Senior Google Security Operations (Chronicle) Engineer / SIEM & SOAR
yondu, inc.- Posted 9 hours ago
- Be among the first 10 applicants
Job Description
The role is responsible for the engineering, integration, optimization, and administration of Google Security Operations (Google SecOps / Chronicle) and related Security Operations platforms. The position focuses on building and improving SIEM, SOAR, log management, detection engineering, and security automation capabilities, rather than performing day-to-day SOC analyst activities.
The role will work closely with SOC teams, security engineers, customers, and technical stakeholders to design and implement scalable security monitoring, detection, automation, and response capabilities using Google Security Operations.
DUTIES AND RESPONSIBILITIES1. Google Security Operations / SIEM Engineering- Design, configure, administer, and optimize Google Security Operations (Google SecOps / Chronicle).
- Configure SIEM capabilities including log ingestion, search, analytics, correlation, detection, and monitoring.
- Optimize Google SecOps platform performance, reliability, data quality, and detection capabilities.
- Troubleshoot Google SecOps platform, configuration, integration, and data ingestion issues.
- Implement security monitoring solutions based on customer and operational requirements.
- Onboard and integrate security, infrastructure, cloud, network, endpoint, application, and other technology log sources into Google Security Operations.
- Configure and troubleshoot log collection, ingestion, parsing, normalization, and enrichment.
- Work with Google SecOps data ingestion and normalization capabilities, including UDM-based security data.
- Validate log source connectivity, data quality, event coverage, and field mapping.
- Troubleshoot ingestion and parsing issues and implement corrective actions.
- Develop, configure, test, and fine-tune security detections and monitoring use cases within Google Security Operations.
- Develop and maintain detection rules, correlation logic, and security monitoring content.
- Translate customer security requirements, threat scenarios, and operational requirements into actionable detection use cases.
- Tune detections to improve accuracy, reduce false positives, and increase security visibility.
- Take onboarded log sources through to customer-specific detection and monitoring capabilities.
- Support threat-based detection engineering and continuous improvement of security use cases.
- Configure, develop, and optimize SOAR playbooks, workflows, integrations, and automated response processes.
- Automate security investigation, enrichment, notification, and response activities.
- Integrate Google Security Operations with security tools, third-party platforms, APIs, and external services.
- Develop automation workflows that improve SOC efficiency and reduce manual operational activities.
- Troubleshoot and enhance existing SOAR integrations and playbooks.
- Integrate Google Security Operations with enterprise security and technology platforms.
- Work with APIs, Syslog, agents, collectors, connectors, and other integration mechanisms.
- Support integrations with endpoint, network, identity, cloud, vulnerability management, threat intelligence, and other security technologies.
- Develop or configure technical integrations required for SIEM/SOAR capabilities.
- Troubleshoot integration failures and data flow issues.
- Perform Google SecOps configuration changes, upgrades, maintenance, and platform enhancements.
- Monitor platform health, data ingestion, detection performance, and overall system reliability.
- Support platform lifecycle management, including configuration updates and technical improvements.
- Conduct root-cause analysis for platform and integration issues.
- Implement corrective and preventive actions to improve platform stability and performance.
- Work with customers and SOC teams to understand security monitoring, detection, automation, and response requirements.
- Provide technical guidance on Google SecOps, SIEM, SOAR, log onboarding, detection engineering, and integrations.
- Support technical workshops, requirements gathering, solution design, and implementation activities.
- Maintain technical documentation, architecture documentation, configuration records, and knowledge articles.
- Provide knowledge transfer and technical guidance to SOC analysts and security engineering teams.
N/A
FUNCTIONAL / TECHNICAL COMPETENCIES- Google Security Operations (Google SecOps / Chronicle)
- SIEM Engineering and Administration
- SOAR Engineering and Automation
- Detection Engineering
- Log Management and Security Data Engineering
- Security Monitoring and Correlation
- Security Platform Integration
- API and Data Integration
- Incident Management
- Configuration Management
- Release and Deployment
- Systems Installation and Maintenance
- Security Operations Methods and Tools
Teamwork & Collaboration, Accountability, Customer Focus, Communication, Innovation, Quality, Problem Solving, Technical Ownership
JOB SPECIFICATIONSEducation- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Security, Engineering, or a related discipline.
- Relevant cybersecurity, Google Cloud, or security vendor certifications are an advantage.
- Minimum 5 years of relevant experience in Security Operations, SIEM/SOAR engineering, security platform engineering, or cybersecurity engineering.
- Strong hands-on experience with Google Security Operations (Google SecOps / Chronicle) is required.
- Hands-on experience administering, configuring, integrating, and optimizing SIEM platforms.
- Hands-on experience with SOAR platforms, playbooks, workflows, and security automation.
- Experience onboarding and integrating multiple security and technology log sources into a SIEM platform.
- Experience with Google SecOps data ingestion, normalization, UDM, and security event data.
- Experience developing, tuning, and maintaining security detection rules and monitoring use cases.
- Experience with security automation, orchestration, and response workflows.
- Experience integrating SIEM/SOAR platforms with security tools, APIs, Syslog, cloud services, and enterprise technologies.
- Experience troubleshooting platform, ingestion, integration, and detection issues.
- Experience in an enterprise SOC, MSSP, managed security services, cybersecurity operations, or security engineering environment.
- Google Security Operations (Google SecOps / Chronicle)
- SIEM architecture, administration, and engineering
- SOAR architecture, automation, and orchestration
- Security event collection and log ingestion
- Google SecOps UDM and security data normalization
- Log parsing, normalization, enrichment, and data quality
- Detection engineering and security analytics
- Correlation rules and security monitoring use cases
- Threat detection and security use-case development
- Security automation and SOAR playbook development
- APIs, Syslog, connectors, collectors, and security integrations
- Cloud and enterprise security technologies
- SOC platform administration, configuration, monitoring, and troubleshooting
- Platform lifecycle management, upgrades, maintenance, and configuration changes
- Strong hands-on Google Security Operations / Chronicle engineering skills
- Strong SIEM engineering, configuration, integration, and troubleshooting skills
- Strong SOAR automation and playbook development skills
- Ability to onboard, normalize, validate, and troubleshoot diverse log sources
- Ability to develop, tune, and optimize security detections and correlation use cases
- Ability to design and implement security automation workflows
- Strong analytical, problem-solving, and technical troubleshooting skills
- Ability to translate customer security requirements into practical technical solutions
- Ability to work with APIs, integrations, data pipelines, and security technologies
- Strong technical documentation and communication skills
- Ability to collaborate effectively with SOC analysts, security engineers, technical teams, and customers
- Strong technical ownership, accountability, and attention to quality
- Continuous improvement mindset with the ability to identify and implement security platform enhancements
- Strong customer orientation and stakeholder management skills
- Ability to provide technical guidance, mentoring, and knowledge transfer
More Info
Key Skills
SIEM Engineering
SOAR Engineering
Google SecOps Chronicle
Detection Engineering
Google Security Operations
