The Blackmores Group

Senior Cyber Security Engineer – Detection and Response

The Blackmores Group Sydney, New South Wales, Australia

Wellness and Fitness Services · 1,001-5,000 employees

6 h ago
security Principal (10+ yrs) Full-time Temporary Australia
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Senior Cyber Security Engineer will lead the technical evolution of detection and response capabilities across endpoint, cloud, identity, and network environments. They will also manage incident response activities, threat hunting, and provide technical leadership to internal teams and service providers.

What they look for

Cyber security Detection and response Incident response EDR SIEM Microsoft Defender for Endpoint Microsoft Sentinel Threat hunting Log analysis Network security Cloud security Identity security KQL PowerShell Python Stakeholder engagement

Requirements

Candidates must have 10+ years of experience in security operations, detection engineering, or incident response. Strong technical proficiency with EDR and SIEM technologies, particularly the Microsoft security stack, is required.

Benefits

Flexible work arrangements Supportive and collaborative environment

Full description

Our Vision

Our vision is to connect 1 billion people to the healing power of nature. A wholly owned subsidiary of Kirin Holdings, Blackmores Group is a leading natural health company with proud Australian heritage. We operate across Asia-Pacific and Greater China, delivering high-quality, evidence-based health solutions that help people live healthier lives.

Opportunity

Join Blackmores Group and play a critical role in protecting a trusted health and wellbeing organisation during a period of significant business and technology transformation. As our Senior Cyber Security Engineer (12 months fixed term role), you will lead the technical evolution of our Detection and Response capability across endpoint, cloud, identity, network and operational environments.

As a senior member of our Cyber Security team, you'll act as the subject matter expert for Detection & Response, partnering with technology teams, projects, vendors and managed security providers to strengthen Blackmores' security posture and response capability.

What's in it for you?

  • Play a key role protecting a global organisation through a significant SAP transformation program
  • Lead and influence cyber detection and response capabilities across endpoint, cloud, identity and network environments
  • Work with the modern Microsoft technology security stack.
  • This role reports to the Head of Cyber Governance and Operations; we are open for this person to be based in Sydney, working out either from our Surry Hills or Warriewood offices or based in Victoria, working from our Braeside Manufacturing Site. This role will follow our flexible work arrangements of working at least 3 days per week from office and 2 days per week from home.
  • This is a senior individual-contributor role with technical leadership responsibility. The position does not currently have direct reports but will provide technical direction to internal teams, service providers and incident-response participants.

What will you be doing?

Detection & Monitoring

  • Lead the development, tuning and optimisation of Blackmores' detection and monitoring capabilities
  • Maintain and enhance detection use cases across EDR, SIEM, cloud, identity and network security platforms
  • Assess monitoring coverage, identify detection gaps and improve visibility across the environment
  • Lead onboarding of new log sources and monitoring capabilities
  • Drive continuous improvement of alert quality and detection effectiveness

Incident Response

  • Lead technical investigations and response activities for cyber security incidents
  • Coordinate containment, eradication and recovery activities
  • Provide technical leadership during major cyber incidents
  • Support executive reporting, lessons learned and post-incident reviews
  • Maintain incident response procedures, runbooks and playbooks

Threat Hunting & Cyber Analytics

  • Lead proactive threat hunting activities across enterprise environments
  • Analyse emerging threats and determine relevance to Blackmores
  • Improve detection logic based on threat intelligence, trends and findings
  • Identify opportunities to strengthen cyber resilience and response readiness

Project & Technology Enablement

  • Provide cyber security SME input into projects, technology initiatives and transformation programs
  • Define monitoring, logging, alerting and response requirements for new technologies
  • Develop high-level Detection & Response integration requirements and designs
  • Ensure new platforms can be effectively monitored and supported by Cyber Security Operations

SOC & Vendor Management

  • Lead operational engagement with external SOC and managed security service providers
  • Review service performance and drive continuous improvement initiatives
  • Provide technical validation and direction during investigations and incidents
  • Ensure outsourced services align with Blackmores' cyber security objectives

Process & Continuous Improvement

  • Contribute to cyber security standards, frameworks and operational procedures
  • Support audit, compliance and cyber governance activities
  • Maintain operational documentation and response processes
  • Drive initiatives that improve Detection & Response capability maturity

What We're Looking For?

Experience

  • 10+ years' experience in security operations, detection engineering, incident response or cyber defence roles
  • Demonstrated experience leading cyber investigations and incident response activities
  • Strong experience with EDR and SIEM technologies
  • Solid understanding of attacker techniques, MITRE ATT&CK, malware behaviours and security telemetry
  • Experience working with managed security providers and SOC environments

Technical Skills

  • Experience with Microsoft Defender for Endpoint or similar EDR platforms
  • Experience with Microsoft Sentinel or comparable SIEM solutions
  • Understanding of threat hunting, log analysis and event correlation
  • Working knowledge of Windows, Linux and network security concepts
  • Familiarity with SOAR capabilities and security automation

Desirable

  • Experience with Azure and Microsoft 365 security monitoring
  • Exposure to Operational Technology (OT) environments
  • Scripting capability using KQL, PowerShell or Python

Personal Attributes

  • Strong stakeholder engagement and influencing skills
  • Ability to communicate complex technical concepts in business language
  • Excellent problem-solving and decision-making capability
  • High levels of ownership, accountability and professional judgement
  • Calm, resilient and effective during high-pressure cyber incidents

At Blackmores, you'll join a purpose-led organisation committed to helping people take control of their wellbeing. You'll have the opportunity to make a real impact, contribute to meaningful business outcomes, and grow your career within a supportive and collaborative environment.

Agencies please note: this recruitment assignment is being managed directly by the Blackmores Talent Acquisition team. We will reach out to our preferred agency partners if required. Your respect for this process is appreciated.

Similar roles