events, identifying patterns, determining severity, and escalating incidents in line with established playbooks and procedures
  • Contributing to the continuous improvement and uplift of SOC processes, runbooks, and detection logic
  • Collaborating with internal cloud, network, endpoint, and engineering teams to improve log coverage and security monitoring across environments
  • Keeping up with the evolving threat landscape and bringing practical ideas to improve the team’s capability

About You.

  • A degree in Cyber Security, Information Technology, Computer Science, or a related field
  • 18 months to 4 years of hands-on SOC experience, including practical experience onboarding, validating, and tuning log sources in Splunk
  • Strong working knowledge of common attack techniques, threat indicators, and the MITRE ATT&CK framework, with the ability to apply this knowledge during investigations
  • Experience working with security technologies such as firewalls, IDS/IPS, endpoint detection tools, cloud security platforms, and related monitoring tools
  • Confident analytical and problem-solving skills, with the ability to assess complex security events and make sound escalation decisions
  • Clear written and verbal communication skills, with the ability to explain incidents, risks, and findings to both technical and non-technical stakeholders

Nice to Have.

  • Splunk certifications (e.g., Splunk Core Certified User or Power User)
  • Exposure to SOAR platforms or security automation
  • Experience with cloud environments (AWS, Azure, or GCP)
  • Relevant industry certifications such as CompTIA Security+, CySA+, or equivalent

Candidates *must*be Australian citizens and eligible to obtain or hold an Australian Government security clearance.

If this role excites you Apply Now!

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Canberra

Why this fits a police background

  • Police experience explicitly valued
  • Incident command & response
  • Investigative casework
  • Security operations

More cyber security & digital forensics jobs for ex-police

  • Cyber Security Officer

    Brennan IT · Canberra

    Full-time

    Your experience with evidence handling and investigative discipline translates directly into GRC audit and assurance work.

    Posted 5 days ago

  • eSafety - Cyber Security Analyst, APS 6

    Australian Communications and Media Authority · Canberra

    Full-time

    Your digital forensics and cybercrime investigative experience gives you an edge in threat detection and incident response.

    Posted 6 days ago

  • Senior Network Security Engineer

    Airservices Australia · Canberra

    Full-time

    • Work with industry-leading network security technologies in a complex, always-on environment where your expertise contributes to secure, resilient and high-performing network services • Fixed term contract|2 Years • Brisbane, Canberra, Melbourne or Sydney Summary Join Airservices Australia's…

    Posted 6 days ago

  • Cyber Security Analyst

    SKNG Services · Canberra

    Contract

    Key information • Estimated Start Date: 01/09/2026 • Initial contract duration: 12 months • Extensions term: 12 months • Location: ACT • Working arrangements: Onsite • Security clearance: NV1 Why SKNG representation? When you choose SKNG, you are making a strategic investment in your professional…

    Posted 7 days ago