Cyber Threat Intelligence (CTI) Detection Engineer
Date: 6 Aug 2026
Location: AU
Company: Department of Parliamentary Services
Job Details
Job Title: Cyber Threat Intelligence (CTI) Detection Engineer
Employment Type: Ongoing
Classification: Parliamentary Executive Level 1
Closing Date: 11:30pm AEST, 24 August 2026
Contact: Brendon McKinley, (02) 6277 2828, brendon.mckinley@aph.gov.au
The Opportunity
The Department of Parliamentary Services (DPS) supports the operation of the Australian Parliament by providing secure, reliable and effective ICT services across Australian Parliament House (APH). Within the Information Services Division, the Cyber Security Branch protects DPS and APH systems, information and users from cyber security threats through governance, assurance, engineering, monitoring, detection and response activities.
The role sits within the Cyber Security Operations Centre (CSOC), which is responsible for monitoring, detecting and responding to cyber security events and incidents across DPS-supported APH environments. CSOC operates in a high-tempo and nationally significant context, supporting the security and continuity of parliamentary services by turning security telemetry, threat intelligence and operational findings into practical protective outcomes.
As the Assistant Director Detection Engineering and Technical CTI, you will lead and manage the CSOC detection lifecycle management process. This includes identifying detection gaps, developing and testing detection hypotheses, deploying and tuning analytics, maintaining technical cyber threat intelligence workflows, and ensuring detections remain current, effective and actionable as adversary tactics, techniques and procedures evolve.
The role works closely with CSOC analysts, cyber engineering, Cyber Hunt and Threat Emulation (CHATE), Cyber Intelligence and Assurance, system owners, service providers and senior stakeholders. It provides expert technical advice on detection coverage, logging requirements, telemetry gaps, alert quality, response guidance and practical uplift options that improve DPS’s ability to detect and respond to cyber security threats.
This is a unique opportunity to shape an intelligence-led detection engineering capability in a critical national institution. The successful candidate will help connect technical cyber threat intelligence with real-world monitoring and response.
Who we are looking for
We are looking for a technically strong, analytical and outcomes-focused cyber security professional who can translate intelligence, incident findings and adversary tradecraft into practical detection and response improvements. The ideal candidate will be comfortable working with ambiguity, prioritising competing operational demands, and producing clear, evidence-based advice for both technical and non-technical audiences.
The successful candidate will demonstrate:
- experience leading or contributing to detection engineering, detection lifecycle management, security monitoring or cyber security operations in a complex enterprise environment;
- the ability to convert cyber threat intelligence, adversary tactics, incident lessons, vulnerability information and threat hunting outcomes into practical detection logic, alerting, response guidance and measurable uplift;
- strong technical knowledge of security telemetry, logging, SIEM, SOAR, endpoint detection and response, cloud security monitoring and cyber threat intelligence platforms;
- sound analytical and problem-solving skills, including the ability to assess detection effectiveness, reduce false positives, identify missed detection opportunities and provide evidence-based recommendations;
- well-developed communication, stakeholder engagement and documentation skills, including the ability to brief technical and non-technical audiences and negotiate practical outcomes with system owners and service providers;
- a collaborative, curious and improvement-focused approach, with the judgement to balance operational urgency, cyber risk and business impact.
Relevant qualifications or demonstrated equivalent experience in cyber security, information technology, computer science, intelligence, security operations or a related discipline are required. Desirable experience includes working with SIEM and SOAR platforms, endpoint detection and response, cloud security monitoring, cyber threat intelligence platforms, MITRE ATT&CK, structured threat intelligence standards and Australian Government cyber security frameworks including the ISM and PSPF.
Job Specific Requirements:
• The successful applicant will be required to obtain and maintain a Negative Vetting 1 (Confidential/Highly Protected/Secret) security clearance.
At DPS, we are committed to building a diverse and inclusive workplace that ensures all our people can contribute to our shared purpose. We encourage applications from Aboriginal and Torres Strait Islander people, people with disability, people with caring responsibilities, people who identify as LGBTQIA+, people from cultural and linguistically diverse backgrounds, people who identify as neurodivergent, and mature aged people.
Duty Statement
Classification: Parliamentary Executive Level 1
Branch: Cyber Security
Section: Cyber Security Operations
Immediate supervisor: Director, Cyber Security Operations
Duty Statement
Under limited/general direction undertake duties in accordance with the agreed standards for the specified classification. The duties will include, but are not limited to, the following:
1. Lead and manage the CSOC Detection Lifecycle Management process, including the identification, prioritisation, development, testing, deployment, tuning, health monitoring and retirement of cyber security detections across DPS and APH environments.
2. Translate cyber threat intelligence, incident findings, vulnerability information, threat hunting outcomes and adversary tactics, techniques and procedures into actionable detection hypotheses, analytics, alert logic, response guidance and playbooks.
3. Develop, maintain and assure technical CTI products, systems and workflows that support CSOC monitoring, detection and response, including indicator management, enrichment processes and intelligence-led detection engineering.
4. Provide expert technical advice to CSOC analysts, cyber engineering, cyber intelligence, CHATE, system owners, service providers and senior stakeholders on detection coverage, logging requirements, telemetry gaps, detection health, alert quality and practical uplift options.
5. Prepare clear, evidence-based technical reports, briefs, detection documentation, assurance artefacts and recommendations that communicate cyber risk, operational impact, detection effectiveness, known limitations and remediation priorities to technical and non-technical audiences.
