About us
We’re growing, not slowing, here at Macquarie Technology Group because we’re passionate about doing things differently. We want to challenge the industry and look for better ways of doing things. As a team, Macquarie Government are hardworking, results and success focused. We also take the time to celebrate our success and make sure our people are doing work that makes a difference.
We believe that collaboration & team connection is key for success. This role will be based in Canberra on-site with one of our clients.
We require security clearance for this role you must be an Australian citizen to be eligible to obtain a security clearance or ideally already hold NV1 security clearance.
The Opportunity
We’re looking for a Security Engineer to join our growing security team in Canberra. This is a great opportunity for someone with hands-on SOC experience who is ready for more ownership, broader exposure, and the chance to build their capability in a high-performing SOC environment.
You’ll be working closely with experienced security professionals, building your Splunk capability, sharpening your incident response skills, and helping protect environments that genuinely matter. If you’re hungry to learn, humble in how you work, and smart in how you solve problems, this could be a brilliant next step.
What You'll Be Doing.
Monitoring, triaging, investigating, and responding to security alerts and incidents within our Security Operations Centre (SOC)
Onboarding and integrating new log sources into Splunk, including writing and tuning data inputs, parsing configurations, field extractions, and validating data quality
Developing, refining, and optimising Splunk searches, dashboards, alerts, and detection logic to improve threat detection capability
Investigating security events, identifying patterns, determining severity, and escalating incidents in line with established playbooks and procedures
Contributing to the continuous improvement and uplift of SOC processes, runbooks, and detection logic
Collaborating with internal cloud, network, endpoint, and engineering teams to improve log coverage and security monitoring across environments
Keeping up with the evolving threat landscape and bringing practical ideas to improve the team’s capability
About You.
A degree in Cyber Security, Information Technology, Computer Science, or a related field
18 months to 4 years of hands-on SOC experience, including practical experience onboarding, validating, and tuning log sources in Splunk
Strong working knowledge of common attack techniques, threat indicators, and the MITRE ATT&CK framework, with the ability to apply this knowledge during investigations
Experience working with security technologies such as firewalls, IDS/IPS, endpoint detection tools, cloud security platforms, and related monitoring tools
Confident analytical and problem-solving skills, with the ability to assess complex security events and make sound escalation decisions
Clear written and verbal communication skills, with the ability to explain incidents, risks, and findings to both technical and non-technical stakeholders
Nice to Have.
- Splunk certifications (e.g., Splunk Core Certified User or Power User)
- Exposure to SOAR platforms or security automation
- Experience with cloud environments (AWS, Azure, or GCP)
- Relevant industry certifications such as CompTIA Security+, CySA+, or equivalent
Candidates must be Australian citizens and eligible to obtain or hold an Australian Government security clearance.
If this role excites you Apply Now!