Security Engineer (SIEM)

Metrea · Brisbane, Australia · Engineering

Posted 2026-09-08

Apply for this role →

Group Overview

Metrea is actively building its presence in Australia as part of a deliberate, globally coordinated expansion into the Asia-Pacific region. Our Asia-Pacific Market Group, headquartered in Brisbane with an additional office in Perth, is the enterprise's dedicated regional interface — connecting Australia's national security community with Metrea's full suite of capabilities across three core domains: Aerospace, Electromagnetic & Cyber, and Digital & Synthetic. Metrea is now bringing that same depth of mission expertise and proven operating model to Australia.

Underpinning these capabilities is a global network of Support Groups spanning people, finance, platform, operations, legal, and engagement — ensuring that as we grow in Australia, we do so with the full weight of an established global enterprise behind us.

Metrea's solutions are built for elegance: effective, efficient, and evolving — enabling our partners to scale capacity and achieve asymmetric advantage against rapidly evolving threats.

Position Summary

We are seeking a skilled and motivated Security Engineer to join our Australian team. This role is responsible for the design, documentation, implementation, optimisation, and ongoing management of security monitoring and detection capabilities across a classified Microsoft Azure environment.

The Security Engineer will play a key role in the administration and continuous improvement of the organisation's Microsoft Sentinel SIEM platform, Azure Log Analytics workspaces, security automation, and detection engineering capabilities. Working closely with security operations, infrastructure and application teams, the role will focus on enhancing visibility, reducing risk, improving threat detection coverage, and supporting effective incident response outcomes.

The successful candidate will be responsible for SIEM architecture and configuration, use case development, alert tuning, threat hunting, playbook automation, and the investigation of security events and incidents. They will leverage the Microsoft security ecosystem to develop and maintain effective monitoring and response capabilities aligned with evolving cyber threats and business requirements.

This position requires strong technical expertise in cloud security, security monitoring, and detection engineering, combined with a proactive approach to continuous improvement and cyber defence.

What You'll Do

Design, implement, and continuously improve security monitoring and detection capabilities within Microsoft Sentinel and Azure Log Analytics, ensuring effective visibility across the organisation's technology environment. Develop and optimise SIEM use cases, analytics rules, and automated response playbooks while investigating security events and enhancing the organisation's threat detection and incident response capabilities. Responsibilities fall into the following main areas:

Administer, configure, and maintain Microsoft Sentinel and supporting Azure security monitoring platforms

Design, implement, and continuously improve SIEM detection use cases and analytics rules

Perform alert tuning and optimisation to improve detection fidelity and reduce false positives

Develop and maintain automated response playbooks using Azure Logic Apps and Sentinel automation capabilities

Conduct threat hunting activities using Microsoft Sentinel, KQL, and threat intelligence sources

Investigate, analyse, and support the response to cyber security incidents and alerts

Develop and maintain security monitoring dashboards, workbooks, and operational reporting

Integrate and onboard new data sources to improve visibility across the technology estate

Map detections and use cases to MITRE ATT&CK techniques and threat-based frameworks

Collaborate with infrastructure and application teams to address identified security risks

Identify opportunities to improve detection coverage, monitoring effectiveness, and incident response processes

Support security audits, compliance activities, and cyber security assessments as required

What You Bring

The successful candidate will have the following key qualifications, skills, and experiences:

5+ years of experience in cyber security, security operations, detection engineering, or SIEM administration roles

Demonstrated experience managing enterprise-scale SIEM platforms and security monitoring services

Experience leading technical initiatives related to security monitoring, detection improvement, and incident response maturity

Experience working in government, Defence, critical infrastructure, or highly regulated environments

Experience supporting and authorising systems operating at PROTECTED, or higher security classifications is highly desirable

Demonstrated experience applying ISM and PSPF requirements within operational environments

Advanced knowledge of Azure Log Analytics, Kusto Query Language (KQL), and data ingestion architecture

Experience designing, implementing, and maintaining SIEM use cases, analytics rules, workbooks, watchlists, and data connectors

Proven ability to analyse complex security events and translate findings into actionable improvements

Familiarity with Microsoft security technologies including:

Microsoft Defender XDR

Microsoft Defender for Endpoint

Microsoft Defender for Identity

Microsoft Defender for Cloud

Microsoft Entra ID (Azure AD)

Experience working within cloud-first or hybrid enterprise environments

Experience onboarding and integrating log sources from cloud, infrastructure, network, and third-party security platforms

Strong understanding of cyber security monitoring, threat detection, incident response, and security operations practices

Knowledge of common attack frameworks such as MITRE ATT&CK and their application to detection and threat hunting activities

Understanding of security automation, orchestration, and response (SOAR) principles

Experience creating dashboards, workbooks, reporting, and operational metrics for security monitoring and compliance

Additional Eligibility Qualifications

Bachelor or higher degree in Cyber Security, Information Technology, Computer Science, Information Systems, Engineering, or relevant industry experience

The below certifications are highly desirable.

•    Microsoft Certified: Cybersecurity Architect Expert (SC-100)

•    Microsoft Certified: Security Operations Analyst Associate (SC-200)

•    Microsoft Certified: Azure Security Engineer Associate (AZ-500)

•    Microsoft Certified: Azure Administrator Associate (AZ-104)

•    equivalent Azure administration experience may be considered

•    CompTIA Security+

•    CCSP, GCDA, GCIA or other related security certification would be highly regarded

Benefits

Private Health Insurance

Generous annual leave

Annual incentive plan

Paid parental leave

Life and disability insurance

Income Protection Insurance

Employee Assistance Program

Novated Car Leasing

Work Authorisation / Security Clearance

Ability to obtain and maintain an AGSVA Security Clearance.

Inclusion Statement

We are committed to building a team that reflects a broad range of backgrounds, experiences and perspectives. We welcome applications from all qualified candidates and make hiring decisions based on capability, potential and alignment with our values. If you require any adjustments throughout the recruitment process, please let us know.

Apply for this role →

← Back to all jobs