Cyber security specialist: MDR/MSIEM with options.
dotSec · Brisbane City, Queensland, Australia
قدّم وتابع مع أبلاي إيدجTechnical Security Analyst dotSec · Brisbane · Full timeIf you can look at an Entra ID sign-in log and tell the difference between a user on a new laptop and a replayed token, without pasting it into a chatbot first, then keep reading!We run a 24x7 managed SIEM on ISO 27001 and PCI DSS-compliant infrastructure, using Splunk Enterprise Security for Australian clients, and we’ve been doing it for 15 years. We also conduct almost any kind of testing and assessment exercise you can think of, and our comprehensive GRC services span IRAP, 27001 and PCI DSS. We’re looking for an independent, polite, experienced and collaborative expert to join our team of like-minded professionals. What you will actually doYou'll be busy!Onboard messy client data sources that don't come with a tidy plugin or structure. Write the transforms yourself, normalise to CIM, and make the data useful to the SIEM.Write detection content in SPL from a blank page, map it to ATT&CK, and tune correlation searches until the false positives stop without killing the information we need to see.Triage real notable events against our SLA. Decide whether an event is malicious and if so, escalate it, and be confident to defend your call.Keep Splunk running on Linux in AWS. Diagnose ingestion faults across CloudTrail, CrowdStrike Falcon, the M365 unified audit log and Entra ID.Get on the front foot and discover improvements. Help to run purple team test cases, find the gap where nothing fired, then close the gaps yourself.Review client Microsoft 365, Entra ID, Windows and AWS configurations against CIS Benchmarks and the Essential Eight, and write findings someone can act on straight away.Your work will vary based on demand but an average week will look like: Roughly 50% managed SIEM and detection engineering, 35% configuration reviews, testing and assessment, threat hunting and purple team, 15% keeping our own ISO 27001 ISMS and related infrastructure in top notch condition.The Microsoft half of the jobOur infrastructure (on prem and SaaS) runs on Linux and AWS. Most of what we look at does not. The bulk of the telemetry we monitor, and most of the configurations we assess, is Microsoft. This part of the role is really important, so read this section properly.You need to be able to read the logs and say what happened:Windows. Security event logs on Windows Server and Windows 11. Logon types and what they imply, privilege assignment, process creation, service and scheduled task installs, what a 4625 storm actually means… and when it means nothing.Active Directory. As an attack surface, not an org chart. Kerberos behaviour, delegation, replication, group membership changes, GPO and Bloodhound.Entra ID. Sign-in and audit logs, Conditional Access evaluation results, CAP reviews and improvements, authentication methods, device identity, risk detections. Enough to separate a genuine new device from token theft.Microsoft 365. The Unified Audit Log during a suspected compromise. Inbox rules and forwarding, BEC, mailbox delegation, OAuth consent grants, SharePoint and OneDrive file access, anonymous sharing links, bulk download.Azure. Activity logs, NSGs and flow logs, resource-level RBAC, AzureHound, Prowler, and Azure Lighthouse delegated access into client tenants.Then the two steps that matter most:Confirm the shortcoming. How do you go and prove a control is missing, misconfigured or being bypassed. Not "the tool flagged it", but "I checked, here is the evidence, here is what it lets an attacker do, and here’s what we need to do to reduce the risk."Recommend the remediation. The specific setting, policy or configuration change, written so the client's Windows admin can action it without twenty ticket iterations for never-ending clarification.On the LLM question, since it will come up: You can use AI/LLM tooling at dotSec in accordance with our policies. But first, you need to be able to show that you can do this kind of work unaided. When a client is on the phone and something is actively going wrong, the answer has to come from you, not some LLM that coughs up a plausible, reasonable-sounding suggestion… that turns out to be WRONG! The technical interview is conducted on that basis and you won’t have access to an LLM, so don’t continue here if that thought makes you uneasy.What else we are asking forWe care about what you have done yourself, not what your team did around you.You have onboarded a source that had no supported app and got it parsing properly.You have written a search from scratch, not just run one someone else saved.You have taken a noisy detection and made it quiet without making it useless, and can explain exactly what you changed.You have investigated something suspicious and worked through to a defensible conclusion and written that conclusion down, and had it reviewed, accepted and actioned.You are comfortable at a Linux command line when something is broken and there is no runbook for it.You script enough Bash, PowerShell or Python to avoid doing the boring part twice.Between 2 to 4 years in IT or security, at least one of them hands-on in a SOC, MSSP or security engineering role. Splunk preferred. Real depth in Sentinel, Elastic or QRadar counts, and SPL is learnable if the fundamentals are there. However, the Microsoft knowledge above is not learnable on the job at the pace we need it, so you’ll need to bring those skills to the table on day 1.Worth knowing before you applyThis is a Brisbane based job. There is an after-hours on-call roster, shared across the team. You get to do some WFH after you get through probation. There are no WFH long-weekends. You will report to the director. Architecture and SLA accountability sit with senior staff, and client deliverables are peer reviewed before release. We run a supporting and collaborative environment so while you get room to make decisions, you won't end up left alone with them.Certifications are sponsored, and we’ll cover agreed costs and on-the-job study time. Splunk, AWS, CrowdStrike, SC-200, BSCP, ISO 27001.You must have, from day 1, the right to work in Australia, and you must be willing to undergo a background and criminal history check.How to applySend your CV and a few paragraphs about one thing you built, broke or fixed yourself. A detection you wrote. An ingestion fault you chased down. A Windows or M365 finding you confirmed and got remediated. Tell us what was wrong, what you tried, and what worked. And you should skip the tool and buzzwords lists; we have all those already!Shortlisted candidates will be invited to take part in a technical exercise and write a one-page report: We will give you three configuration review findings, you turn them into risk-rated recommendations with a short executive summary. Then a technical interview where we go deep on what you have done.If you got this far and started thinking about the last sign-in log you pulled apart, then apply! We’d love to hear from you.