Search by job, company or skills

Senior Google Security Operations (Chronicle) Engineer / SIEM & SOAR

Senior Google Security Operations (Chronicle) Engineer / SIEM & SOAR

yondu, inc.
5-7 Years
Not Disclosed
  • Posted 9 hours ago
  • Be among the first 10 applicants

Job Description

SENIOR GOOGLE SECURITY GENERAL RESPONSIBILITIES

The role is responsible for the engineering, integration, optimization, and administration of Google Security Operations (Google SecOps / Chronicle) and related Security Operations platforms. The position focuses on building and improving SIEM, SOAR, log management, detection engineering, and security automation capabilities, rather than performing day-to-day SOC analyst activities.

The role will work closely with SOC teams, security engineers, customers, and technical stakeholders to design and implement scalable security monitoring, detection, automation, and response capabilities using Google Security Operations.

DUTIES AND RESPONSIBILITIES1. Google Security Operations / SIEM Engineering
  • Design, configure, administer, and optimize Google Security Operations (Google SecOps / Chronicle).
  • Configure SIEM capabilities including log ingestion, search, analytics, correlation, detection, and monitoring.
  • Optimize Google SecOps platform performance, reliability, data quality, and detection capabilities.
  • Troubleshoot Google SecOps platform, configuration, integration, and data ingestion issues.
  • Implement security monitoring solutions based on customer and operational requirements.
2. Log Source Integration and Data Onboarding
  • Onboard and integrate security, infrastructure, cloud, network, endpoint, application, and other technology log sources into Google Security Operations.
  • Configure and troubleshoot log collection, ingestion, parsing, normalization, and enrichment.
  • Work with Google SecOps data ingestion and normalization capabilities, including UDM-based security data.
  • Validate log source connectivity, data quality, event coverage, and field mapping.
  • Troubleshoot ingestion and parsing issues and implement corrective actions.
3. Detection Engineering
  • Develop, configure, test, and fine-tune security detections and monitoring use cases within Google Security Operations.
  • Develop and maintain detection rules, correlation logic, and security monitoring content.
  • Translate customer security requirements, threat scenarios, and operational requirements into actionable detection use cases.
  • Tune detections to improve accuracy, reduce false positives, and increase security visibility.
  • Take onboarded log sources through to customer-specific detection and monitoring capabilities.
  • Support threat-based detection engineering and continuous improvement of security use cases.
4. SOAR and Security Automation
  • Configure, develop, and optimize SOAR playbooks, workflows, integrations, and automated response processes.
  • Automate security investigation, enrichment, notification, and response activities.
  • Integrate Google Security Operations with security tools, third-party platforms, APIs, and external services.
  • Develop automation workflows that improve SOC efficiency and reduce manual operational activities.
  • Troubleshoot and enhance existing SOAR integrations and playbooks.
5. Platform Integration and API Engineering
  • Integrate Google Security Operations with enterprise security and technology platforms.
  • Work with APIs, Syslog, agents, collectors, connectors, and other integration mechanisms.
  • Support integrations with endpoint, network, identity, cloud, vulnerability management, threat intelligence, and other security technologies.
  • Develop or configure technical integrations required for SIEM/SOAR capabilities.
  • Troubleshoot integration failures and data flow issues.
6. Platform Administration and Maintenance
  • Perform Google SecOps configuration changes, upgrades, maintenance, and platform enhancements.
  • Monitor platform health, data ingestion, detection performance, and overall system reliability.
  • Support platform lifecycle management, including configuration updates and technical improvements.
  • Conduct root-cause analysis for platform and integration issues.
  • Implement corrective and preventive actions to improve platform stability and performance.
7. Customer and SOC Technical Support
  • Work with customers and SOC teams to understand security monitoring, detection, automation, and response requirements.
  • Provide technical guidance on Google SecOps, SIEM, SOAR, log onboarding, detection engineering, and integrations.
  • Support technical workshops, requirements gathering, solution design, and implementation activities.
  • Maintain technical documentation, architecture documentation, configuration records, and knowledge articles.
  • Provide knowledge transfer and technical guidance to SOC analysts and security engineering teams.
LEADERSHIP COMPETENCIES

