Skip to main content
AfterDuty

Cyber Security Engineer

ORRO · Sydney, New South Wales

Type
Full-time
Posted
41 days ago

Overview

This role demands deep, hands-on technical expertise in SentinelOne, SIEM configuration, and cloud security that a typical policing background does not provide without years of retraining. While your investigative mindset and incident-response discipline are relevant, the core requirements are engineering-focused and customer-facing in a commercial consulting context, which is a significant departure from operational policing. Unless you have already built a second career in cyber security, this is not a realistic entry point.

About this role

Sydney | Brisbane | Melbourne | Hybrid Work Model | Competitive base + super + benefits

*We are not your typical cyber team.*We are collaborative, curious and customer obsessed, and we are looking for a Cyber Security Engineer specialising in SentinelOne to join our Cyber Engineering team. You will work directly with customers, owning and delivering security engagements end to end across EDR, XDR, SIEM and cloud native security operations. From scoping through to deployment and reporting, you will help strengthen customer security postures while managing your own engagements and building trusted advisory relationships across a diverse client base.

About Orro

We're an Australian success story, now close to 500 people strong, delivering secure, end to end digital solutions across cloud, collaboration, cyber security, data services and network infrastructure, all backed by over 20 years of experience. Trusted by some of Australia's biggest brands, Orro leads the way in designing, building and operating digital infrastructure that delivers greater efficiency, agility, performance and resilience. Our solutions take the stress out of tech for more than 400 businesses and over 20 million Australians every single day.

Our mission? To create "future now" solutions making it faster, simpler and safer for people to access, store and share information, wherever they are and whoever they're with. But more than that, we know that real impact comes from connecting people, not just machines. That's why we take the time to understand our clients; how they work, what matters to them, and where they're headed so we can deliver not just what they need today, but what they'll need next.

With offices in Sydney, Melbourne, Canberra, Brisbane and Perth, and teams across New Zealand, the Philippines and the UK, Orro is known for delivering future ready solutions, backed by deep expertise, genuine human insight and lasting partnerships.

What You'll Be Doing

In this role, you will deliver consulting led cyber security services with a SentinelOne specialisation across a range of customer environments. Working closely with the Cyber Security Engineering Manager and the wider cyber team, you will plan and execute security engagements, manage delivery milestones, and provide hands on implementation and advisory support across security and cloud platforms. You will balance deep technical expertise with strong customer engagement, ensuring every engagement is delivered efficiently, professionally, and to a high standard.

  • Lead and own customer engagements end to end, from scoping and kickoff through to delivery, as the trusted technical point of contact
  • Design, deploy, configure and optimise SentinelOne and SIEM environments, including data connector integration, detection rules, Power Query and custom alerting
  • Configure and manage automation, incident response playbooks and automation rules across SIEM and SOAR
  • Build workbooks, dashboards and UEBA configurations to sharpen threat visibility and operational insight
  • Conduct security operations assessments and threat detection capability reviews, providing pragmatic best practice guidance
  • Produce clear technical documentation and customer ready reports to a consistently high standard

What You'll Bring

The Essentials

  • Minimum 2 years of experience in a customer facing or consulting cyber security role, with strong communication skills and the ability to manage multiple engagements at the same time
  • Hands on experience with SentinelOne across data connector configuration, detection rules, hyperautomation, and workbook or dashboard development
  • Solid understanding of Microsoft Azure, cloud security fundamentals, and SIEM based threat detection and incident response

Bonus Points

  • Additional SentinelOne certifications such as SIREN or Paladin
  • Advanced threat hunting experience and working knowledge of adversary TTPs
  • Scripting skills across Power Query, PowerShell, Python or Bash, and experience across Windows and Linux environments

Even if you don't tick every box, don't let that hold you back. If this sounds like your kind of challenge, we'd genuinely love to hear from you.

Why Orro?

At Orro, we're proud to support our people and the people who matter most to them in meaningful and inclusive ways. From public holiday swaps that embrace family and cultural diversity, to generous parental and caregiver leave, flexible work options, and company wide mentoring, we're here to help you thrive at every stage of life. We also invest in the future through our Emerging Leaders Development Program, nurturing the next generation of talent from within. On top of that, you'll enjoy 3 days of paid volunteer leave each year, novated leasing, employee discounts, and full access to our wellbeing platform packed with expert fitness plans, nutrition tips, and tools to help you feel your best, inside and out.

Note: The role is subject to state and federal police background checks. Applicants must have the unrestricted right to work in Australia. Visa sponsorship is not available for this position.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Sydney

Why this fits a police background

  • Police experience explicitly valued
  • Incident command & response
  • Security operations
  • Training & coaching delivery

More cyber security & digital forensics jobs for ex-police

  • Your background running operational units and coordinating multi-agency responses maps directly onto leading national support functions and ensuring consistent, secure operations across multiple sites. You're used to setting clear accountabilities, managing risk, and driving continuous improvement, which is exactly what this role requires. Your experience with compliance and governance, from PACE to internal procedures, means you can bring structure and discipline from day one.

    Posted 2 days ago

  • Full-time

    Your experience working to strict regulatory frameworks like PACE and CPIA gives you a natural grounding in compliance and assurance, which is exactly what this cyber security GRC role demands. You've spent years maintaining accurate records, managing risk registers, and engaging with diverse stakeholders under pressure, so coordinating audits and driving adherence to standards like ISO 27001 will feel familiar. The role is a development opportunity, so your proven attention to detail and process-oriented mindset will let you build the specific cyber security knowledge on the job.

    Posted 5 days ago

  • Integrity and Security Analyst

    NSW Government · Sydney

    Full-time

    A$133,348 – A$146,945Estimated

    This role directly leverages your operational intelligence experience from policing — you'll produce intelligence products that identify security risks and inform frontline decisions, just as you did under the National Intelligence Model. Your ability to assess threats, manage multi-agency coordination, and apply legislative frameworks like PACE or RIPA is exactly what the NSW Electoral Commission needs to safeguard election integrity. The requirement for 10+ years in law enforcement confirms this is a role built for your background, not a sideways move into a completely new field.

    Posted 5 days ago

  • Full-time

    Your investigative experience from policing—evidence handling, chain of custody, case file management, and conducting structured interviews—maps directly onto the core responsibilities of this insider threat role. You are used to working with sensitive information, maintaining confidentiality, and producing defensible reports for multiple stakeholders, which is exactly what this position demands. The analytical and risk-assessment skills you developed through intelligence-led policing and managing complex investigations will let you hit the ground running in identifying and mitigating insider

    Posted 7 days ago