Your opportunity:
The Cyber Security SIEM Analyst is responsible for providing support, administration, and continuous improvement of Splunk Enterprise Security. This includes the onboarding of new technologies, the development of detection use cases/data models and security monitoring scenarios to enhance the Cyber Security Operations team's ability to identify, investigate, and respond to emerging threats across the TPG Telecom environment.
You'll make impact by:
- Lead technical security technology integration efforts to facilitate accurate and timely identification and mitigation of cyber security threat.
- Support the development and testing of security event correlation content and threat-based use cases using SIEM technologies
- Support and develop TPG SIEM platform continuous improvement efforts and support TPG in navigating the continuously evolving threat landscape with a focus on bringing that information into the SIEM platform
- Assist with Technology Security sponsored or led security assessments, audits and reviews
- Understanding of the Common Information Model (CIM) and ensuring log sources are mapped and compliant with CIM standards.
- Strong understanding of the MITRE ATT&CK framework, including assessing detection coverage, mapping security events and use cases to ATT&CK techniques, and identifying opportunities to enhance monitoring effectiveness.
- Creating playbooks for Splunk SOAR and automations.
- Maintain up-to-date and thorough understanding of various critical log event sources in various formats including network devices, security platforms, operating systems, applications, and log management platforms like Splunk Enterprise Security.
What you’ll bring:
- Tertiary qualifications in IT or Engineering, or related discipline
- In-depth knowledge of information security concepts and technologies
- 2-3 years of in-depth technical SIEM integration, administration and security event correlation use case development experience with Splunk Enterprise Security(preferred)
- Information Security related experience, in areas such as: security operations, incident analysis, incident handling, and vulnerability management or testing, system patching, log analysis, intrusion detection, or firewall administration
- Extensive understanding of cyber security hygiene benchmarks and industry frameworks applicable to VHA’s complex hybrid (on-premise, private and public cloud) environment
- In depth technical skills, includes TCP/IP knowledge, networking and security product experience
Ideally, you will also have:
- Good understanding of Telco business desirable
What's in it for you?
- Flexible hybrid way of working (from home and office)
- ‘Stay Connected Mobile’ - Access to a free mobile plan
- ‘Stay Connected NBN’ - Access to a free, high-speed NBN plan (up to 500 Mbps)
- ‘Your Leave’ - additional leave to be used whenever you like - every year
- Access to TPG Learning Hub platform and internal development opportunities
- Access to Corporate Partner Discounts
Don’t meet every single requirement? That’s OK! At TPG Telecom, we’re all about creating an accessible workplace where everybody feels safe to bring their authentic self to work - regardless of background. If you think this role is a great fit for you but some of the qualifications don’t align with your experience, we still encourage you to apply - you might just be the perfect candidate for a similar role with us! Learn more about life at TPG Telecom here.
TPG Telecom also acknowledges the Gadigal People of the Eora Nation as the Traditional Custodians of lands and waterways where this office can be found in Barangaroo.
Our Talent Acquisition Team and Hiring Managers kindly request no unsolicited resumes or approaches from Recruitment Agencies. TPG Telecom is not responsible for any fees related to unsolicited resumes.
#LI-Hybrid

