KPMG Australia Logo

KPMG Australia

Senior Security Operations Analyst

Posted 3 Days Ago
Be an Early Applicant
Hybrid
Melbourne, Victoria, AUS
Senior level
Hybrid
Melbourne, Victoria, AUS
Senior level
Lead detection engineering and Level 3 security operations for complex cyber incidents. Develop, test, tune, and maintain SIEM/XDR detection content; conduct threat hunting; map coverage to MITRE ATT&CK; improve telemetry, automation, and SOAR playbooks; and support major incident response. Mentor analysts, perform adversary emulation and purple-team validation, document detection logic, and collaborate with engineering, stakeholders, and clients to strengthen SOC capabilities.
The summary above was generated by AI
Job Description

Join our Security Operations Centre as a Senior Security Operations Analyst, where you will play a leading role in strengthening our detection capability and responding to complex cyber security incidents. With a primary focus on detection engineering, you will translate threat intelligence, hunting outcomes and incident findings into effective, tested and maintainable detection content across our SOC technology platforms.

Your Opportunity

As a senior cyber security practitioner, you will own the end-to-end lifecycle of detection content and provide Level 3 technical support to the SOC. You will act as the final escalation point for complex and high-severity incidents, while mentoring analysts and supporting the continuous improvement of our security operations capability.

Your responsibilities will include:

Detection engineering

  • Own the detection lifecycle, including requirements intake, research, development, testing, deployment, tuning and retirement.
  • Develop and maintain detection content across SIEM and XDR platforms, including analytics rules, correlation logic and custom queries.
  • Write and optimise advanced queries using technologies such as KQL in Microsoft Sentinel and Microsoft Defender XDR.
  • Apply detection-as-code practices, including version control, peer review, change management and automated testing.
  • Map detection coverage to the MITRE ATT&CK framework, identify gaps against prioritised threats and maintain a documented detection backlog.
  • Validate detections through adversary emulation, purple team exercises and controlled test scenarios before deployment to production.
  • Maintain clear documentation covering detection rationale, data dependencies, expected true-positive behaviour, triage guidance and response actions.
  • Measure and report detection performance using metrics such as alert volumes, precision, false-positive rates and time to detect.
  • Review, rewrite or retire detections that no longer provide value, including where platform, telemetry or environmental changes affect existing content.

Data, telemetry and platform enablement

  • Assess log-source coverage and data quality, and define onboarding requirements for new telemetry sources.
  • Develop and maintain parsers, data normalisation and schema alignment to support consistent and portable detection logic.
  • Partner with security engineering and platform teams to address gaps in logging, retention and telemetry fidelity.
  • Contribute to the configuration and optimisation of SIEM, SOAR and supporting SOC technologies, including ingestion cost management.
  • Build and maintain automation, enrichment and SOAR playbooks to improve triage consistency and reduce manual effort.

Level 3 security operations support

  • Act as the final technical escalation point for complex, ambiguous or high-severity incidents raised by Level 1 and Level 2 analysts.
  • Lead deep technical analysis across endpoint, identity, network and cloud evidence sources during major incidents.
  • Provide technical leadership across incident workstreams and support incident commanders with findings, timelines and containment options.
  • Conduct post-incident reviews, identify detection and response gaps, and translate findings into improved detection content.
  • Participate in escalation and on-call arrangements were required to support extended-hours coverage.

Threat intelligence and threat hunting

  • Translate threat intelligence into prioritised detection requirements aligned with the firm’s threat profile.
  • Conduct structured, hypothesis-driven threat hunts across SIEM, endpoint, identity and cloud telemetry.
  • Convert threat-hunting findings into repeatable detection logic, automation and documented hunting queries.
  • Monitor adversary tradecraft, vulnerabilities and emerging threats, assessing their relevance and detection implications.

Collaboration and continuous improvement

  • Mentor and coach Level 1 and Level 2 analysts in investigation techniques, query development and detection engineering concepts.
  • Peer review detection content created by other analysts and engineers, ensuring agreed quality standards are maintained.
  • Improve SOC playbooks, triage guidance and response workflows associated with detection content.
  • Work closely with internal technology teams and security specialists to deliver effective security outcomes.
  • Support client and stakeholder engagements where the SOC provides managed or advisory security services.

How are you extraordinary?

  • You are an analytical problem-solver who can navigate ambiguity, connect complex technical evidence and make sound decisions during high-pressure security incidents.
  • You are a collaborative technical leader who builds trusted relationships, shares knowledge and supports others to strengthen their investigation and detection capabilities.
  • You are a clear and influential communicator who can translate complex technical findings into concise guidance for analysts, incident leaders, stakeholders and clients.

