
SR INFORMATION SECURITY ENGINEER
Lumen Technologies11 days ago
Melbourne, AustraliaSenior
Responsibilities
- Design and implement MSSP-grade security platform architectures for multi-customer SOC delivery.
- Engineer and integrate SIEM, XDR, SOAR, EDR, NDR, cloud security, identity security, threat intelligence, ITSM, vulnerability, and exposure management platforms.
- Build and maintain security telemetry ingestion, parsing, normalization, enrichment, routing, retention, archival, and data-quality controls.
- Develop SOAR playbooks and automate workflows for phishing triage, suspicious sign-in response, IOC enrichment, endpoint containment support, case creation, notifications, and SLA tracking.
- Deploy, validate, tune, and maintain detection content across SIEM, XDR, EDR, cloud, identity, and network platforms, including MITRE ATT&CK-aligned and detection-as-code practices.
- Own lifecycle management, patching, upgrades, compatibility checks, rollback planning, and production validation for security platforms, agents, collectors, connectors, and integrations.
- Lead technical onboarding and service transition for MSSP customers from discovery and design through integration, acceptance, and SOC handover.
- Produce architecture diagrams, onboarding plans, integration checklists, validation test cases, runbooks, reporting requirements, and acceptance criteria.
Requirements
- 5+ years of experience in cybersecurity engineering, security platform engineering, SOC engineering, security data engineering, or security infrastructure.
- 3+ years of hands-on experience designing, deploying, maintaining, or upgrading SIEM and/or SOAR platforms in an enterprise, MSSP, MDR, SOC, or security consulting environment.
- Hands-on experience with at least one major SIEM platform, such as Microsoft Sentinel, Splunk, Cortex XSIAM, Google SecOps, FortiSIEM, QRadar, or an equivalent platform.
- Hands-on experience with at least one SOAR or automation platform, such as Cortex XSOAR, FortiSOAR, Splunk SOAR, Microsoft Sentinel automation, Azure Logic Apps, Google SecOps SOAR, or an equivalent platform.
- Experience with agent deployment and patching, collector and forwarder management, connector updates, platform upgrades, change control, rollback planning, and production validation.
- Strong understanding of security telemetry across cloud, SaaS, identity, endpoint, network, application, database, and infrastructure environments.
- Working knowledge of APIs, scripting, automation, secrets handling, service principals, certificates, secure integration design, and production support practices.
- Strong troubleshooting skills across source devices, agents, collectors, network paths, parsers, ingestion pipelines, storage, dashboards, alerts, playbooks, and ticketing integrations.
- Ability to create clear architecture diagrams, technical documentation, runbooks, onboarding artifacts, and stakeholder-ready explanations.
Benefits
- Lumen describes a collaborative, human, connected, and high-accountability work environment.
- Selected candidates may undergo background screening, which can include criminal-record, motor-vehicle-report, and drug screening checks depending on position requirements.
Tech Stack
Splunk