waypointjobs

PowerData Group Consulting

SOC Detection Specialist

Remote — United States (see country and timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

This is a remote position.

Location:Canberra, Australian Capital Territory (ACT)Security Clearance:​Baseline Clearance

Threat Detection Engineering

SIEM use case development and detection content creation

Detection rule development and tuning

EDR detection engineering

SOAR playbook development

Alert validation processes

Threat Modelling

STRIDE

MITRE ATT&CK

Attack path analysis

Detection coverage assessment

Gap analysis

Threat Intelligence

Threat intelligence integration and management

Research into emerging threats

Intelligence sharing across infrastructure and architecture teams

Security Operations

SOC operations

Incident response support

Detection engineering lifecycle management

Data source onboarding

ITIL and Agile environments

AI Security (Important New Requirement)

The RFQ specifically calls for experience in:

AI threat modelling

Prompt injection detection

AI model abuse detection

AI-related data leakage monitoring

Adversarial AI activity detection

Security monitoring of AI platforms, services and agents

A strong candidate would typically have:

5+ years in SOC, Detection Engineering, Threat Hunting, or Cyber Security Operations

Hands-on experience with platforms such as:

Microsoft Sentinel

Microsoft Defender XDR

Splunk

QRadar

CrowdStrike

Palo Alto Cortex XDR

Experience developing KQL, SPL, Sigma, YARA, or similar detection content

Strong understanding of MITRE ATT&CK

Experience integrating threat intelligence feeds

Good documentation and stakeholder engagement skills

Evaluation Themes to Address in a Submission

When preparing a candidate response, focus on evidence demonstrating:

Development of threat detection use cases and rules.

SIEM/EDR content engineering and tuning.

Threat modelling expertise using STRIDE and ATT&CK.

Threat intelligence integration and analysis.

Experience supporting incident response activities.

Security monitoring of cloud and on-premises environments.

AI security and emerging threat detection capabilities.

Working within Agile and ITIL environments.

Requirements

Essential criteria

1.Detection Engineering and SIEM Expertise - Demonstrated experience developing detection content across at least two enterprise SIEM platforms (e.g. Splunk, Microsoft Sentinel, QRadar, Elastic).

2.Threat Detection and Response Capability - Experience developing and implementing detections across SIEM, SOAR and EDR platforms, including incident response automation and playbook development.

3.Threat Modelling and Threat Intelligence - Practical experience conducting threat modelling using recognised methodologies (e.g. STRIDE, PASTA, ATT&CK) and translating outcomes into detection and monitoring requirements, supported by a strong understanding of the cyber threat intelligence lifecycle.

4.AI Security Monitoring - Experience identifying, assessing and developing monitoring controls for AI-related security risks, including enterprise AI platforms such as Microsoft Copilot or Azure AI.

5.Cyber Security Operations Experience - Minimum five years' experience in cyber security operations, supported by strong organisational, communication and stakeholder engagement skills.

Desirable criteria

1.Sigma Rule Development - Experience developing or using Sigma detection rules and translating detections between security platforms.

2.Advanced AI Security Knowledge - Familiarity with AI security frameworks and guidance, including ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10. Relevant industry certifications such as GIAC, SANS, CISSP, GCIA, GCIH or equivalent cyber security qualifications.

3.EDR Platform Expertise - Experience with enterprise EDR technologies such as CrowdStrike, Microsoft Defender for Endpoint and Carbon Black.

4.Automation and Scripting - Proficiency in scripting languages such as Python and Bash to support detection engineering and security automation activities.

LH-07702

Benefits

\

Originally posted on Himalayas

Who can apply

Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

Red Wine and Blue

Himalayas

General Interest Application

Remote — United States (see country and timezone requirements)

Salary not specifiedfull timeRemote

WHO THE HECK ARE WE? Red Wine & Blue is a national community of over 600,000 diverse suburban women working together to defeat extremism, one fr…

Listing expires 2026-12-04View job

Carle Health

Himalayas

Finance Systems Analyst

Remote — United States (see country and timezone requirements)

$26.41 – $44.10 per hourfull timeRemote

OverviewThe Finance Systems Analyst assists with supporting assigned finance/accounting applications for the enterprise such as costing, producti…

Listing expires 2026-12-04View job

Kyowa Kirin

Himalayas

Scientific Relations Manager

Remote — Worldwide (see timezone requirements)

Salary not specifiedfull timeRemote

OverviewWE PUSH THE BOUNDARIES OF MEDICINE. LEAPING FORWARD TO MAKE PEOPLE SMILE At Kyowa Kirin International (KKI), our purpose is to make peop…

Listing expires 2026-12-04View job

Belden, Inc

Himalayas

Solution Consultant - Cybersecurity Practice (US)

Remote — United States (see country and timezone requirements)

$125,000.00 – $160,000.00 per yearfull timeRemote

Innovation Starts With YouPropel your career at Belden, where innovation creates possibilities—for our people, our customers, and the communities…

Listing expires 2026-12-04View job