Employment OS for your Business

Security Engineer

Security Operations Services • North Sydney, New South Wales 2060, Australia • Full-time
AI Job Summary
  • Demonstrated experience in security engineering, detection engineering, or senior SOC role.
  • Hands-on experience with Elastic SIEM and/or Microsoft Sentinel (KQL) building high-fidelity detection rules.
  • Proficiency in Python for scripting, automation, and tooling development to accelerate SOC workflows.

Role Type

Permanent • Full-time • Mid-level Senior

Pay Rate

$140,000 AUD – $160,000 AUD (Annum)

Description

About the Role

Excite Cyber is looking for a Security Engineer to join our Security Operations Centre. This is a diverse role and we are looking for someone who brings an engineering mindset to security problems. You will work alongside the core analyst team to strengthen detection, accelerate incident response, and continuously improve the way we operate. If you see a broken process and instinctively want to rebuild it, this role is for you.

What You’ll Do

· Build, test, and maintain high-fidelity detection rules across Elastic SIEM and Microsoft Sentinel (KQL), with a focus on reducing noise and improving signal quality.

· Advance our detection-as-code capability; version-controlled rules, automated testing pipelines, and CI/CD-driven deployment of detection content.

· Support the analyst team with alert triage, escalation, and hands-on incident response during high-severity events.

· Conduct proactive threat hunts informed by threat intelligence, MITRE ATT&CK, and your own curiosity about customer environments.

· Tune and optimise existing detections and SIEM data pipelines to keep pace with changing infrastructure and threat landscape.

· Write Python tooling and automation to eliminate repetitive tasks and accelerate SOC workflows.

· Collaborate with infrastructure and cloud teams to ensure logging coverage and visibility across cloud environments (AWS, Azure, or GCP).

· Engage directly with customers to understand their environment and the telemetry and data sources available for the purpose of detection & response.

· Enable our SOC to leverage technology, including AI, to become more efficient & effective for our customers.

What You Bring

· Demonstrated experience in a security engineering, detection engineering, or senior SOC role.

· Strong hands-on experience with Elastic SIEM and/or Microsoft Sentinel – highly preferred.

· Familiarity with leading XDR platforms, Microsoft Defender, Trend Micro Vision One, Crowdstrike.

· Proficiency in Python for scripting, automation, and tooling development (required).

· Solid understanding of cloud infrastructure (AWS, Azure) and the security telemetry these platforms produce.

· Experience with detection-as-code practices, CI/CD pipelines, and version control (Git).

· Familiarity with MITRE ATT&CK and structured approaches to threat modelling and adversary emulation.

· An engineering mindset above all – you attack problems based on their unique circumstances, think in systems, and build scalable solutions.

Nice to Have

· Experience with SOAR platforms, log enrichment, or data pipeline engineering (e.g., Logstash, Cribl).

· Relevant certifications (e.g., GCIA, GCIH, GCED, AZ-500, AWS Security Specialty).

· Contributions to open-source security tooling or community detection rule sets.

Why Excite Cyber

You will join a team that values creative problem-solving over checkbox compliance. We invest in our people, our tooling, and our craft. We want engineers who push us forward. If you thrive on making things better and want real ownership of the security engineering function inside a growing SOC, we’d love to hear from you.