openqareer

Detection Engineer

Orro Pty Ltd · Sydney NSW 2000

# Detection Engineer **Orro Pty Ltd** · Sydney NSW 2000 · `On-site` 🕒 **Статус:** *Опубликовано: вчера* · *Источник: Indeed* --- ### About the Role Sydney | Melbourne | Brisbane | Hybrid Work Model | Competitive base + super + benefits Most detection engineering roles hand you a single SIEM and a backlog of tickets. This one hands you three platforms, a customer base that includes some of Australia's biggest brands, and a seat between the threat hunters and the SOC analysts who rely on what you build. As a Detection Engineer in our Security Operations Centre, you'll turn hunting findings and intelligence reporting into detection logic across Microsoft Sentinel, SentinelOne and Splunk, tune out the noise that costs analyst attention, and shape the structured context that lets AI make a confident first pass in triage. If you are ready to take on more, not just more of the same, this is the role. About Orro We're an Australian success story, now close to 500 people strong, delivering secure, end to end digital solutions across cloud, collaboration, cyber security, data services and network infrastructure, all backed by over 20 years of experience. Trusted by some of Australia's biggest brands, Orro leads the way in designing, building and operating digital infrastructure that delivers greater efficiency, agility, performance and resilience. Our solutions take the stress out of tech for more than 400 businesses and over 20 million Australians every single day. Our mission? To create "future now" solutions making it faster, simpler and safer for people to access, store and share information, wherever they are and whoever they're with. But more than that, we know that real impact comes from connecting people, not just machines. That's why we take the time to understand our clients; how they work, what matters to them, and where they're headed so we can deliver not just what they need today, but what they'll need next. With offices in Sydney, Melbourne, Canberra, Brisbane and Perth, and teams across New Zealand, the Philippines and the UK, Orro is known for delivering future ready solutions, backed by deep expertise, genuine human insight and lasting partnerships. What You'll Be Doing You'll own detection content across the platforms our customers run, whether that is Microsoft Sentinel, SentinelOne or Splunk. A typical week mixes authoring new detections against a freshly mapped technique, tuning down the false positives that consume analyst attention, tracing a coverage gap back to a missing log source, and pairing with the SOC to make sure the content you ship lands well in triage. You'll work closely with threat hunters, SOC analysts and customer stakeholders, both remotely and onsite, and you'll mentor less experienced members of the team along the way. Design high fidelity detections for subtle or evasive behaviours, balancing coverage against noise and writing logic that ports cleanly across SIEMs Tune the highest volume rules by finding the root cause of noise in the data, not just the rule, and improve precision systematically Translate customer risk profiles into a prioritised detection strategy that closes the highest impact gaps first Audit customer logging against intended coverage, map it to MITRE ATT&CK and business risk, and flag the gaps that matter most with the impact of each Turn threat tradecraft and intelligence reporting into concrete things to look for in telemetry, mapped to ATT&CK techniques with reference Perform SIEM based event analysis and incident triage, and coordinate security incidents and projects with internal and external stakeholders What You'll Bring The Essentials At least 2 years of hands on experience in detection engineering or a large scale security operations practice Experience building detection rules in at least two of Microsoft Sentinel, SentinelOne and Splunk, with a proven record of reducing false positive rates Fluency across multiple query languages, writing efficient queries over large data sets and picking up unfamiliar languages quickly Solid understanding of MITRE ATT&CK and the cyber kill chain, and how both map to business risk Ability to document and explain technical detail clearly to technical and non technical audiences Even if you don't tick every box, don't let that hold you back. If this sounds like your kind of challenge, we'd genuinely love to hear from you. Bonus Points A computer science qualification at certificate, diploma, bachelor's or master's level Current certifications such as SC 200, Blue Team Level 1 or 2, SANS Incident Responder or GIAC GCDA Why Orro? At Orro, we're proud to support our people and the people who matter most to them in meaningful and inclusive ways. From public holiday swaps that embrace family and cultural diversity, to generous parental and caregiver leave, flexible work options, and company wide mentoring, we're here to help you thrive at every stage of life. We also invest in the future through our Emerging Leaders Development Program, nurturing the next generation of talent from within. On top of that, you'll enjoy 3 days of paid volunteer leave each year, novated leasing, employee discounts, and full access to our wellbeing platform packed with expert fitness plans, nutrition tips, and tools to help you feel your best, inside and out. Note: The role is subject to state and federal police background checks. Applicants must have the unrestricted right to work in Australia. Visa sponsorship is not available for this position.

Наблюдалась 2026-09-15, впервые 2026-09-14, источник — Indeed.

Открыть у работодателя