Senior Security Operations Analyst

Posted 5 Days Ago
Be an Early Applicant
Melbourne, Victoria, AUS
Hybrid
Senior level
Professional Services
The Role
Lead detection engineering and Level 3 security operations for complex cyber incidents. Develop, test, tune, and maintain SIEM/XDR detection content; conduct threat hunting; map coverage to MITRE ATT&CK; improve telemetry, automation, and SOAR playbooks; and support major incident response. Mentor analysts, perform adversary emulation and purple-team validation, document detection logic, and collaborate with engineering, stakeholders, and clients to strengthen SOC capabilities.
Summary Generated by Built In
Job Description

Join our Security Operations Centre as a Senior Security Operations Analyst, where you will play a leading role in strengthening our detection capability and responding to complex cyber security incidents. With a primary focus on detection engineering, you will translate threat intelligence, hunting outcomes and incident findings into effective, tested and maintainable detection content across our SOC technology platforms.

Your Opportunity

As a senior cyber security practitioner, you will own the end-to-end lifecycle of detection content and provide Level 3 technical support to the SOC. You will act as the final escalation point for complex and high-severity incidents, while mentoring analysts and supporting the continuous improvement of our security operations capability.

Your responsibilities will include:

Detection engineering

  • Own the detection lifecycle, including requirements intake, research, development, testing, deployment, tuning and retirement.
  • Develop and maintain detection content across SIEM and XDR platforms, including analytics rules, correlation logic and custom queries.
  • Write and optimise advanced queries using technologies such as KQL in Microsoft Sentinel and Microsoft Defender XDR.
  • Apply detection-as-code practices, including version control, peer review, change management and automated testing.
  • Map detection coverage to the MITRE ATT&CK framework, identify gaps against prioritised threats and maintain a documented detection backlog.
  • Validate detections through adversary emulation, purple team exercises and controlled test scenarios before deployment to production.
  • Maintain clear documentation covering detection rationale, data dependencies, expected true-positive behaviour, triage guidance and response actions.
  • Measure and report detection performance using metrics such as alert volumes, precision, false-positive rates and time to detect.
  • Review, rewrite or retire detections that no longer provide value, including where platform, telemetry or environmental changes affect existing content.

Data, telemetry and platform enablement

  • Assess log-source coverage and data quality, and define onboarding requirements for new telemetry sources.
  • Develop and maintain parsers, data normalisation and schema alignment to support consistent and portable detection logic.
  • Partner with security engineering and platform teams to address gaps in logging, retention and telemetry fidelity.
  • Contribute to the configuration and optimisation of SIEM, SOAR and supporting SOC technologies, including ingestion cost management.
  • Build and maintain automation, enrichment and SOAR playbooks to improve triage consistency and reduce manual effort.

Level 3 security operations support

  • Act as the final technical escalation point for complex, ambiguous or high-severity incidents raised by Level 1 and Level 2 analysts.
  • Lead deep technical analysis across endpoint, identity, network and cloud evidence sources during major incidents.
  • Provide technical leadership across incident workstreams and support incident commanders with findings, timelines and containment options.
  • Conduct post-incident reviews, identify detection and response gaps, and translate findings into improved detection content.
  • Participate in escalation and on-call arrangements were required to support extended-hours coverage.

Threat intelligence and threat hunting

  • Translate threat intelligence into prioritised detection requirements aligned with the firm’s threat profile.
  • Conduct structured, hypothesis-driven threat hunts across SIEM, endpoint, identity and cloud telemetry.
  • Convert threat-hunting findings into repeatable detection logic, automation and documented hunting queries.
  • Monitor adversary tradecraft, vulnerabilities and emerging threats, assessing their relevance and detection implications.

Collaboration and continuous improvement

  • Mentor and coach Level 1 and Level 2 analysts in investigation techniques, query development and detection engineering concepts.
  • Peer review detection content created by other analysts and engineers, ensuring agreed quality standards are maintained.
  • Improve SOC playbooks, triage guidance and response workflows associated with detection content.
  • Work closely with internal technology teams and security specialists to deliver effective security outcomes.
  • Support client and stakeholder engagements where the SOC provides managed or advisory security services.

How are you extraordinary?

  • You are an analytical problem-solver who can navigate ambiguity, connect complex technical evidence and make sound decisions during high-pressure security incidents.
  • You are a collaborative technical leader who builds trusted relationships, shares knowledge and supports others to strengthen their investigation and detection capabilities.
  • You are a clear and influential communicator who can translate complex technical findings into concise guidance for analysts, incident leaders, stakeholders and clients.

Your Experience

To be successful in this role, you will bring:

  • Demonstrated experience developing and maintaining detection content within SIEM or XDR platforms, including rule authoring, testing and tuning.
  • Advanced capability in query languages such as KQL, SPL or equivalent, with experience writing and optimising complex queries.
  • Practical knowledge of MITRE ATT&CK and experience assessing and improving detection coverage against prioritised threats.
  • Senior-level experience in a Security Operations Centre or an equivalent operational cyber security environment.
  • Proven experience leading the analysis of complex security incidents across endpoint, identity, network and cloud environments.
  • Strong knowledge of enterprise and cloud log sources, telemetry, data quality and normalisation.
  • A sound understanding of cyber security frameworks, standards and industry-leading practices.
  • Strong written and verbal communication skills, including the ability to clearly document detection logic, investigation guidance and response actions.