6. Contribute to the continual uplift of CSOC capability by developing frameworks, procedures, quality assurance practices, metrics, tooling, automation and stakeholder engagement approaches aligned to DPS cyber security objectives, the CSOC Charter, the Cyber Security Incident Response Plan, the System Logging and Audit Plan, the ISM and the PSPF.
Selection Criteria
1. Demonstrated experience leading or contributing to detection engineering, detection lifecycle management, security monitoring or cyber security operations in a complex enterprise environment, including the development, testing, tuning and sustainment of detections.
2. Demonstrated ability to convert cyber threat intelligence, adversary tradecraft, incident lessons, vulnerability information and threat hunting outcomes into practical detection logic, alerting, response guidance and measurable improvements to cyber security operations.
3. Strong technical knowledge of security telemetry, logging, SIEM, SOAR, endpoint detection and response, cloud security monitoring and cyber threat intelligence platforms, including the ability to identify data source requirements and resolve detection gaps.
4. Demonstrated analytical and problem-solving ability, including the capacity to assess detection effectiveness, reduce false positives, identify missed detection opportunities, evaluate technical risk and provide evidence-based recommendations in a high-tempo operational environment.
5. Well-developed communication, stakeholder engagement and documentation skills, including the ability to brief technical and non-technical audiences, negotiate outcomes with system owners and service providers, and produce clear technical documentation, reports and procedures.
6. Eligible qualifications and/or other technical requirements: relevant qualifications or demonstrated equivalent experience in cyber security, information technology, computer science, intelligence, security operations or a related discipline. Desirable experience includes working with SIEM, SOAR, endpoint detection and response, cloud security monitoring, cyber threat intelligence platforms, detection-as-code practices, MITRE ATT&CK, structured threat intelligence standards and Australian Government cyber security frameworks including the ISM and PSPF.
Employees of DPS are required to be able, and to be seen to be able, to provide professional advice and services to all Senators and Members without favour or prejudice.
How to apply
Please upload a one page pitch describing how your skills and experience would contribute to the role and work of the department.
Your pitch is an opportunity to tell us why you want to work at DPS, why you are interested in the role and what you can offer in the role. Frame your pitch around the role description and relevant ILS Profile. Make sure to use relevant examples and accomplishments that demonstrate your ability to perform the role.
For additional guidance when crafting you application, please refer to the DPS Recruitment - Candidate Information Pack, which provides helpful tips on how to structure your pitch and highlight your most relevant skills and experience effectively.
Our purpose and values
We proudly provide innovative, unified, and client-focused services to the Australian Parliament and parliamentarians. We are a values driven department, placing our values at the heart of everything we do; from our service offerings and decision making to our interactions with stakeholders and each other.
Our people are employed in a broad and unique range of professional, customer service and trade-based roles, all joined by a shared purpose: to make an enduring contribution to Australia’s parliamentary democracy. We have an inclusive workplace that reflects the diversity of the community we serve. While we come from all walks of life, we share a commitment to care for and protect our iconic workplace.
Every year, almost one million people visit Australian Parliament House to experience the parliamentary process, the building’s architecture, nationally significant art collections, events, tours, and food and dining experiences – all made possible by our people, who are active participants in an environment where no two days are the same.
What we can offer
Join our community based on innovative, unified, and client-focused services, where your skills and development will be nurtured. You will also enjoy:
- flexible working arrangements can be negotiated in accordance with our Enterprise Agreement and the operational needs of the roles
- ongoing opportunities to learn and develop new capabilities
- a competitive remuneration package
- free on-site parking
- free gym membership and access to recreational facilities available a APH
- childcare (pending availability), banking services, post office, value-for-money dining options and more available at APH.
Salary
An attractive salary, which could be negotiated with the successful candidate, is on offer.
Conditions of Employment
Employment opportunities at the department are subject to a range of conditions prescribed in the Parliamentary Service Act 1999 which include:
- Australian citizenship: Section 22 of the Parliamentary Service Act 1999 requires that employees of the Parliamentary Service are generally required to be Australian citizens. However, if you are not an Australian citizen you may be considered for engagement on the condition that you are able to gain Australian Citizenship within a specified time. Failure to obtain citizenship within the timeframe could lead to termination of employment.
- Loss and resumption of Australian citizenship: Under historical provisions of the Australian Citizenship Act 1948 (section 17), some Australian citizens automatically lost their citizenship if they voluntarily acquired the citizenship of another country between 26 January 1949 and 3 April 2002. This loss occurred by operation of law and may not have been known to the individual at the time. Although these provisions were repealed in 2002 to allow dual citizenship, the repeal did not restore citizenship that was previously lost. Individuals who believe they may be affected are recommended to seek advice about resuming their Australian citizenship. Further information, is available on the Department of Home Affairs website.
- Applicants who progress to the offer stage with our department who have been affected by the loss of citizenship as outlined above will be required to demonstrate within a reasonable time that they have resumed, or are actively undertaking the process to resume, Australian citizenship.
- Security clearance and character clearance: the preferred applicant will be required to obtain and maintain a security clearance at the level specified, as well as complete and be deemed suitable through a Nationally Coordinated Criminal History Check.
- Health assessment: a pre-employment health assessment will be required where there are physical or medical requirements for the role.
- External Work Approval: Employees must seek approval for any paid employment outside the department and declare voluntary activities that could impact their role.