About this role
Role Title Principal Security Engineer Cyber Advisor Location Canberra, ACT Clearance required Must hold Negative Vetting Level 1 (NV1) Security Clearance. Company overview The Australian Federal Police (AFP) is Australia's national policing agency. The AFP protects Australians and Australia's interests by enforcing Commonwealth and Australian Capital Territory criminal law and safeguarding the Commonwealth from criminal activity in Australia and overseas. The organisation works closely with domestic and international partners to combat complex transnational serious and organised crime and continues to develop its technology capabilities to support operational and corporate services. Job Description An opportunity exists for a Principal Security Engineer Cyber Advisor to support the Australian Federal Police's Technology function. Cyber Advisors provide ICT security advice and assistance to government, including policy creation, project advice and assistance, and research. The successful candidate will provide technical leadership across enterprise SIEM and SOAR platforms, supporting security monitoring, detection engineering, automation, incident response and continuous improvement initiatives. The role requires extensive experience in the implementation, optimisation and administration of enterprise security monitoring and response capabilities. Duties and Responsibilities • Design and implement onboarding of log sources into the SIEM from cloud, on-premises, identity, endpoint and network platforms. • Develop and maintain parsing, normalisation and data quality standards for logs. • Build and maintain SOAR workflows to automate alert triage, enrichment, containment and response. • Integrate SIEM and SOAR platforms with security and IT tooling including EDR, IAM, ticketing, email, firewall and threat intelligence systems. • Develop, tune and maintain detection rules aligned to threat detection capability, attacker techniques and organisational risk. • Create and maintain SOC playbooks and operational runbooks mapped to automated workflows. • Reduce false positives and improve alert fidelity through continuous tuning and enrichment. • Support incident response through log analysis, detection insights and rapid rule development. • Conduct detection gap analysis following cyber events, incidents and threat intelligence updates. • Maintain performance, reliability and configuration of SIEM and SOAR platforms. • Implement dashboards for monitoring and health checks across SIEM and SOAR environments. • Develop and maintain clear documentation to support operational continuity and knowledge transfer. • Define and report on key detection and response performance metrics, including MTTD, MTTR, alert quality, automation and MITRE coverage. • Maintain currency in information technology processes and technical knowledge through ongoing professional development. • Establish and maintain effective business relationships and professional networks. • Contribute to improved ICT practices and procedures. • Provide mentoring, coaching and training to team members. • Work effectively within a small team and broader command environment. • Maintain records and information in accordance with organisational requirements. Knowledge/Skills required • Demonstrated hands-on experience as a technical lead implementing and administering enterprise SIEM platforms such as Microsoft Sentinel, Microsoft Defender, IBM QRadar, Elastic or Splunk. • Strong experience in security automation, writing complex queries, correlation rules, parsers and developing SOC playbooks. • Proven ability to optimise and integrate SIEM platforms. • Experience reducing false positives and improving alert quality. • Strong knowledge of detection engineering, incident response and security monitoring operations. • Experience integrating security platforms with enterprise security and IT systems. Employment benefits • Initial 36-month engagement. • Opportunity to support Australia's national policing agency. • Work on enterprise-scale cybersecurity, SIEM and SOAR capabilities. • Opportunity to contribute to the AFP's technology modernisation and cybersecurity uplift initiatives. • Work within a highly skilled technology environment supporting national security outcomes. Diversity and Inclusion We value diversity and are committed to creating an inclusive environment for all employees. Veterans Defence and Federal Government industry experience is highly desirable. We strongly encourage veterans and individuals with Defence experience to apply. Your unique skills and background are highly valued, and we are committed to supporting your transition into this role. About Cleared At Cleared, we provide tailored recruitment solutions to individuals seeking their next opportunity and to organisations searching for talent within Defence Industry, Intelligence and National Security.
Public Roles standardises this vacancy for easier discovery. The original advertiser controls the requirements, application process, and deadline. Report a problem through corrections.
Related active roles
Business Operations Officer
Department of Defence · Brindabella Business Park ACT · Permanent · $99,733–$112,431
Conservation Loans and Exhibitions Coordinator
National Gallery of Australia · Parkes ACT · Permanent · $92,164–$106,531
Rights & Permissions Manager
National Gallery of Australia · Parkes ACT · Permanent · $116,261–$132,660
Analyst
Australian Energy Regulator · Adelaide SA, Brisbane QLD, Canberra ACT, Melbourne VIC, Sydney NSW · Fixed term · $93,004–$98,617