N/A

FUNCTIONAL / TECHNICAL COMPETENCIES
  • Google Security Operations (Google SecOps / Chronicle)
  • SIEM Engineering and Administration
  • SOAR Engineering and Automation
  • Detection Engineering
  • Log Management and Security Data Engineering
  • Security Monitoring and Correlation
  • Security Platform Integration
  • API and Data Integration
  • Incident Management
  • Configuration Management
  • Release and Deployment
  • Systems Installation and Maintenance
  • Security Operations Methods and Tools
CORE COMPETENCIES

Teamwork & Collaboration, Accountability, Customer Focus, Communication, Innovation, Quality, Problem Solving, Technical Ownership

JOB SPECIFICATIONSEducation
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Security, Engineering, or a related discipline.
  • Relevant cybersecurity, Google Cloud, or security vendor certifications are an advantage.
Related Work Experience
  • Minimum 5 years of relevant experience in Security Operations, SIEM/SOAR engineering, security platform engineering, or cybersecurity engineering.
  • Strong hands-on experience with Google Security Operations (Google SecOps / Chronicle) is required.
  • Hands-on experience administering, configuring, integrating, and optimizing SIEM platforms.
  • Hands-on experience with SOAR platforms, playbooks, workflows, and security automation.
  • Experience onboarding and integrating multiple security and technology log sources into a SIEM platform.
  • Experience with Google SecOps data ingestion, normalization, UDM, and security event data.
  • Experience developing, tuning, and maintaining security detection rules and monitoring use cases.
  • Experience with security automation, orchestration, and response workflows.
  • Experience integrating SIEM/SOAR platforms with security tools, APIs, Syslog, cloud services, and enterprise technologies.
  • Experience troubleshooting platform, ingestion, integration, and detection issues.
  • Experience in an enterprise SOC, MSSP, managed security services, cybersecurity operations, or security engineering environment.
Knowledge
  • Google Security Operations (Google SecOps / Chronicle)
  • SIEM architecture, administration, and engineering
  • SOAR architecture, automation, and orchestration
  • Security event collection and log ingestion
  • Google SecOps UDM and security data normalization
  • Log parsing, normalization, enrichment, and data quality
  • Detection engineering and security analytics
  • Correlation rules and security monitoring use cases
  • Threat detection and security use-case development
  • Security automation and SOAR playbook development
  • APIs, Syslog, connectors, collectors, and security integrations
  • Cloud and enterprise security technologies
  • SOC platform administration, configuration, monitoring, and troubleshooting
  • Platform lifecycle management, upgrades, maintenance, and configuration changes
Skills
  • Strong hands-on Google Security Operations / Chronicle engineering skills
  • Strong SIEM engineering, configuration, integration, and troubleshooting skills
  • Strong SOAR automation and playbook development skills
  • Ability to onboard, normalize, validate, and troubleshoot diverse log sources
  • Ability to develop, tune, and optimize security detections and correlation use cases
  • Ability to design and implement security automation workflows
  • Strong analytical, problem-solving, and technical troubleshooting skills
  • Ability to translate customer security requirements into practical technical solutions
  • Ability to work with APIs, integrations, data pipelines, and security technologies
  • Strong technical documentation and communication skills
  • Ability to collaborate effectively with SOC analysts, security engineers, technical teams, and customers
  • Strong technical ownership, accountability, and attention to quality
  • Continuous improvement mindset with the ability to identify and implement security platform enhancements
  • Strong customer orientation and stakeholder management skills
  • Ability to provide technical guidance, mentoring, and knowledge transfer

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

SIEM Engineering

SOAR Engineering

Google SecOps Chronicle

Detection Engineering

Google Security Operations

About Company