653,119open jobs
37,986companies
91,654added this week
Browse all
Salary
$54k – $137k per year (Estimated)
Location
Remote/Hybrid (Sydney, Australia)
Seniority
Junior · 2+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match

Sydney | Melbourne | Brisbane | Hybrid Work Model | Competitive base + super + benefits

Most detection engineering roles hand you a single SIEM and a backlog of tickets. This one hands you three platforms, a customer base that includes some of Australia's biggest brands, and a seat between the threat hunters and the SOC analysts who rely on what you build. As a Detection Engineer in our Security Operations Centre, you'll turn hunting findings and intelligence reporting into detection logic across Microsoft Sentinel, SentinelOne and Splunk, tune out the noise that costs analyst attention, and shape the structured context that lets AI make a confident first pass in triage. If you are ready to take on more, not just more of the same, this is the role.

About Orro

We're an Australian success story, now close to 500 people strong, delivering secure, end to end digital solutions across cloud, collaboration, cyber security, data services and network infrastructure, all backed by over 20 years of experience. Trusted by some of Australia's biggest brands, Orro leads the way in designing, building and operating digital infrastructure that delivers greater efficiency, agility, performance and resilience. Our solutions take the stress out of tech for more than 400 businesses and over 20 million Australians every single day.

Our mission? To create "future now" solutions making it faster, simpler and safer for people to access, store and share information, wherever they are and whoever they're with. But more than that, we know that real impact comes from connecting people, not just machines. That's why we take the time to understand our clients; how they work, what matters to them, and where they're headed so we can deliver not just what they need today, but what they'll need next.

With offices in Sydney, Melbourne, Canberra, Brisbane and Perth, and teams across New Zealand, the Philippines and the UK, Orro is known for delivering future ready solutions, backed by deep expertise, genuine human insight and lasting partnerships.

What You'll Be Doing

You'll own detection content across the platforms our customers run, whether that is Microsoft Sentinel, SentinelOne or Splunk. A typical week mixes authoring new detections against a freshly mapped technique, tuning down the false positives that consume analyst attention, tracing a coverage gap back to a missing log source, and pairing with the SOC to make sure the content you ship lands well in triage. You'll work closely with threat hunters, SOC analysts and customer stakeholders, both remotely and onsite, and you'll mentor less experienced members of the team along the way.

  • Design high fidelity detections for subtle or evasive behaviours, balancing coverage against noise and writing logic that ports cleanly across SIEMs

  • Tune the highest volume rules by finding the root cause of noise in the data, not just the rule, and improve precision systematically

  • Translate customer risk profiles into a prioritised detection strategy that closes the highest impact gaps first

  • Audit customer logging against intended coverage, map it to MITRE ATT&CK and business risk, and flag the gaps that matter most with the impact of each

  • Turn threat tradecraft and intelligence reporting into concrete things to look for in telemetry, mapped to ATT&CK techniques with reference

  • Perform SIEM based event analysis and incident triage, and coordinate security incidents and projects with internal and external stakeholders

What You'll Bring

The Essentials

  • At least 2 years of hands on experience in detection engineering or a large scale security operations practice

  • Experience building detection rules in at least two of Microsoft Sentinel, SentinelOne and Splunk, with a proven record of reducing false positive rates

  • Fluency across multiple query languages, writing efficient queries over large data sets and picking up unfamiliar languages quickly

  • Solid understanding of MITRE ATT&CK and the cyber kill chain, and how both map to business risk

  • Ability to document and explain technical detail clearly to technical and non technical audiences

Even if you don't tick every box, don't let that hold you back. If this sounds like your kind of challenge, we'd genuinely love to hear from you.

Bonus Points

  • A computer science qualification at certificate, diploma, bachelor's or master's level

  • Current certifications such as SC 200, Blue Team Level 1 or 2, SANS Incident Responder or GIAC GCDA

Why Orro?

