Senior Security Engineer - Architecture
Macquarie Technology GroupAbout us
We’re growing, not slowing, here at Macquarie Technology Group because we’re passionate about doing things differently. We want to challenge the industry and look for better ways of doing things. As a team, Macquarie Government are hardworking, results and success focused. We also take the time to celebrate our success and make sure our people are doing work that makes a difference. We believe that collaboration & team connection is key for success.
This role will be based in Sydney or Canberra. We require security clearance for this role, you must be an Australian citizen to be eligible to obtain a security clearance. The Opportunity
Are you a Security Engineer who thrives on building and enhancing cyber security solutions that protect critical Australian Government environments?
As a Senior Security Engineer - Architecture, you'll play a key role in designing, implementing and optimising security services across Macquarie Government's Secure Internet Gateway (SIG) and managed cyber security environments. Working alongside a highly skilled cyber team, you'll leverage technologies such as Microsoft Sentinel and Splunk to strengthen detection and response capabilities, deliver security outcomes for customers and drive continuous improvement across our security platforms. This role offers the opportunity to work on complex government environments while influencing the future direction of our cyber security services.
What you'll be doing.
- Design, implement and support cyber security solutions for Australian Government customers.
- Lead customer onboarding and implementation activities, including solution design and technical documentation.
- Build, configure and optimise Microsoft Sentinel and Splunk environments.
- Develop and tune security detections, analytics rules, dashboards and reporting capabilities.
- Investigate cyber threats, identify trends and implement preventative security controls.
- Support and enhance Secure Internet Gateway (SIG) infrastructure and managed security services.
- Collaborate with Security Operations, Infrastructure and Customer Success teams to deliver exceptional outcomes.
- Drive automation, process improvements and operational efficiencies through scripting and orchestration technologies.
- Provide technical guidance and escalation support for complex security incidents and customer enquiries.
About You.
- 3+ years' experience in Security Engineering, Security Operations or SIEM environments.
- Strong hands-on experience with Microsoft Sentinel and/or Splunk.
- Advanced Kusto Query Language (KQL) skills and/ or Splunk SPL.
- Experience developing and tuning SIEM detections, analytics rules and threat hunting use cases.
- Solid understanding of security operations, incident response and cyber threat detection.
- Strong knowledge of networking fundamentals, firewalls and security architecture principles.
- Understanding of log collection technologies including syslog and security telemetry.
- Experience working within environments aligned to Essential Eight, ISM or similar security frameworks.
- Strong troubleshooting skills with the ability to analyse and interpret large volumes of security data.
- Excellent communication skills with a customer-focused mindset.
Nice to Have.
- SC-100, SC-200, AZ-500 or equivalent security certifications.
- Splunk Enterprise Security certification.
- Experience with SOAR platforms and security automation.
- Scripting experience with Python, Bash or similar languages.
- Experience working within Federal Government or highly regulated environments.
- Current NV1 Security Clearance.