542,849open jobs
19,763companies
74,611added this week
Browse all
Salary
$86k – $197k per year (Estimated)
Location
Remote/Hybrid (Melbourne, Australia)
Seniority
Senior
Employment
Full-Time
Overview
Company
Impact
Profile match
KPMG Australia is part of a global network of professional firms providing Audit, Tax and Advisory services.

Join our Security Operations Centre as a Senior Security Operations Analyst, where you will play a leading role in strengthening our detection capability and responding to complex cyber security incidents. With a primary focus on detection engineering, you will translate threat intelligence, hunting outcomes and incident findings into effective, tested and maintainable detection content across our SOC technology platforms.

Your Opportunity

As a senior cyber security practitioner, you will own the end-to-end lifecycle of detection content and provide Level 3 technical support to the SOC. You will act as the final escalation point for complex and high-severity incidents, while mentoring analysts and supporting the continuous improvement of our security operations capability.

Your responsibilities will include:

Detection engineering

  • Own the detection lifecycle, including requirements intake, research, development, testing, deployment, tuning and retirement.
  • Develop and maintain detection content across SIEM and XDR platforms, including analytics rules, correlation logic and custom queries.
  • Write and optimise advanced queries using technologies such as KQL in Microsoft Sentinel and Microsoft Defender XDR.
  • Apply detection-as-code practices, including version control, peer review, change management and automated testing.
  • Map detection coverage to the MITRE ATT&CK framework, identify gaps against prioritised threats and maintain a documented detection backlog.
  • Validate detections through adversary emulation, purple team exercises and controlled test scenarios before deployment to production.
  • Maintain clear documentation covering detection rationale, data dependencies, expected true-positive behaviour, triage guidance and response actions.
  • Measure and report detection performance using metrics such as alert volumes, precision, false-positive rates and time to detect.
  • Review, rewrite or retire detections that no longer provide value, including where platform, telemetry or environmental changes affect existing content.

Data, telemetry and platform enablement

  • Assess log-source coverage and data quality, and define onboarding requirements for new telemetry sources.
  • Develop and maintain parsers, data normalisation and schema alignment to support consistent and portable detection logic.
  • Partner with security engineering and platform teams to address gaps in logging, retention and telemetry fidelity.
  • Contribute to the configuration and optimisation of SIEM, SOAR and supporting SOC technologies, including ingestion cost management.
  • Build and maintain automation, enrichment and SOAR playbooks to improve triage consistency and reduce manual effort.

Level 3 security operations support

  • Act as the final technical escalation point for complex, ambiguous or high-severity incidents raised by Level 1 and Level 2 analysts.
  • Lead deep technical analysis across endpoint, identity, network and cloud evidence sources during major incidents.
  • Provide technical leadership across incident workstreams and support incident commanders with findings, timelines and containment options.
  • Conduct post-incident reviews, identify detection and response gaps, and translate findings into improved detection content.
  • Participate in escalation and on-call arrangements were required to support extended-hours coverage.

Threat intelligence and threat hunting

  • Translate threat intelligence into prioritised detection requirements aligned with the firm’s threat profile.
  • Conduct structured, hypothesis-driven threat hunts across SIEM, endpoint, identity and cloud telemetry.
  • Convert threat-hunting findings into repeatable detection logic, automation and documented hunting queries.
  • Monitor adversary tradecraft, vulnerabilities and emerging threats, assessing their relevance and detection implications.

Collaboration and continuous improvement

  • Mentor and coach Level 1 and Level 2 analysts in investigation techniques, query development and detection engineering concepts.
  • Peer review detection content created by other analysts and engineers, ensuring agreed quality standards are maintained.
  • Improve SOC playbooks, triage guidance and response workflows associated with detection content.
  • Work closely with internal technology teams and security specialists to deliver effective security outcomes.
  • Support client and stakeholder engagements where the SOC provides managed or advisory security services.

How are you extraordinary?

  • You are an analytical problem-solver who can navigate ambiguity, connect complex technical evidence and make sound decisions during high-pressure security incidents.
  • You are a collaborative technical leader who builds trusted relationships, shares knowledge and supports others to strengthen their investigation and detection capabilities.
  • You are a clear and influential communicator who can translate complex technical findings into concise guidance for analysts, incident leaders, stakeholders and clients.

Your Experience

To be successful in this role, you will bring:

  • Demonstrated experience developing and maintaining detection content within SIEM or XDR platforms, including rule authoring, testing and tuning.
  • Advanced capability in query languages such as KQL, SPL or equivalent, with experience writing and optimising complex queries.
  • Practical knowledge of MITRE ATT&CK and experience assessing and improving detection coverage against prioritised threats.
  • Senior-level experience in a Security Operations Centre or an equivalent operational cyber security environment.
  • Proven experience leading the analysis of complex security incidents across endpoint, identity, network and cloud environments.
  • Strong knowledge of enterprise and cloud log sources, telemetry, data quality and normalisation.
  • A sound understanding of cyber security frameworks, standards and industry-leading practices.
  • Strong written and verbal communication skills, including the ability to clearly document detection logic, investigation guidance and response actions.