Your Experience

To be successful in this role, you will bring:

  • Demonstrated experience developing and maintaining detection content within SIEM or XDR platforms, including rule authoring, testing and tuning.
  • Advanced capability in query languages such as KQL, SPL or equivalent, with experience writing and optimising complex queries.
  • Practical knowledge of MITRE ATT&CK and experience assessing and improving detection coverage against prioritised threats.
  • Senior-level experience in a Security Operations Centre or an equivalent operational cyber security environment.
  • Proven experience leading the analysis of complex security incidents across endpoint, identity, network and cloud environments.
  • Strong knowledge of enterprise and cloud log sources, telemetry, data quality and normalisation.
  • A sound understanding of cyber security frameworks, standards and industry-leading practices.
  • Strong written and verbal communication skills, including the ability to clearly document detection logic, investigation guidance and response actions.

The following experience will be highly regarded:

  • Experience applying detection-as-code practices, including source control and CI/CD pipelines for security content.
  • Scripting and automation capability using Python, PowerShell or SOAR playbook development.
  • Experience conducting adversary emulation or purple team testing to validate detection coverage.
  • Experience within professional services, consulting or a managed security services environment.
  • A tertiary qualification in Cyber Security, Computer Science, Information Technology or another relevant technical discipline.
  • Relevant industry certifications, such as SC-200, SC-300, AZ-500, CISSP, CompTIA Security+, ISC2 certifications or GIAC certifications including GCDA, GCIA, GCFA or GCTI.
  • Advanced training in detection engineering, threat hunting or SIEM technologies, supported by an ongoing commitment to professional development.

Additional Information

KPMG is a professional services firm with global outreach and deep sector experience. We work with clients across an array of industries to solve complex challenges, steer change and enable growth. 

Our people are what make KPMG the thriving workplace that it is and what sets us apart is that we know great minds think differently. Collaborate with a team of passionate, highly skilled professionals who’ve got your back. You’ll build relationships with unique and diverse colleagues who will provide you with the support you need to be your best and produce meaningful and impactful work in an inclusive, equitable culture.

At KPMG, you’ll take control over how you work. We’re embracing a new way of working in many ways, from offering flexible hours and locations to generous paid parental leave and career breaks. Our people enjoy a variety of exciting perks, including retail discounts, health and wellbeing initiatives, learning and growth opportunities, salary packaging options and more.

Diverse candidates have diverse needs. During your recruitment journey, information will be provided about adjustment requests. If you require additional support before submitting your application, please contact the Talent Attraction Support Team.

At KPMG every career is different, and we look forward to seeing how you grow with us.

KPMG Australia: grow with us!

Similar Jobs

Yesterday
In-Office
Melbourne, Victoria, AUS
Entry level
Entry level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Designs and integrates mechanical, fluid, thermal, and aircraft systems, including mechanisms, hydraulics, landing gear, and egress systems. Performs spatial integration, CAD modeling, mathematical analysis, optimization, troubleshooting, and technical documentation. Collaborates with production teams and suppliers to support manufacturing readiness, system requirements, design integrity, and proposal development. Requires Australian citizenship and eligibility to obtain and maintain Australian Government Security Clearance.
Top Skills: 3DxCad
Yesterday
In-Office
Melbourne, Victoria, AUS
Senior level
Senior level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Designs, analyzes, integrates, and manages complex electronic and electrical systems across their lifecycle. Responsibilities include power generation and distribution, circuit and signal analysis, EMI/EMC, parts and reliability management, verification and validation, requirements traceability, and hardware-software integration. The role coordinates with engineering teams, suppliers, and customers, researches emerging technologies, and ensures compliance with technical and operational requirements.
Top Skills: 3DxCC++CaptialDfm/AMatlabModel-Based Systems Engineering (Mbse)PythonTcp/IpXML
2 Days Ago
In-Office
Melbourne, Victoria, AUS
Senior level
Senior level
Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software
Leads and scales Shield AI’s international Aechelon sales organization, integrating the acquired business into Shield AI’s go-to-market strategy. Responsibilities include sales team leadership, post-acquisition integration, territory and account planning, pipeline and forecast management, complex defense and enterprise pursuits, cross-selling, partner development, and alignment with product, engineering, marketing, and customer engagement teams.
Top Skills: AechelonAi/MlAutonomy SoftwareCRMHivemindSaaSSimulation TechnologySynthetic RealityVisualization Platforms

What you need to know about the Melbourne Tech Scene

Home to 650 biotech companies, 10 major research institutes and nine universities, Melbourne is among one of the top cities for biotech. In fact, some of the greatest medical advancements were conceptualized and developed here, including Symex Lab's "lab-on-a-chip" solution that monitors hormones to predict ovulation for conception, and Denteric's vaccine for periodontal gum disease. Yet, the thousands of people working in the city's healthtech sector are just getting started, to say nothing of the tech advancements across all other sectors.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account