Our Vision
Our vision is to connect 1 billion people to the healing power of nature. A wholly owned subsidiary of Kirin Holdings, Blackmores Group is a leading natural health company with proud Australian heritage. We operate across Asia-Pacific and Greater China, delivering high-quality, evidence-based health solutions that help people live healthier lives.
Opportunity
Join Blackmores Group and play a critical role in protecting a trusted health and wellbeing organisation during a period of significant business and technology transformation. As our Senior Cyber Security Engineer (12 months fixed term role), you will lead the technical evolution of our Detection and Response capability across endpoint, cloud, identity, network and operational environments.
As a senior member of our Cyber Security team, you'll act as the subject matter expert for Detection & Response, partnering with technology teams, projects, vendors and managed security providers to strengthen Blackmores' security posture and response capability.
What's in it for you?
Play a key role protecting a global organisation through a significant SAP transformation program
Lead and influence cyber detection and response capabilities across endpoint, cloud, identity and network environments
Work with the modern Microsoft technology security stack.
This role reports to the Head of Cyber Governance and Operations; we are open for this person to be based in Sydney, working out either from our Surry Hills or Warriewood offices or based in Victoria, working from our Braeside Manufacturing Site. This role will follow our flexible work arrangements of working at least 3 days per week from office and 2 days per week from home.
This is a senior individual-contributor role with technical leadership responsibility. The position does not currently have direct reports but will provide technical direction to internal teams, service providers and incident-response participants.
What will you be doing?
Detection & Monitoring
Lead the development, tuning and optimisation of Blackmores' detection and monitoring capabilities
Maintain and enhance detection use cases across EDR, SIEM, cloud, identity and network security platforms
Assess monitoring coverage, identify detection gaps and improve visibility across the environment
Lead onboarding of new log sources and monitoring capabilities
Drive continuous improvement of alert quality and detection effectiveness
Incident Response
Lead technical investigations and response activities for cyber security incidents
Coordinate containment, eradication and recovery activities
Provide technical leadership during major cyber incidents
Support executive reporting, lessons learned and post-incident reviews
Maintain incident response procedures, runbooks and playbooks
Threat Hunting & Cyber Analytics
Lead proactive threat hunting activities across enterprise environments
Analyse emerging threats and determine relevance to Blackmores
Improve detection logic based on threat intelligence, trends and findings
Identify opportunities to strengthen cyber resilience and response readiness
Project & Technology Enablement
Provide cyber security SME input into projects, technology initiatives and transformation programs
Define monitoring, logging, alerting and response requirements for new technologies
Develop high-level Detection & Response integration requirements and designs
Ensure new platforms can be effectively monitored and supported by Cyber Security Operations
SOC & Vendor Management
Lead operational engagement with external SOC and managed security service providers
Review service performance and drive continuous improvement initiatives
Provide technical validation and direction during investigations and incidents
Ensure outsourced services align with Blackmores' cyber security objectives
Process & Continuous Improvement
Contribute to cyber security standards, frameworks and operational procedures
Support audit, compliance and cyber governance activities
Maintain operational documentation and response processes
Drive initiatives that improve Detection & Response capability maturity
What We're Looking For?
Experience
10+ years' experience in security operations, detection engineering, incident response or cyber defence roles
Demonstrated experience leading cyber investigations and incident response activities
Strong experience with EDR and SIEM technologies
Solid understanding of attacker techniques, MITRE ATT&CK, malware behaviours and security telemetry
Experience working with managed security providers and SOC environments
Technical Skills
Experience with Microsoft Defender for Endpoint or similar EDR platforms
Experience with Microsoft Sentinel or comparable SIEM solutions
Understanding of threat hunting, log analysis and event correlation
Working knowledge of Windows, Linux and network security concepts
Familiarity with SOAR capabilities and security automation
Desirable
Experience with Azure and Microsoft 365 security monitoring
Exposure to Operational Technology (OT) environments
Scripting capability using KQL, PowerShell or Python
Personal Attributes
Strong stakeholder engagement and influencing skills
Ability to communicate complex technical concepts in business language
Excellent problem-solving and decision-making capability
High levels of ownership, accountability and professional judgement
Calm, resilient and effective during high-pressure cyber incidents
At Blackmores, you'll join a purpose-led organisation committed to helping people take control of their wellbeing. You'll have the opportunity to make a real impact, contribute to meaningful business outcomes, and grow your career within a supportive and collaborative environment.
Agencies please note: this recruitment assignment is being managed directly by the Blackmores Talent Acquisition team. We will reach out to our preferred agency partners if required. Your respect for this process is appreciated.
- Locations
- Sydney, New South Wales, Australia · Victoria, Australia
- Timezones
- Australia
- Experience
- 10+ years