The following experience will be highly regarded:

  • Experience applying detection-as-code practices, including source control and CI/CD pipelines for security content.
  • Scripting and automation capability using Python, PowerShell or SOAR playbook development.
  • Experience conducting adversary emulation or purple team testing to validate detection coverage.
  • Experience within professional services, consulting or a managed security services environment.
  • A tertiary qualification in Cyber Security, Computer Science, Information Technology or another relevant technical discipline.
  • Relevant industry certifications, such as SC-200, SC-300, AZ-500, CISSP, CompTIA Security+, ISC2 certifications or GIAC certifications including GCDA, GCIA, GCFA or GCTI.
  • Advanced training in detection engineering, threat hunting or SIEM technologies, supported by an ongoing commitment to professional development.

Additional Information

KPMG is a professional services firm with global outreach and deep sector experience. We work with clients across an array of industries to solve complex challenges, steer change and enable growth. 

Our people are what make KPMG the thriving workplace that it is and what sets us apart is that we know great minds think differently. Collaborate with a team of passionate, highly skilled professionals who’ve got your back. You’ll build relationships with unique and diverse colleagues who will provide you with the support you need to be your best and produce meaningful and impactful work in an inclusive, equitable culture.

At KPMG, you’ll take control over how you work. We’re embracing a new way of working in many ways, from offering flexible hours and locations to generous paid parental leave and career breaks. Our people enjoy a variety of exciting perks, including retail discounts, health and wellbeing initiatives, learning and growth opportunities, salary packaging options and more.

Diverse candidates have diverse needs. During your recruitment journey, information will be provided about adjustment requests. If you require additional support before submitting your application, please contact the Talent Attraction Support Team.

At KPMG every career is different, and we look forward to seeing how you grow with us.

KPMG Australia: grow with us!

Skills Required

  • Experience developing and maintaining detection content in SIEM or XDR platforms, including rule authoring, testing, and tuning
  • Advanced capability with KQL, SPL, or equivalent query languages
  • Practical knowledge of MITRE ATT&CK and detection coverage assessment
  • Senior-level experience in a Security Operations Centre or equivalent operational cybersecurity environment
  • Experience leading complex security incident analysis across endpoint, identity, network, and cloud environments
  • Strong knowledge of enterprise and cloud log sources, telemetry, data quality, and normalization
  • Understanding of cybersecurity frameworks, standards, and industry practices
  • Strong written and verbal communication skills, including technical documentation
  • Experience with detection-as-code, source control, and CI/CD pipelines
  • Scripting or automation experience using Python, PowerShell, or SOAR playbooks
  • Experience with adversary emulation or purple-team testing
  • Experience in professional services, consulting, or managed security services
  • Tertiary qualification in Cybersecurity, Computer Science, Information Technology, or a related discipline
  • Relevant cybersecurity certifications such as SC-200, SC-300, AZ-500, CISSP, Security+, ISC2, or GIAC certifications
  • Advanced training in detection engineering, threat hunting, or SIEM technologies
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
9,782 Employees

What We Do

Welcome to KPMG. We are a global network of professional firms providing Audit, Tax and Advisory services across a wide range of industries, government and not for profit sectors. KPMG provides a full range of services tailored to meet the unique needs of mid-sized, fast growing and family owned businesses. In Australia, KPMG has a long tradition of professionalism and integrity, combined with our dynamic approach to helping clients in a digital-driven world. We have approximately 6,700 people, including over 400 partners, with 13 offices around the country. Find out more about our Audit, Tax and Advisory services and benefit from our industry insights and thought leadership at: kpmg.com.au Twitter: @kpmgaustralia YouTube: KPMGAustralia Instagram: @kpmgaustralia

Similar Jobs

CrowdStrike Logo CrowdStrike

Analyst, Falcon Complete (Remote, AUS)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
5 Locations
11000 Employees

CrowdStrike Logo CrowdStrike

Architect

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
Melbourne, Victoria, AUS
11000 Employees

Ericsson Logo Ericsson

Security Director

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
Melbourne, Victoria, AUS
88000 Employees

HiBob Logo HiBob

Implementation Manager

HR Tech • Information Technology • Professional Services • Sales • Software
Remote or Hybrid
Australia
1350 Employees

Similar Companies Hiring

ABN AMRO Clearing USA LLC Thumbnail
Information Technology • Professional Services • Financial Services
Chicago, IL
215 Employees
Fora Thumbnail
Agency • On-Demand • Professional Services • Sales • Software • Travel • Hospitality
New York, NY
250 Employees
Energy CX Thumbnail
Greentech • Professional Services • Business Intelligence • Consulting • Energy • Financial Services • Utilities
Chicago, IL
108 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account