Confidential mandate
Detection Engineering Coverage Director — Digital Banking
Planned Hiring / New
Detection Engineering Coverage Director mandate in Sydney, Australia · Digital Banking
An Australian digital bank needs an independent director to rebuild detection coverage around attack paths, validate telemetry and deliver an analyst-operated engineering system within five months.
The mandate
Thousands of alerts coexist with untested gaps around privileged identity, cloud control-plane and payment-administration paths. Several rules have no named threat behaviour, source dependency or regression case, while analysts compensate through personal searches that are neither versioned nor available overnight. The defined problem is to create measurable detection coverage from plausible adversary action to analyst decision, rather than tune the existing queue cosmetically.
Deliverables include an attack-path inventory, telemetry fitness register, detection-as-code library, validation harness, triage evidence standard, coverage dashboard and engineering runbook. Every production detection must identify its data fields, expected attacker variation, severity logic, analyst decision and retirement owner; blind spots require an explicit compensating response rather than an optimistic coverage score.
Milestone one on 30 October 2026 accepts priority paths and data gaps; milestone two on 4 December delivers the first validated library; milestone three on 22 January 2027 concludes controlled purple-team testing; final delivery on 26 February requires bank-operated deployment, regression and acceptance. Each milestone includes failed simulations and deferred telemetry so reviewers see what remains undetectable.
Acceptance requires seeded behaviours to trigger with stated latency, analysts to reach reproducible conclusions, false positives to remain within threshold and engineers to modify and test detections unaided. Operational risk will sample one privileged, one cloud and one payment attack path, including a telemetry outage, and approve only when the resulting limitation is visible in the dashboard and response playbook.
The client bank provides telemetry, threat models, test tenants, analysts and change windows, while source owners resolve access and field-definition questions within forty-eight hours. The consultant cannot perform offensive testing outside approved cases, accept risk or direct live incident response; bank engineers execute production changes and retain accountability for collection continuity.
Why this is external work
The incumbent SOC is measured by alert handling and cannot independently judge its own visibility. Platform teams lack a shared testing method. External direction establishes outcome-based coverage without preserving inherited content.
What you will own
- Prioritise attack paths by reachable privilege, transaction impact, observed exposure and adversary feasibility across customer and administrative surfaces.
- Grade identity, cloud, endpoint, network and application telemetry for detection fitness, field stability and outage visibility.
- Engineer detections with versioned logic, tests, ownership and retirement criteria.
- Build simulations that exercise precursor, execution and follow-on behaviours safely.
- Define analyst evidence needed to escalate, close or classify an observed behaviour.
- Measure detection latency, blind spots, regression, noise, analyst confidence and decision quality separately for each attack path.
- Transfer repositories, harnesses, dashboards and release governance to bank engineers.
Candidate qualifications
- Led detection engineering for a regulated cloud-intensive bank or payment platform with direct operational-risk scrutiny.
- Can evidence attack-path coverage validated through controlled adversary behaviour, telemetry interruption and analyst reperformance.
- Built production detection-as-code with peer review, regression, controlled simulation and telemetry dependency tests.
- Improved analyst decisions without simply suppressing alert volume, documenting escalation consistency and missed-behaviour reduction.
- Integrated identity, cloud, endpoint and transaction context in detections with explicit field-level dependencies.
- Handed an engineering system to internal operators after formal acceptance.
Non-negotiables
- Available across Sydney and Melbourne milestones.
- Independent of incumbent SIEM and managed-SOC suppliers.
- Will contract against validated behaviour and analyst outcomes.
- Has director or principal-level production detection authority.
- 49 words maximum. Which attack path would you test first in a cloud-native digital bank?
- 49 words maximum. Describe a high-volume detection you retired because it added no decision value.
- 49 words maximum. What evidence proves an analyst can reproduce an escalation decision?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.