PowerData Group Consulting

SOC Detection Specialist

United States · REMOTE · FREELANCE
Publiée le 22 septembre 2026 · Candidature traitée sur le site de l’entreprise
SOC-Detection-SpecialistDetection-EngineeringThreat-IntelligenceSecurity-OperationsAI-SecuritySOC-SpecialistSOC-Detection-and-ResponseDetection-AnalystSOC-Security-AnalystSOC-Analysis

This is a remote position. Location:Canberra, Australian Capital Territory (ACT) Security Clearance:​Baseline Clearance Threat Detection Engineering • SIEM use case development and detection content creation • Detection rule development and tuning • EDR detection engineering • SOAR playbook development • Alert validation processes Threat Modelling • STRIDE • MITRE ATT&CK • Attack path analysis • Detection coverage assessment • Gap analysis Threat Intelligence • Threat intelligence integration and management • Research into emerging threats • Intelligence sharing across infrastructure and architecture teams Security Operations • SOC operations • Incident response support • Detection engineering lifecycle management • Data source onboarding • ITIL and Agile environments AI Security (Important New Requirement) The RFQ specifically calls for experience in: • AI threat modelling • Prompt injection detection • AI model abuse detection • AI-related data leakage monitoring • Adversarial AI activity detection • Security monitoring of AI platforms, services and agents A strong candidate would typically have: • 5+ years in SOC, Detection Engineering, Threat Hunting, or Cyber Security Operations • Hands-on experience with platforms such as: • Microsoft Sentinel • Microsoft Defender XDR • Splunk • QRadar • CrowdStrike • Palo Alto Cortex XDR • Experience developing KQL, SPL, Sigma, YARA, or similar detection content • Strong understanding of MITRE ATT&CK • Experience integrating threat intelligence feeds • Good documentation and stakeholder engagement skills Evaluation Themes to Address in a Submission When preparing a candidate response, focus on evidence demonstrating: • Development of threat detection use cases and rules. • SIEM/EDR content engineering and tuning. • Threat modelling expertise using STRIDE and ATT&CK. • Threat intelligence integration and analysis. • Experience supporting incident response activities. • Security monitoring of cloud and on-premises environments. • AI security and emerging threat detection capabilities. • Working within Agile and ITIL environments. Requirements Essential criteria • 1.Detection Engineering and SIEM Expertise - Demonstrated experience developing detection content across at least two enterprise SIEM platforms (e.g. Splunk, Microsoft Sentinel, QRadar, Elastic). • 2.Threat Detection and Response Capability - Experience developing and implementing detections across SIEM, SOAR and EDR platforms, including incident response automation and playbook development. • 3.Threat Modelling and Threat Intelligence - Practical experience conducting threat modelling using recognised methodologies (e.g. STRIDE, PASTA, ATT&CK) and translating outcomes into detection and monitoring requirements, supported by a strong understanding of the cyber threat intelligence lifecycle. • 4.AI Security Monitoring - Experience identifying, assessing and developing monitoring controls for AI-related security risks, including enterprise AI platforms such as Microsoft Copilot or Azure AI. • 5.Cyber Security Operations Experience - Minimum five years' experience in cyber security operations, supported by strong organisational, communication and stakeholder engagement skills. Desirable criteria • 1.Sigma Rule Development - Experience developing or using Sigma detection rules and translating detections between security platforms. • 2.Advanced AI Security Knowledge - Familiarity with AI security frameworks and guidance, including ASD/ACSC, NIST, MITRE ATLAS and OWASP LLM Top 10. Relevant industry certifications such as GIAC, SANS, CISSP, GCIA, GCIH or equivalent cyber security qualifications. • 3.EDR Platform Expertise - Experience with enterprise EDR technologies such as CrowdStrike, Microsoft Defender for Endpoint and Carbon Black. • 4.Automation and Scripting - Proficiency in scripting languages such as Python and Bash to support detection engineering and security automation activities. LH-07702 Benefits \ Originally posted on Himalayas