We’re growing, not slowing, here at Macquarie Technology Group because we’re passionate about doing things differently. We want to challenge the industry and look for better ways of doing things. As a team, Macquarie Government are hardworking, results and success focused. We also take the time to celebrate our success and make sure our people are doing work that makes a difference.
We believe that collaboration & team connection is key for success. This role will be based in Canberra on-site with one of our clients.
We require security clearance for this role you must be an Australian citizen to be eligible to obtain a security clearance or ideally already hold NV1 security clearance.
We're looking for a Security Engineer to join our growing cyber security team in Canberra. This opportunity is ideal for someone with around 18 months to 4 years' experience in a SOC or cyber security environment who has hands-on experience with Splunk log onboarding, use case development, detection engineering and security monitoring.
You'll play a key role in onboarding and normalising log sources, building and tuning detections, investigating alerts, and supporting incident triage and response activities across customer environments. We're looking for someone who understands how security data flows into a SIEM, can work through detection logic, and enjoys improving visibility and security outcomes through well-designed use cases and analytics.
Working alongside experienced cyber professionals, you'll continue to develop your skills across Splunk, detection engineering, threat monitoring and incident response while supporting environments that genuinely matter. If you're curious, proactive, and eager to grow your technical capability in a high-performing team, this could be a great next step in your cyber security career.
We're looking for a Security Engineer to join our growing cyber security team in Canberra. This opportunity is ideal for someone with around 18 months to 4 years' experience in a SOC or cyber security environment who has hands-on experience with Splunk log onboarding, use case development, detection engineering and security monitoring.
You'll play a key role in onboarding and normalising log sources, building and tuning detections, investigating alerts, and supporting incident triage and response activities across customer environments. We're looking for someone who understands how security data flows into a SIEM, can work through detection logic, and enjoys improving visibility and security outcomes through well-designed use cases and analytics.
Working alongside experienced cyber professionals, you'll continue to develop your skills across Splunk, detection engineering, threat monitoring and incident response while supporting environments that genuinely matter. If you're curious, proactive, and eager to grow your technical capability in a high-performing team, this could be a great next step in your cyber security career.
Monitoring, triaging, investigating, and responding to security alerts and incidents within our Security Operations Centre (SOC) Onboarding and integrating new log sources into Splunk, including writing and tuning data inputs, parsing configurations, field extractions, and validating data quality Developing, refining, and optimising Splunk searches, dashboards, alerts, and detection logic to improve threat detection capability Investigating security events, identifying patterns, determining severity, and escalating incidents in line with established playbooks and procedures Contributing to the continuous improvement and uplift of SOC processes, runbooks, and detection logic Collaborating with internal cloud, network, endpoint, and engineering teams to improve log coverage and security monitoring across environments Keeping up with the evolving threat landscape and bringing practical ideas to improve the team’s capability
A degree in Cyber Security, Information Technology, Computer Science, or a related field 18 months to 4 years of hands-on SOC experience, including practical experience onboarding, validating, and tuning log sources in Splunk Strong working knowledge of common attack techniques, threat indicators, and the MITRE ATT&CK framework, with the ability to apply this knowledge during investigations Experience working with security technologies such as firewalls, IDS/IPS, endpoint detection tools, cloud security platforms, and related monitoring tools Confident analytical and problem-solving skills, with the ability to assess complex security events and make sound escalation decisions Clear written and verbal communication skills, with the ability to explain incidents, risks, and findings to both technical and non-technical stakeholders
- Splunk certifications (e.g., Splunk Core Certified User or Power User)
- Exposure to SOAR platforms or security automation
- Experience with cloud environments (AWS, Azure, or GCP)
- Relevant industry certifications such as CompTIA Security+, CySA+, or equivalent
Candidates must be Australian citizens and eligible to obtain or hold an Australian Government security clearance.
If this role excites you Apply Now!