About this role
Senior Cyber Security Operations Engineer
Employment Type: Full-time, Permanent
Role Summary
I am seeking a Senior Cyber Security Operations Engineer to drive its defensive cybersecurity operations. In this high-impact position, you will act as the primary subject matter expert across threat detection, incident handling, cloud posture, and defensive automation across a modern, multi-cloud environment.
Working closely with engineering and operational leads, you will elevate our internal SOC capabilities, refine monitoring infrastructure, and ensure high operational resilience.
Core Responsibilities
- Defensive Automation & Infrastructure: Drive the architecture and continuous tuning of enterprise SIEM, EDR, and identity protection tools. Build automated response playbooks to streamline triage and accelerate incident response.
- Incident Escalation & Threat Mitigation: Serve as the principal technical contact for critical security alerts, directing host containment, account isolation, and post-incident remediation.
- Proactive Threat Detection: Design and implement custom detection logic, hunt hypotheses, and correlation rules to uncover emerging threats.
- Security Control Engineering: Collaborate with infrastructure, development, and cloud teams to integrate Secure-by-Design principles into organizational change pipelines.
- Process & Compliance Maturity: Develop standard operating procedures (SOPs) and align operational capabilities with recognized security frameworks.
Requirements
- Proven Experience: 5+ years in dedicated cybersecurity roles, including 3+ years operating as a senior engineer or technical lead within an enterprise SecOps or SOC environment.
- Technical Mastery: Deep hands-on experience configuring and maintaining enterprise XDR, SIEM, and cloud identity platforms.
- Detection & Scripting: Strong capability writing custom detection rules (KQL or similar query languages) and building SOAR workflows.
- Vulnerability & Cloud Operations: Demonstrated background in vulnerability management, risk-based prioritization, and core cloud security principles (Azure/AWS).
- Framework Exposure: Working knowledge of standards such as NIST, ISO 27001, MITRE ATT&CK, or Essential Eight.
- Certifications: CISSP, SC-200, or equivalent senior security credentials highly regarded.
About cyber security & digital forensics roles for ex-police
Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.
See all cyber security & digital forensics jobs in Sydney →Why this fits a police background
- Incident command & response
- Working to legislation & regulation
- Security operations