SIEM Expert (Principal Security Engineer)
Our client is a global managed security services provider with a strong presence across Australia and a portfolio of enterprise and government customers. They are hiring a Principal SIEM Engineer to join their Cyber Security Incident Response team. This is a hands-on platform engineering role. You will own and improve the SIEM environment across a portfolio of clients, write detection rules, manage log ingestion, and act as the senior technical escalation point for the team.
What you will be doing
- Hands-on platform ownership across Palo Alto XSIAM, SPLUNK, or Microsoft Sentinel
- Detection rule and use case creation, correlation searches, CIM normalisation
- Log ingestion design, agent configuration and onboarding new data sources
- Custom dashboard creation, RBA configuration and platform health management
- Senior technical advisor to clients and engineering escalation point for the team
- Contributing to incident response discussions from an engineering standpoint
What we are looking for
- 10+ years of overall IT experience with at least 8 years in security operations
- Hands-on SIEM platform engineering experience with Splunk, Sentinel or XSIAM
- Strong query language skills (SPL, KQL or XQL)
- Experience writing detection rules and use cases from scratch
- Background in a SOC, CSIRT or managed security services environment
- Exposure to the analyst and operations side of SOC work
- Excellent communication skills suited to a client-facing role
Nice to have
- Splunk Enterprise Security Certified Admin or Splunk Architect certification
- Palo Alto XSIAM Engineer or PCNSE certification
- SOAR experience (XSOAR, Splunk Phantom)
- Vulnerability management exposure (Qualys, Tenable)
- CISSP, GCIH, GCIA or similar industry certifications
The setup
- Permanent role, no sponsorship available
- Hybrid working, 2-3 days in office
- Rotating roster across business hours only (7am-7pm AEST). No overnight shifts.
- Join an established CSIR team
Aboriginal and Torres Strait Islander Peoples are encouraged to apply.
To apply please click apply or call Cody Berry on 02 8289 3123 for a confidential discussion.
About the job
Contract Type: Permanent
Specialism: Technology & Digital
Focus: Cyber Security & Risk
Industry: IT
Salary: AUD150,000 - AUD170,000 per annum + + Super + Bonus
Workplace Type: Hybrid
Experience Level: Mid Management
Location: Sydney CBD
FULL_TIMEJob Reference: 7TMBIN-A92D05F8
Date posted: 26 May 2026
Consultant: Cody Berry
sydney technology-and-digital/cyber-security-and-risk 2026-05-26 2026-06-25 it Sydney CBD New South Wales Sydney CBD AU 2000 AUD 150000 170000 170000 YEAR Robert Walters https://www.robertwalters.com.au https://www.robertwalters.com.au/content/dam/robert-walters/global/images/logos/web-logos/square-logo.png true