The following experience will be highly regarded:

  • Experience applying detection-as-code practices, including source control and CI/CD pipelines for security content.
  • Scripting and automation capability using Python, PowerShell or SOAR playbook development.
  • Experience conducting adversary emulation or purple team testing to validate detection coverage.
  • Experience within professional services, consulting or a managed security services environment.
  • A tertiary qualification in Cyber Security, Computer Science, Information Technology or another relevant technical discipline.
  • Relevant industry certifications, such as SC-200, SC-300, AZ-500, CISSP, CompTIA Security+, ISC2 certifications or GIAC certifications including GCDA, GCIA, GCFA or GCTI.
  • Advanced training in detection engineering, threat hunting or SIEM technologies, supported by an ongoing commitment to professional development.

KPMG is a professional services firm with global outreach and deep sector experience. We work with clients across an array of industries to solve complex challenges, steer change and enable growth.

Our people are what make KPMG the thriving workplace that it is and what sets us apart is that we know great minds think differently. Collaborate with a team of passionate, highly skilled professionals who’ve got your back. You’ll build relationships with unique and diverse colleagues who will provide you with the support you need to be your best and produce meaningful and impactful work in an inclusive, equitable culture.

At KPMG, you’ll take control over how you work. We’re embracing a new way of working in many ways, from offering flexible hours and locations to generous paid parental leave and career breaks. Our people enjoy a variety of exciting perks, including retail discounts, health and wellbeing initiatives, learning and growth opportunities, salary packaging options and more.

Diverse candidates have diverse needs. During your recruitment journey, information will be provided about adjustment requests. If you require additional support before submitting your application, please contact the Talent Attraction Support Team.

At KPMG every career is different, and we look forward to seeing how you grow with us.

KPMG Australia: grow with us!

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
542,849 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Melbourne
$116k – $194k per year • Remote • 8+ years exp
Python
SQL
Databases
Snowflake
AI/ML
LangGraph
LangChain
LlamaIndex
dbt
Embeddings
Prompt Engineering
Function Calling
AI Agents
LLM
RAG
LLM Guardrails
Agentic Workflows
Tool Use
DevOps
GCP
Prometheus
Azure
CI/CD
AWS
Docker
Kubernetes
Vector
Cortex
Apply
Remote/Hybrid • 5+ years exp • Bachelor's Degree
Python
SQL
PowerShell
C#
C#
.NET
AI/ML
Copilot Studio
DevOps
Git
Management
Power Automate
Power Apps
Microsoft Teams
Apply
Remote/Hybrid • 5+ years exp
Python
JavaScript
Java
C#
C++
Java
Maven
C#
.NET
Databases
Oracle
MS SQL
Apache Kafka
Frontend
React.js
DevOps
GCP
Azure
CI/CD
Git
AWS
Docker
Kubernetes
Apply
$34k – $82k per year (Estimated) • In office • Full-Time • 8+ years exp • Hanoi
Python
DevOps
CI/CD
Git
GitLab
Apply
Remote/Hybrid • 6+ years exp • Bachelor's Degree
C#
C#
.NET
DevOps
GCP
Azure
CI/CD
AWS
Kubernetes
Apply
$71k – $159k per year (Estimated) • Remote/Hybrid • Full-Time • Sydney
Apply
$116k – $259k per year (Estimated) • Remote/Hybrid • Full-Time • Melbourne
Apply
$115k – $256k per year (Estimated) • Remote/Hybrid • Full-Time • Sydney
Apply
$71k – $159k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Sydney
Apply
$71k – $160k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Melbourne
Apply
$132k – $251k per year (Estimated) • Equity • In office • Full-Time • 5+ years exp • Bachelor's Degree • Melbourne
Apply
$122k – $282k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Melbourne • Sydney • Brisbane
Python
AI/ML
vLLM
Triton Inference Server
Multimodal AI
TensorRT-LLM
TensorFlow
PyTorch
NVIDIA NIM
DevOps
OpenShift
Kubernetes
Apply
$78k – $190k per year (Estimated) • Remote/Hybrid • Full-Time • Wollongong • Melbourne
Apply
$66k – $151k per year (Estimated) • Remote/Hybrid • 5+ years exp • Melbourne
AI/ML
Midjourney
Design
Adobe Photoshop
Figma
Canva
Apply
$79k – $190k per year (Estimated) • In office • Full-Time • 4+ years exp • Sydney • Melbourne
Databases
MySQL
AI/ML
AI Agents
Apply
See all jobs
This is one of many
542,849 more open roles from verified company boards, updated every day.