Job title: 1 Senior Cyber Threat Analyst
Job type: Contract
Emp type: Full-time
Pay interval: Hourly
Pay rate: negotiable
Job published: 24/09/2026

Job Description

Job Title: Senior Cyber Threat Analyst

Security Clearance: Must be able to obtain Baseline

Duration: Initial 12 months with 2 x 12-month extensions

Industry: Information Technology

Functional Expertise: Cyber Security

Sub-functional Expertise: Threat Detection Engineering

Location of work: ACT

Working arrangements: Hybrid. Flexible work is generally supported. Remote working arrangements may be considered on a case-by-case basis in consultation with the supervising manager, subject to business needs.

Closing date: 9AM Thursday, 1 October 2026

Description:

Our client is seeking a Senior Cyber Threat Analyst to develop and maintain the material required to detect threats and incidents across the Security Operations Centre technology stack.

The role is responsible for researching, developing, testing and maintaining use cases and detection rules, and coordinating with Cyber Defence Analysts to develop detection content across SIEM, SOAR and EDR platforms. The successful candidate will work within ITIL and Agile environments, develop process and engineering documentation, and support threat intelligence sharing across cloud and on-premise environments.

Responsibilities:

  • Develop use cases based off threat models, system risks, vulnerabilities, intelligence, incident reports and industry frameworks.
  • Develop the detection rule syntax associated with use cases within the SIEM and EDR technologies.
  • Develop playbooks for alert validation by understanding the context in which the detection rule is designed.
  • Develop and maintain threat models using industry recognised methodologies such as STRIDE, ATT&CK and attack path analysis to identify detection opportunities and coverage gaps.
  • Assess emerging threats associated with Artificial Intelligence (AI) platforms, services and agents, and develop detection content to identify AI-related misuse, data leakage, prompt injection, model abuse and adversarial activity.
  • Collaborate with architecture and engineering teams to ensure threat modelling outcomes are translated into effective monitoring, detection and response capabilities.
  • Maintain the threat intelligence integrations across the SOC technology stack.
  • Conduct in-depth research and analysis for new detection content.
  • Collaborate with Cyber Defence Analysts for detection rule tuning.
  • Assist with threat model development to inform the detection engineering strategy.
  • Assist in the identification of content shortfalls across the detection engineering practice.
  • Assist with incident response at the direction of the incident manager.
  • Assist in the onboarding of new data sources to meet requirements of use cases.
  • Provide evaluation and feedback necessary for improving intelligence production and reporting.
  • Provide support to designated exercises, planning activities, and time sensitive operations.

Requirements:

  • Research, develop, test and maintain use cases and detection rules.
  • Develop detection content for use across SIEM, SOAR and EDR platforms.
  • Work within an ITIL and Agile environment.
  • Develop process and engineering documentation.
  • Provide threat intelligence sharing to infrastructure and architecture teams across cloud and on-premise environments.

Key Capabilities:

  • Detection engineering and SIEM expertise.
  • Threat detection and response capability.
  • Threat modelling and threat intelligence.
  • AI security monitoring.
  • Cyber security operations.
  • Sigma rule development.
  • EDR platform expertise.
  • Security automation and scripting.

Essential Criteria:

  • Detection Engineering and SIEM Expertise - Demonstrated experience developing detection content across at least two enterprise SIEM platforms (e.g. Splunk, Microsoft Sentinel, QRadar, Elastic).
  • Threat Detection and Response Capability - Experience developing and implementing detections across SIEM, SOAR and EDR platforms, including incident response automation and playbook development.
  • Threat Modelling and Threat Intelligence - Practical experience conducting threat modelling using recognised methodologies (e.g. STRIDE, PASTA, ATT&CK) and translating outcomes into detection and monitoring requirements, supported by a strong understanding of the cyber threat intelligence lifecycle.
  • AI Security Monitoring - Experience identifying, assessing and developing monitoring controls for AI-related security risks, including enterprise AI platforms such as Microsoft Copilot or Azure AI.
  • Cyber Security Operations Experience - Minimum five years' experience in cyber security operations, supported by strong organisational, communication and stakeholder engagement skills.

Desirable Criteria:

  • Sigma Rule Development - Experience developing or using Sigma detection rules and translating detections between security platforms.
  • Advanced AI Security Knowledge - Familiarity with AI security frameworks and guidance, including ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10. Relevant industry certifications such as GIAC, SANS, CISSP, GCIA, GCIH or equivalent cyber security qualifications.
  • EDR Platform Expertise - Experience with enterprise EDR technologies such as CrowdStrike, Microsoft Defender for Endpoint and Carbon Black.
  • Automation and Scripting - Proficiency in scripting languages such as Python and Bash to support detection engineering and security automation activities.

How to apply:

Please submit your application including your resume and a completed application form addressing the essential and desirable criteria. Ensure your application highlights your experience and any relevant certifications.

File types (doc, docx, pdf, rtf, png, jpeg, jpg, bmp, jng, ppt, pptx, csv, gif) size up to 5MB
File types (doc, docx, pdf, rtf, png, jpeg, jpg, bmp, jng, ppt, pptx, csv, gif) size up to 5MB