{"id":1484170,"url":"https://alion.io/job/salt-cyber-detection-engineer","title":"Cyber Detection Engineer","company":{"id":1935342,"name":"Salt","domain":"welovesalt.com","url":"https://alion.io/company/welovesalt","size_band":"201-500","is_staffing_agency":true,"employer_type":"agency","is_intermediary":false,"listed_via":null,"ats_vendor":null,"truth_index":{"grade":"C","score":64,"open_postings":1440,"ghost_share":0.608,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-01T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Melbourne, Australia"],"countries":["AU"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":100000,"max_usd":227000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":1261},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"IBM QRadar","optional":false},{"name":"Microsoft Sentinel","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"SIEM","optional":false},{"name":"Splunk","optional":false},{"name":"SQL","optional":false}],"status":"live","first_seen_at":"2026-07-21T00:00:00Z","employer_posted_date":"2026-07-22","last_verified_at":"2026-09-29T22:22:26Z","board_verified":true,"closed_at":null,"days_open":72,"trust":{"level":"ok","repost_count":0,"flags":["company_stale"],"days_open":72},"description":"Melbourne | Contract Opportunity | Enterprise Cyber Security TransformationReady to help shape the future of enterprise cyber defence?\nWe’re partnering with a leading enterprise organisation undertaking a significant cyber security transformation and are looking for an experienced Detection Engineer to play a critical role in delivering a modern Unified SIEM capability.\nThis is a hands-on technical position where you’ll design, build and optimise detection use cases that strengthen cyber resilience, improve SOC capability and enhance threat detection across cloud and on-premise environments.\nWorking alongside Threat Engineering, Security Engineering and SOC teams, you’ll help build a scalable, intelligence-driven detection capability that enables faster identification and response to evolving cyber threats.\nWhat You’ll Be Doing Design, develop and maintain high-quality detection use cases aligned to threat intelligence, MITRE ATT&CK and business risk priorities.\nBuild, tune and optimise SIEM analytics, alerting logic and correlation rules.\nImprove detection quality by reducing false positives and increasing detection fidelity.\nApply Detection-as-Code principles using version control and structured deployment processes.\nSupport the delivery of a large-scale Unified SIEM transformation, including migration and consolidation activities.\nOnboard, normalise and optimise log sources across cloud, endpoint, identity and network platforms.\nTranslate threat intelligence, red/purple team findings and incident learnings into actionable detection content.\nDevelop detections targeting identity attacks, endpoint compromise, malware, network threats and cloud-native attack techniques.\nPartner with SOC teams to validate detections, tune alerts and develop operational playbooks.\nAssess logging requirements, identify telemetry gaps and improve overall detection coverage. What You’ll Bring\nYou’ll be an experienced Detection Engineer, SIEM Engineer or SOC Detection Specialist with a passion for improving cyber detection capabilities.\nYou’ll ideally have: 5+ years’ experience in Detection Engineering, SIEM Engineering or advanced SOC Analytics.\nExperience delivering SIEM transformation, migration or uplift programmes.\nStrong experience with enterprise SIEM platforms such as Microsoft Sentinel, Splunk, Elastic or IBM QRadar.\nStrong query development skills using KQL, SPL and/or SQL.\nExcellent understanding of the MITRE ATT&CK Framework and modern threat detection methodologies.\nExperience analysing and correlating logs across: Identity and Active Directory\nEndpoint security platforms\nNetwork infrastructure\nAzure, AWS and Microsoft 365 Experience detecting: Identity compromise\nLateral movement\nMalware and endpoint attacks\nNetwork-based threats\nCloud attacks and privilege escalation Strong analytical and investigation skills with the ability to identify patterns across multiple data sources. Why Apply? Join a major enterprise cyber transformation programme.\nWork with modern SIEM technologies and advanced detection engineering practices.\nInfluence how cyber threats are detected across a large and complex environment.\nCollaborate with highly skilled SOC, Threat Intelligence and Security Engineering teams.\nOpportunity to drive Detection-as-Code, automation and continuous improvement initiatives.\nCompetitive contract rates with a long-term programme of work. If you’re passionate about building high-quality detections, improving SOC capability and helping organisations stay ahead of emerging threats, we’d love to hear from you.\nApply today or get in touch for a confidential discussion about this opportunity.\nInterested to explore other cyber security roles? Contact our team today to discuss potential opportunities in Melbourne!\nAt Salt, our mission is Creating Futures by putting our clients, candidates, partners, and team members at the heart of everything we do. We extend our sincere appreciation to everyone who has contributed to our continued success.\nSalt acknowledges the Traditional Owners of the lands across Australia as the continuing custodians of country and culture. We pay our respects to all First Nations Australians and their Elders past and present.","description_format":"text","description_chars":4211,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Security Operations"],"lifecycle":[{"event":"open","at":"2026-09-29T22:01:35Z"}],"liveness":{"score":12,"band":"cold","label":"Long shot","p_open":1,"p_active":0.345,"p_room":0.36,"age_days":72,"expected_fill_days":47,"reasons":["conf:31","agency","stale_co","urgency","velocity","win:tail","crowd:brand"],"computed_at":"2026-10-01T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/salt-cyber-detection-engineer","json_url":"https://alion.io/job/salt-cyber-detection-engineer.json","meta":{"generated_at":"2026-10-01T10:21:29Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1459,"day_limit":5000,"remaining_today":3541,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}