Skip to content
AEY
← All open roles
Cyber Security

Senior Security Engineer (Cleared)

Confidential client

Senior security engineering role inside a defence-mission software capability. Hands-on engineering across SIEM/SOAR (Splunk), EDR, vulnerability management, IAM and privileged access - operating in a cleared environment with strong autonomy and the option to mentor junior engineers.

About the role

A senior security engineering role inside a mission-software capability serving Australian defence. The role contributes to design, delivery and uplift of security engineering and operations across a complex enterprise environment - SIEM / SOAR engineering, endpoint and network security, vulnerability management, IAM and privileged access.

Strong autonomy expected. The role reports to the Security Lead and works closely with broader engineering teams. Real flexibility in scope depending on which of the listed areas the candidate brings the most depth in.

Why AEY is running this

Confidential client, defence-mission engineering capability. Multi-mandate AEY engagement.

Process

Three stages: technical conversation with the Security Lead, deep-dive engineering panel covering SIEM architecture and incident-response uplift, and a final discussion with capability leadership.

Responsibilities

  • SIEM / SOAR platform engineering (Splunk) - onboarding, health, optimised search queries, dashboards, alerts.
  • Security engineering across endpoint, network, gateway and adjacent technologies.
  • Vulnerability management tooling, integration and continuous improvement.
  • Support and uplift incident response capability using enterprise tooling.
  • Manage data ingestion and ensure reliability, security and scalability of the security stack.
  • Provide trusted security engineering advice to internal stakeholders.
  • Develop and uplift security operations system requirements.
  • Participate in change review and approval.
  • Mentor junior engineers and contribute to capability uplift.

Requirements

  • 5+ years' experience in security engineering or security operations with a strong hands-on focus.
  • Australian Citizen with active NV2 clearance, willing to uplift to TSPV.
  • OSA accreditation, or willingness to obtain.
  • Strong capability across SIEM/SOAR platforms - Splunk preferred.
  • Hands-on experience with EDR / Device Control / Application Control (Trellix, Carbon Black or similar).
  • Demonstrated work with vulnerability management solutions.
  • Strong engineering mindset and autonomous problem-solving.
  • Comfortable operating both independently and across a broader engineering team.

Bonus

  • Multi-Factor Authentication (MFA) deployment experience.
  • Identity & Access Management (IAM) engineering.
  • Privileged Access Management - CyberArk, BeyondTrust.
  • Hardware Security Module (HSM) integration.
  • Track record of mentoring engineers or running capability-uplift initiatives.
SplunkSIEMSOAREDRIAMCyber SecurityCleared NV2Defence
Not quite right?

Tell us what you are looking for.

If this role isn't the one, we likely have something adjacent - or coming up. A short conversation is enough to align.

Newsletter

A piece in your inbox, when it's worth it.

One short note a month - never more - when there's something specific worth saying about specialist hiring in our markets. No automation. No sales nudges. Unsubscribe with one click.