Metrea
Security Engineer (SIEM)
Brisbane, Australia
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →hirly's read of this role
- Role family
- Engineering
- Seniority
- Mid level
- Country
- AU
- Work mode
- On-site / unstated
- First seen by hirly
- 29 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Company Overview
Metrea delivers effects-as-a-service to national security partners across five domains and more than a dozen mission areas. These include airborne ISR, electronic warfare, secure communications, aerial refueling, special air missions, aerial firefighting, and advanced simulation. We own the whole stack: designing, building, and operating turnkey capabilities that give our partners decisive, asymmetric advantage against rapidly evolving threats.
Our operating model is built around three interlocking pillars. The Support Groups provide a global shared-service – spanning people, finance, platform, operations, legal, and engagement. This frees up our Core Groups, who develop and own mission capabilities end-to-end, to focus entirely on delivery. The Market Groups apply a regional lens, ensuring that our agile and adaptable capabilities remain aligned to the wicked problems that matter most to our partners across the Americas, EMEA, and Asia-Pacific.
At the heart of our model is a simple but powerful idea: be a true partner with skin in the game. Our partners need effects, not just equipment. By owning the full stack – from the lab to the field – we are able to drive a continuous cycle of innovation that keeps our partners ahead. It's a fast-moving, intellectually demanding environment where talented people are given real responsibility, work on problems that matter, and contribute to an enterprise that is growing quickly and deliberately.
Headquartered in Washington, DC, with facilities across the United States, the United Kingdom, as well as Continental Europe and Asia-Pacific.
Group Overview
Metrea is actively building its presence in Australia as part of a deliberate, globally coordinated expansion into the Asia-Pacific region. Our Asia-Pacific Market Group, headquartered in Brisbane with an additional office in Perth, is the enterprise's dedicated regional interface — connecting Australia's national security community with Metrea's full suite of capabilities across three core domains: Aerospace, Electromagnetic & Cyber, and Digital & Synthetic. Metrea is now bringing that same depth of mission expertise and proven operating model to Australia.
- Underpinning these capabilities is a global network of Support Groups spanning people, finance, platform, operations, legal, and engagement — ensuring that as we grow in Australia, we do so with the full weight of an established global enterprise behind us.
- Metrea's solutions are built for elegance: effective, efficient, and evolving — enabling our partners to scale capacity and achieve asymmetric advantage against rapidly evolving threats.
Position Summary
We are seeking a skilled and motivated Security Engineer to join our Australian team. This role is responsible for the design, documentation, implementation, optimisation, and ongoing management of security monitoring and detection capabilities across a classified Microsoft Azure environment.
The Security Engineer will play a key role in the administration and continuous improvement of the organisation's Microsoft Sentinel SIEM platform, Azure Log Analytics workspaces, security automation, and detection engineering capabilities. Working closely with security operations, infrastructure and application teams, the role will focus on enhancing visibility, reducing risk, improving threat detection coverage, and supporting effective incident response outcomes.
The successful candidate will be responsible for SIEM architecture and configuration, use case development, alert tuning, threat hunting, playbook automation, and the investigation of security events and incidents. They will leverage the Microsoft security ecosystem to develop and maintain effective monitoring and response capabilities aligned with evolving cyber threats and business requirements.
This position requires strong technical expertise in cloud security, security monitoring, and detection engineering, combined with a proactive approach to continuous improvement and cyber defence.
What You'll Do
Design, implement, and continuously improve security monitoring and detection capabilities within Microsoft Sentinel and Azure Log Analytics, ensuring effective visibility across the organisation's technology environment. Develop and optimise SIEM use cases, analytics rules, and automated response playbooks while investigating security events and enhancing the organisation's threat detection and incident response capabilities. Responsibilities fall into the following main areas:
Administer, configure, and maintain Microsoft Sentinel and supporting Azure security monitoring platforms
Design, implement, and continuously improve SIEM detection use cases and analytics rules
Perform alert tuning and optimisation to improve detection fidelity and reduce false positives
Develop and maintain automated response playbooks using Azure Logic Apps and Sentinel automation capabilities
Conduct threat hunting activities using Microsoft Sentinel, KQL, and threat intelligence sources
Investigate, analyse, and support the response to cyber security incidents and alerts
Develop and maintain security monitoring dashboards, workbooks, and operational reporting
Integrate and onboard new data sources to improve visibility across the technology estate
Map detections and use cases to MITRE ATT&CK techniques and threat-based frameworks
Collaborate with infrastructure and application teams to address identified security risks
Identify opportunities to improve detection coverage, monitoring effectiveness, and incident response processes
Support security audits, compliance activities, and cyber security assessments as required
What You Bring
The successful candidate will have the following key qualifications, skills, and experiences:
5+ years of experience in cyber security, security operations, detection engineering, or SIEM administration roles
Demonstrated experience managing enterprise-scale SIEM platforms and security monitoring services
Experience leading technical initiatives related to security monitoring, detection improvement, and incident response maturity
Experience working in government, Defence, critical infrastructure, or highly regulated environments
Experience supporting and authorising systems operating at PROTECTED, or higher security classifications is highly desirable
Demonstrated experience applying ISM and PSPF requirements within operational environments
Advanced knowledge of Azure Log Analytics, Kusto Query Language (KQL), and data ingestion architecture
Experience designing, implementing, and maintaining SIEM use cases, analytics rules, workbooks, watchlists, and data connectors
Proven ability to analyse complex security events and translate findings into actionable improvements
Familiarity with Microsoft security technologies including:
Microsoft Defender XDR
Microsoft Defender for Endpoint
Microsoft Defender for Identity
Microsoft Defender for Cloud
Microsoft Entra ID (Azure AD)
Experience working within cloud-first or hybrid enterprise environments
Experience onboarding and integrating log sources from cloud, infrastructure, network, and third-party security platforms
Strong understanding of cyber security monitoring, threat detection, incident response, and security operations practices
Knowledge of common attack frameworks such as MITRE ATT&CK and their application to detection and threat hunting activities
Understanding of security automation, orchestration, and response (SOAR) principles
Experience creating dashboards, workbooks, reporting, and operational metrics for security monitoring and compliance
Additional Eligibility Qualifications
Bachelor or higher degree in Cyber Security, Information Technology, Computer Science, Information Systems, Engineering, or relevant industry experience
The below certifications are highly desirable.
Microsoft Cer
Similar jobs
- Security Engineer, AWS Customer Incident Response Team (CIRT)Amazon · Brisbane, Queensland, AUS; Perth, Western Australia, AUS; Sydney, New South Wales, AUS; Melbourne, Victoria, AUSFirst seen 2d ago
- Security Engineer, Threat IntelligenceSnapchat · Sydney, AustraliaFirst seen today
- Security Engineer, Threat IntelligenceSnapchat · Sydney, AustraliaFirst seen today
- NMP80323 - ICT Solutions Implementations Security EngineerPae · OCONUS-Australia-SydneyFirst seen yesterday
- Security Engineer, AWS Cloud ResponseAmazon · Melbourne, Victoria, AUSFirst seen 2d ago
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job