Your opportunity:
As a Blue Team Specialist, you will be a part of a team responsible for performing intelligence-driven threat hunting across TPG Telecom's infrastructure and applications. This will involve leveraging the latest cyber threat intelligence to hunt proactively using framework-based approaches for sophisticated cyber threats relevant to the telecommunications sector.
You'll make impact by:
- Apply threat hunting frameworks (i.e. PEAK, TaHITI), leveraging cyber threat intelligence to identify and analyse sophisticated cyber threats.
- Conduct intelligence-driven hypothesis-based threat hunts across endpoint, network, cloud, identity, and application telemetry to identify cyber threat activity not detected by existing controls.
- Develop and execute adversary-focused hunt missions aligned to MITRE ATT&CK tactics, techniques and procedures (TTPs), threat intelligence, and organisational risk priorities.
- Create and maintain advanced hunting queries within SIEM, EDR, NDR, and cloud security platforms.
- Validate cyber threat intelligence through hunting activities and provide feedback to the threat intelligence team on hunt package effectiveness.
- Translate hunt findings into actionable detection use cases and preventative controls enhancements.
- Participate in purple team exercises to validate security control coverage and improve defensive capabilities.
Contribute to threat hunting playbooks, methodologies, and knowledge repositories to mature organisational threat hunting capabilities.
-
What you’ll bring:
- Experience in threat hunting, incident response, detection engineering, or a related cyber security discipline.
- Experience developing and executing hypothesis-driven threat hunts using structured approaches such as PEAK, TaHITI or similar frameworks.
- Experience applying threat intelligence, adversary tactics, techniques and procedures (TTPs) to develop and execute threat hunting hypotheses and identify opportunities for detective and preventative control enhancements.
- Ability to analyse aggregate logs in a security information and event management (SIEM) platform.
- Ability to distil complex technical findings into concise and actionable recommendations tailored to technical and non-technical audiences.
Relevant qualifications such as GIAC Certified Forensic Analyst (GCFA), Certified Threat Hunting Professional (eCTHP), GIAC Defending Advanced Threats (GDAT), GIAC Certified Incident Handler (GCIH).
-
Ideally, you will also have:
- Experience leveraging automation and AI-assisted capabilities to improve the efficiency and effectiveness of threat hunting activities.
What's in it for you?
- Flexible hybrid way of working (from home and office)
- ‘Stay Connected Mobile’ – Access to a free mobile plan
- ‘Stay Connected NBN’ – Access to a free, high‑speed NBN plan (up to 500 Mbps)
- ‘Your Leave’ - additional leave to be used whenever you like - every year
- Access to TPG Learning Hub platform and internal development opportunities
- Access to Corporate Partner Discounts
Don’t meet every single requirement? That’s OK! At TPG Telecom, we’re all about creating an accessible workplace where everybody feels safe to bring their authentic self to work - regardless of background. If you think this role is a great fit for you but some of the qualifications don’t align with your experience, we still encourage you to apply - you might just be the perfect candidate for a similar role with us!
TPG Telecom also acknowledges the Gadigal People of the Eora Nation as the Traditional Custodians of lands and waterways where this office can be found in Barangaroo.
Our Talent Acquisition Team and Hiring Managers kindly request no unsolicited resumes or approaches from Recruitment Agencies. TPG Telecom is not responsible for any fees related to unsolicited resumes.
#LI-Hybrid