SR INFORMATION SECURITY ENGINEER
Lumen Technologies
- Location
- MELBOURNE, AUS
- Work model
- On-Site
- Level
- Senior
- Posted
- 5h ago
Skills
About this role
Lumen is the trusted network for the AI‑powered world, connecting people, data, and applications through our expansive fiber network and connected ecosystem. We enable secure, high‑performance connectivity across cloud, edge, and AI workloads for enterprises, governments, and communities. At Lumen, you’ll work on infrastructure customers rely on today and build for what’s next, where performance, security, and resilience matter. This is a high accountability environment where bold ideas drive real innovation for our customers, partners, and industry. The work is challenging, expectations are clear, and trust is built into how we operate. If you’re ready to take ownership, deliver meaningful impact, and help shape the future of AI‑ready connectivity, join us today. The Role We are hiring a Security Platform & SecOps Engineer to design, build, automate, operate, and continuously improve the security platforms that power modern Managed Security Services Provider (MSSP) Security Operations Centre services. This is a senior hands-on engineering role for someone who can take end-to-end ownership of platforms across SIEM, XDR, SOAR, security data pipelines, threat intelligence, cloud security, identity protection, exposure management, and SecOps automation. In one sentence: Own and engineer the end-to-end MSSP security platform ecosystem to deliver scalable, automated, resilient, and measurable 24x7 SOC services. The Main Responsibilities Platform Architecture & Engineering Design and implement MSSP-grade security platform architectures for multi-customer SOC service delivery. Engineer unified SecOps capabilities across SIEM, XDR, SOAR, EDR, NDR, cloud security, identity security, threat intelligence, ITSM, vulnerability, and exposure management platforms. Develop reference architectures, integration standards, data flow diagrams, onboarding patterns, and engineering guardrails. SIEM, Security Data Pipelines & Telemetry Build and maintain reliable telemetry ingestion using agents, collectors, syslog, CEF/LEEF, APIs, event hubs, forwarders, cloud connectors, custom connectors, OpenTelemetry where applicable. Develop parsing, normalization, schema mapping, enrichment, routing, filtering, retention, archival, and data quality controls. Prioritize critical security telemetry across endpoint, identity, cloud, SaaS, email, firewall, proxy, VPN, DNS, server, application, and database sources. Monitor ingestion health, data volume, parser quality, delayed or missing data, connector failures, duplication, query performance, and storage/licensing usage. SOAR, Automation & AI-Assisted SecOps Design and implement SOAR playbooks for enrichment, triage, escalation, evidence collection, notification, reporting, and case management. Integrate security platforms using REST APIs, webhooks, scripts, connectors, service principals, certificates, managed identities, and secure secrets handling. Automate repeatable SOC workflows such as phishing triage, suspicious sign-in response, IOC enrichment, endpoint containment support, case creation, and SLA tracking. Apply human-in-the-loop controls for high-impact response actions Detection Engineering Enablement Work with SOC analysts, threat hunters, and detection engineers to deploy, validate, tune, and maintain detection content across SIEM, XDR, EDR, cloud, identity, and network platforms. Support MITRE ATT&CK-aligned detection coverage, telemetry gap analysis, threat-informed defence, and purple-team validation. Enable Detection-as-Code practices, including version control, peer review, testing, deployment, rollback, and reusable detection content libraries. Platform Lifecycle, Patching & Upgrades Own lifecycle management for SOC platforms, endpoint agents, cloud agents, collectors, forwarders, connectors, integrations, certificates, API credentials, and supporting infrastructure. Plan and execute agent patching, collector upgrades, connector updates, integration maintenance, and