We are seeking a skilled and motivated Security Engineer to join our Australian team. This role is responsible for the design, documentation, implementation, optimisation, and ongoing management of security monitoring and detection capabilities across a classified Microsoft Azure environment.
🏢 About Metrea
Metrea delivers effects-as-a-service to national security partners across five domains and more than a dozen mission areas. These include airborne ISR, electronic warfare, secure communications, aerial refueling, special air missions, aerial firefighting, and advanced simulation. We own the whole stack: designing, building, and operating turnkey capabilities that give our partners decisive, asymmetric advantage against rapidly evolving threats.
🎯 The Role
The Security Engineer will play a key role in the administration and continuous improvement of the organisation's Microsoft Sentinel SIEM platform, Azure Log Analytics workspaces, security automation, and detection engineering capabilities. Working closely with security operations, infrastructure and application teams, the role will focus on enhancing visibility, reducing risk, improving threat detection coverage, and supporting effective incident response outcomes.
✅ Key Responsibilities
Administer, configure, and maintain Microsoft Sentinel and supporting Azure security monitoring platforms
Design, implement, and continuously improve SIEM detection use cases and analytics rules
Perform alert tuning and optimisation to improve detection fidelity and reduce false positives
Develop and maintain automated response playbooks using Azure Logic Apps and Sentinel automation capabilities
Conduct threat hunting activities using Microsoft Sentinel, KQL, and threat intelligence sources
Investigate, analyse, and support the response to cyber security incidents and alerts
Develop and maintain security monitoring dashboards, workbooks, and operational reporting
Integrate and onboard new data sources to improve visibility across the technology estate
Map detections and use cases to MITRE ATT&CK techniques and threat-based frameworks
Collaborate with infrastructure and application teams to address identified security risks
Identify opportunities to improve detection coverage, monitoring effectiveness, and incident response processes
Support security audits, compliance activities, and cyber security assessments as required
📌 Required Qualifications
5+ years of experience in cyber security, security operations, detection engineering, or SIEM administration roles
Demonstrated experience managing enterprise-scale SIEM platforms and security monitoring services
Experience leading technical initiatives related to security monitoring, detection improvement, and incident response maturity
Experience working in government, Defence, critical infrastructure, or highly regulated environments
Experience supporting and authorising systems operating at PROTECTED, or higher security classifications is highly desirable
Demonstrated experience applying ISM and PSPF requirements within operational environments
Advanced knowledge of Azure Log Analytics, Kusto Query Language (KQL), and data ingestion architecture
Experience designing, implementing, and maintaining SIEM use cases, analytics rules, workbooks, watchlists, and data connectors
Proven ability to analyse complex security events and translate findings into actionable improvements
Familiarity with Microsoft security technologies including: Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud, Microsoft Entra ID (Azure AD)
Experience working within cloud-first or hybrid enterprise environments
Experience onboarding and integrating log sources from cloud, infrastructure, network, and third-party security platforms
Strong understanding of cyber security monitoring, threat detection, incident response, and security operations practices
Knowledge of common attack frameworks such as MITRE ATT&CK and their application to detection and threat hunting activities
Understanding of security automation, orchestration, and response (SOAR) principles
Experience creating dashboards, workbooks, reporting, and operational metrics for security monitoring and compliance
⭐ Desirable Experience
Bachelor or higher degree in Cyber Security, Information Technology, Computer Science, Information Systems, Engineering, or relevant industry experience
Microsoft Certified: Cybersecurity Architect Expert (SC-100)
Microsoft Certified: Security Operations Analyst Associate (SC-200)
Microsoft Certified: Azure Security Engineer Associate (AZ-500)
Microsoft Certified: Azure Administrator Associate (AZ-104)
equivalent Azure administration experience may be considered
CompTIA Security+
CCSP, GCDA, GCIA or other related security certification would be highly regarded
🎁 Benefits
Private Health Insurance
Generous annual leave
Annual incentive plan
Paid parental leave
Life and disability insurance
Income Protection Insurance
Employee Assistance Program
Novated Car Leasing
🛂 Visa & Eligibility
Ability to obtain and maintain an AGSVA Security Clearance.