Australian Capital Territory, Australia

EL1 Cyber Security

 Job Description:

Australian Citizens residing in Australia only respond.

Job details

This position is for a dedicated Security Engineer within the IT Security Team is a hands-on role pivotal to uplifting our security operations maturity.

The Security Engineer will be a skilled cybersecurity professional responsible for uplifting Microsoft Sentinel, security tooling and security operations processes.

The successful candidate will thrive in a small team environment where they can shape strategy initiatives and be hands on in implementing outcomes. As such, they have experience managing end-to-end cyber security operations and will have a strong understanding of all components of cyber security management, particularly in the government context.

Our ideal candidate will be an expert collaborator and will see themselves as a mentor to junior team members, partner to the business, project teams and other areas of IT, as well as with ACMA and cross-government counterparts to deliver effective outcomes.

Key duties and responsibilities

  • Configure and troubleshoot log source integrations into the SIEM.
  • Develop alerting rules and threat response playbooks for systems integrating with Microsoft Sentinel.
  • Build and refine KQL queries to support investigations, threat hunting, and traffic analysis.
  • Administer, and maintain cybersecurity tooling including SIEM, WAF, DLP, vulnerability scanners, Proxy, Application Whitelisting, including integration of new data sources and automation of threat responses.
  • Ensure alignment of our security practises to standard government frameworks such as the ISM, PSFP, and E8.
  • Foster collaboration and knowledge sharing through proactive mentorship of junior colleagues, promoting a culture of continuous improvement.

Criteria

The buyer has specified that each candidate must provide a one page pitch to address all criteria specified. This is equal to 5000 characters.

Essential criteria

  • 1.1. Minimum 5 years experience with Microsoft technology stack and associated security and management tooling such as Sentinel, Intune, Entra Active Directory, Purview and Microsoft M365. 2. Proven experience maintaining, operating and automating SIEM technology. 3. Strong experience in team collaboration and business engagement activities, including cyber uplift projects. 4. Experience implementing the ISM controls, PSPF and E8 strategies. 5. Relevant industry certifications.
  Required Skills:

Environment Scanners Project Teams Data Support Team Collaboration Collaboration Operations Analysis Government Components Active Directory Continuous Improvement Automation Integration Strategy Security Business Management