At Orro, we're proud to support our people and the people who matter most to them in meaningful and inclusive ways. From public holiday swaps that embrace family and cultural diversity, to generous parental and caregiver leave, flexible work options, and company wide mentoring, we're here to help you thrive at every stage of life.

We also invest in the future through our Emerging Leaders Development Program, nurturing the next generation of talent from within. On top of that, you'll enjoy 3 days of paid volunteer leave each year, novated leasing, employee discounts, and full access to our wellbeing platform packed with expert fitness plans, nutrition tips, and tools to help you feel your best, inside and out.

Note: The role is subject to state and federal police background checks. Applicants must have the unrestricted right to work in Australia. Visa sponsorship is not available for this position.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
653,119 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Sydney
$313k – $369k per year • Remote • Full-Time • 4+ years exp • Master's Degree
Python
Databases
Neo4j
AI/ML
Knowledge Distillation
Function Calling
AI Agents
PyTorch
SFT
Post-training
Tool Use
Model Distillation
DevOps
Splunk
AWS
IAM
Cybersecurity
Okta
Crowdstrike
SentinelOne
Microsoft Entra ID
Apply
Sales Enablement 1 day ago
$200k – $250k per year • Equity • In office • Full-Time • 7+ years exp • New York
AI/ML
Claude
DevOps
Splunk
New Relic
Datadog
Dynatrace
PagerDuty
Management
ServiceNow
Marketing
Salesforce
Apply
$92k – $138k per year • Remote/Hybrid • TS/SCI • Full-Time • 6+ years exp • Bachelor's Degree • San Diego
Python
Bash
DevOps
Splunk
Ansible
VMWare
Kubernetes
Bitbucket
GitHub
GitLab
Management
Jira
Agile
Apply
$94k – $142k per year • Remote/Hybrid • Full-Time • 4+ years exp • Mississauga
Java
Kotlin
SQL
Java
Spring Boot
Spring Cloud
Gradle
Lombok
Kotlin
Mockito
Databases
MongoDB
Redis
Couchbase
Apache Kafka
AI/ML
Flink
DevOps
Rest API
gRPC
Splunk
OpenShift
Helm
Prometheus
CI/CD
Jenkins
Docker
Kubernetes
TeamCity
Amazon ECS
Cybersecurity
SonarQube
Management
Agile
Apply
Remote/Hybrid • Full-Time • 5+ years exp • Madrid • Paris
DevOps
Splunk
Marketing
Salesforce
Apply
$15k – $38k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Manila
DevOps
Incident Management
SLI/SLO/SLA
Apply
$34k – $65k per year (Estimated) • Remote/Hybrid • Full-Time • 1+ year exp • Sydney
Cybersecurity
ISO 27001
Analytics
Microsoft Excel
Apply
SOC Analyst 8 days ago
$67k – $160k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Sydney
Cybersecurity
Qualys Cloud Platform
Apply
$78k – $200k per year (Estimated) • Remote/Hybrid • Full-Time • Sydney
Python
Bash
DevOps
Ansible
VMWare
Azure
CI/CD
Git
AWS
Ubuntu
Apply
$89k – $202k per year (Estimated) • In office • Full-Time • 10+ years exp • Sydney
Apply
$98k – $223k per year (Estimated) • In office • Full-Time • 6+ years exp • Bachelor's Degree • Sydney
Apply
$130k – $266k per year (Estimated) • Remote/Hybrid • Full-Time • Melbourne • Sydney
Apply
$50k – $119k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Sydney
Apply
$73k – $195k per year (Estimated) • Remote/Hybrid • Full-Time • 7+ years exp • Bachelor's Degree • Sydney
Analytics
Power BI
Management
SharePoint
Agile
Apply
$113k – $241k per year (Estimated) • In office • Full-Time • PhD • Sydney
Apply
See all jobs
This is one of many
653,119 more open roles from verified company boards, updated every day.