SentinelOne
Associate MDR Security Analyst
Melbourne, Australia· HYBRID
About the role
Managed detection on the vendor's own telemetry, which means you see the raw signal rather than a summary. Shift work with proper handover, and a strong bias toward writing detections instead of clearing the same alert twice.
What you will do
- Triage and investigate endpoint and cloud detections
- Escalate confirmed intrusions with a clear timeline
- Propose detection improvements from what you saw
What they ask for
- Understanding of Windows and Linux process behaviour
- Able to read a command line and say why it is suspicious
- Willing to work a rotating shift
Nice to have
- Detection engineering experience
- Sigma or KQL
What applying with Rooted means
This role accepts applications with Rooted context. Instead of sending only a resume, you can attach a verifiable credential with your proofs, rank, and technical evidence.
Your application includes your Rooted credential: rank, verified proofs, and supporting evidence.
You can read this role without an account. To apply you need a Rooted credential.
This role is curated by Rooted. Rooted is not the hiring company unless explicitly stated. The hiring company is SentinelOne. Confirm the final details with the original source or during the application process.
Posted 2026-08-12