Threat Detection Engineer

Whizdom ·whizdom.shazamme.com

Location Canberra, Australian Capital Territory, Australia
Type Full time
Level Mid
Source Shazamme
Information & Communication Technology (ICT)
Apply direct
Threat Detection Engineer

About the Organisation

Our client is a Commonwealth Government organisation supporting Australia’s economic, scientific and technological priorities. The organisation delivers secure digital services and operates a fast-paced technology environment focused on innovation, transformation and cyber resilience.
This opportunity sits within an established cyber security function responsible for protecting enterprise systems and strengthening security capabilities across cloud and on-premises environments.

About the Role

We are seeking an experienced Senior Cyber Threat Analyst with strong threat detection engineering expertise to develop and maintain the content used to detect cyber threats and security incidents across the Security Operations Centre technology stack.
You will research, develop, test and maintain detection use cases and rules across Security Information and Event Management (SIEM), Security Orchestration, Automation and Response (SOAR), and Endpoint Detection and Response (EDR) platforms.
Working in Agile and ITIL environments, you will collaborate with cyber defence analysts, architects, engineers and infrastructure teams to translate threat intelligence and threat-modelling outcomes into effective monitoring, detection and response capabilities.

The Responsibilities

• Developing detection use cases based on threat models, system risks, vulnerabilities, intelligence, incident reports and recognised industry frameworks.
• Developing and maintaining detection-rule syntax across SIEM and EDR technologies.
• Creating playbooks to support alert validation, incident response and security automation.
• Developing and maintaining threat models using recognised methodologies such as STRIDE, MITRE ATT&CK and attack-path analysis.
• Identifying detection opportunities, monitoring requirements and coverage gaps.
• Assessing emerging threats associated with artificial intelligence platforms, services and agents.
• Developing detection content for AI-related misuse, data leakage, prompt injection, model abuse and adversarial activity.
• Collaborating with architecture and engineering teams to translate threat-modelling outcomes into effective detection and response capabilities.
• Maintaining threat-intelligence integrations across the Security Operations Centre technology stack.
• Conducting detailed research and analysis to develop new detection content.
• Working with cyber defence analysts to test, tune and improve detection rules.
• Supporting the development of the organisation’s detection engineering strategy.
• Identifying content gaps and improvement opportunities across the detection engineering practice.
• Assisting with incident-response activities under the direction of the incident manager.
• Supporting the onboarding of new data sources required for detection use cases.
• Providing feedback to improve threat-intelligence production and reporting.
• Supporting cyber security exercises, planning activities and time-sensitive operations.
• Developing process, engineering and technical documentation within ITIL and Agile delivery environments.

What You Will Bring

• At least five years’ experience in cyber security operations.
• Demonstrated experience developing detection content across at least two enterprise SIEM platforms, such as:

o Splunk
o Microsoft Sentinel
o IBM QRadar
o Elastic
• Experience developing and implementing detections across SIEM, SOAR and EDR platforms.
• Experience developing incident-response automation and security playbooks.
• Practical threat-modelling experience using recognised methodologies such as STRIDE, PASTA or MITRE ATT&CK.
• The ability to translate threat-modelling outcomes into detection, monitoring and response requirements.
• A strong understanding of the cyber threat-intelligence lifecycle.
• Experience identifying, assessing and developing monitoring controls for AI-related security risks.
• Experience working with enterprise AI platforms, such as Microsoft Copilot or Azure AI.
• Strong research, analysis and technical documentation skills.
• Excellent organisational, communication and stakeholder-engagement capabilities.
• The ability to work effectively with cyber analysts, architects, engineers and infrastructure teams.

Desirable Skills and Qualifications

• Experience developing or using Sigma detection rules.
• The ability to translate detection rules between security platforms.
• Knowledge of AI security frameworks and guidance, including:
o Australian Government cyber security guidance
o NIST guidance
o MITRE ATLAS
o OWASP Top 10 for Large Language Model Applications
• Experience with enterprise EDR technologies such as CrowdStrike, Microsoft Defender for Endpoint or Carbon Black.
• Proficiency in Python or Bash for detection engineering and security automation.
• Relevant cyber security certifications or qualifications, including:
o CISSP
o GCIA
o GCIH
o GIAC or SANS certifications
o Equivalent industry-recognised cyber security qualifications.

What’s on Offer
• Initial 12-month contract.
• Up to two additional 12-month extension options.
• Senior engagement at an APS6-equivalent level.
• Hybrid working arrangements.
Security Requirements
• Candidates must hold a Baseline security clearance.


Submissions close COB Thursday the 1st of October 2026.

Please call Lisa Berjak on 0480 011 550 for any further information. Candidates will need to be willing to undergo pre-employment screening checks which may include, ID and work rights, security clearance verification, and any other client-requested checks.

Why partner with Whizdom?
We’re Whizdom. We view you as an extension of our strong, dependable brand and have differentiators which really are different! The Whizdom way:
We pay our contractors same day you submit your timesheet!

We are Level 3, DISP certified and have signed the Veteran Employment Commitment and been awarded the highest level of compliance to this important initiative, proactively assisting veterans transitioning from the forces to civilian roles. We’ve been lucky enough to win industry awards for our high level of process compliance and are ISO 9001 certified. Our commitment to reducing Greenhouse Gas Emissions has been accredited in line with large global organisations.

We value diversity and welcome applications from Indigenous Australians, people from diverse cultural and linguistic backgrounds and people living with a disability.
Our team of talented people are passionate about your experience, doing the right thing always, with a focus on your long-term career goals. We even give you a best in industry merch pack! Even if this role isn’t the exact fit for you, we would love a chat, contact us to find out more.

Frequently asked questions

Who is hiring for the Threat Detection Engineer role?
Whizdom is hiring for the Threat Detection Engineer position, a Shazamme client. Apply directly on the employer's career site.
Where is the Threat Detection Engineer job located?
The Threat Detection Engineer role with Whizdom is based in Canberra, ACT, AU.
Is the Threat Detection Engineer role full-time or contract?
This is a full time position at Whizdom.
What experience level is the Threat Detection Engineer role?
The Threat Detection Engineer position is aimed at mid-level candidates.
How do I apply for the Threat Detection Engineer role at Whizdom?
Apply directly on Whizdom's career page via the Apply button on this listing. ZammeJobs links straight through to the employer's ATS — no third-party form, no resume database.
Apply direct