Skip to main content
AfterDuty

SIEM Specialist and Detection Engineer

BAE Systems Digital Intelligence · Canberra, Australian Capital Territory

Type
Full-time
Posted
16 days ago

Overview

Your incident response and threat assessment experience from policing supports identifying detection use cases.

About this role

BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments.

Role Summary

We are looking for a talented and enthusiastic individual with excellent technical and client-facing skills to act a SIEM specialist who can design and deploy SIEM (Security Information and Event Management) / SOAR (Security Orchestration, Automation and Response) capabilities. They will also be responsible for working with clients to derive the security use cases across a range of platforms and systems to be monitored. These use cases will be based on appropriate MITRE frameworks and client defined insider, vulnerability, business, risk and policy enforcement requirements. The role will range from deploying new solutions and assessing existing capabilities to identify the exposure and coverage gaps.

This role is situated within our Government business, based in Canberra, with substantial time on client sites and will require a government security clearance at NV2 minimum, but candidates will be expected to undergo PV.

Find out more about our award winning Cyber Security solutions: http://www.baesystems.com/en/cybersecurity/solutions/by-business-objective/detect-and-monitor-for-cyber-attacks

What You’ll Be Doing

  • Oversee deployment / implementation activities ensuring that entry criteria are met, all planned activities are completed and that rollback plans are initiated where required.
  • Identify use cases, plan development, deployment, testing and release into production.
  • Produce, update and maintain corresponding playbooks for detection and automation content.
  • Develop, test and deploy updated and new content across the monitored estate in liaison with the client.
  • Maintain existing detection content to ensure it remains current and relevant to the monitored estate, and that false positives are kept to a minimum.
  • Assess the effectiveness of new / updated rules and analytics to feed into future development activities.
  • Review and approve all required documentation as part of a release or change including design, deployment, configuration and administration guides.
  • Support attack, threat and exposure modelling to identify new attack paths and determine suitable detection content to detect path being exploited.
  • Support threat hunting and content enrichment.
  • Integrate solutions with vulnerability and asset and configuration management and other tools to enrich efficacy of the solution.
  • Obtain authorisation for implementing releases and changes through the Change Management process.
  • The strategic focus of the role is to ensure that the detection and monitoring technology remains optimised, current and tailored to the changing threat landscape, client risk position and technology in use.
  • The role is a cyber technical specialist with deep knowledge of the Cyber Monitoring technologies and cyber threat tools, tactics, techniques and procedures.

Technical

What we’re looking for

  • Strong knowledge of how Azure and AWS security functions work as security controls as well as detection tools to protect large cloud estates
  • Production of content and playbooks on Sentinel and Splunk to detect security breaches and recognise the importance of threat led Use Cases.
  • Knowledge of SIEM/SOAR tools (Splunk and Sentinel at a minimum) and other appropriate tooling e.g. SOAR, Threat Intelligence, traffic analysis tools etc. to identify signs of an intrusion, and advise where new/improved tooling could enhance the SOC operation.
  • Deep knowledge and experience of operational ICT service delivery management.
  • Working with a range of security tooling/technology.
  • Strong understanding of security architecture, in particular networking.
  • Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence.
  • Understand TCP/IP component layers to identify normal and abnormal traffic.
  • Experience of Splunk (with ES) &/or Sentinel.
  • Experience developing SIEM/SOAR content desirable.

Non-technical

  • Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others, including briefing skills and report writing.
  • Coaching mindset – helping and mentoring the team.
  • Security process development.
  • Able to understand and adapt to different cultures and hierarchical structures.
  • Self-starter and capable of independent working.
  • Team player and adept at working in multi-disciplinary and diverse teams.

Why BAE Systems?

This is a place where you’ll be able to make a real difference. You’ll be part of an inclusive culture that values diversity of thought, rewards integrity, and merit, and where you’ll be empowered to fulfil your potential. We welcome people from all backgrounds and want to make sure that our recruitment processes are as inclusive as possible. If you have a disability or health condition (for example dyslexia, autism, an anxiety disorder etc.) that may affect your performance in certain assessment types, please speak to your recruiter about potential reasonable adjustments.

Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Canberra

Why this fits a police background

  • Police experience explicitly valued
  • Intelligence & OSINT
  • Training & coaching delivery

More cyber security & digital forensics jobs for ex-police

  • GRC and Advisory Consultant

    DXC Technology · Canberra

    Full-time

    Job Description DXC Technology (NYSE: DXC) is a leading enterprise technology and innovation partner delivering software, services, and solutions to global enterprises and public sector organisations — helping them harness AI to drive outcomes at a time of exponential change with speed.

    Posted 5 days ago

  • Senior Cyber Security Governance Analyst

    radk tech pty ltd · Canberra

    Contract

    Your analytical discipline and experience with strict frameworks (e.g., PACE, CPIA) map well to governance and compliance in cyber security.

    Posted 6 days ago

  • Full-time

    Our Mission At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts.

    Posted 7 days ago

  • ICT Security Analyst

    Fujitsu · Canberra

    Full-time

    Your incident response and investigative skills from policing translate directly to managing security incidents and access controls.

    Posted 8 days ago