4 дня назад
Sr. SOC Engineer (Google SecOps)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Sr. SOC Engineer (Google SecOps/CNAPP): Operating and architecting Google SecOps as the central security operations platform, integrating CNAPP data, detection rules, SOAR workflows, and incident response with an accent on threat detection engineering, automation, and high-severity investigations. Focus on designing log ingestion and correlation, building AI-powered triage and response automation, leading root-cause analysis, and improving SOC metrics and compliance reporting.
Location: Dallas, Texas preferred; hybrid workplace
Company
develops AI-driven mobile security technology that protects mobile applications and devices from phishing, malware, vulnerabilities, and zero-day exploits.
What you will do
- Own and operate Google SecOps as the SOC's central operational platform, including log ingestion, alert routing, case management, SOAR workflows, integrations, and escalation procedures.
- Architect data flows from the CNAPP platform into Google SecOps and other security tools to unify mobile, cloud, and infrastructure security operations.
- Author, tune, and maintain threat detection rules and correlation logic across heterogeneous OS, application, network, DNS, proxy, endpoint, and runtime data.
- Build automation and integrations with Python, Go, or Bash, including enrichment, bulk event analysis, response actions, reporting, APIs, and webhooks.
- Lead investigations of high-severity incidents, including evidence collection, root cause analysis, timeline reconstruction, scope determination, containment, remediation, and post-incident reporting.
- Define SOC KPIs and reporting for detection latency, MTTR, investigation duration, false positives, automation coverage, audits, and continuous improvement.
Requirements
- 8+ years of experience in security operations, threat detection, or incident response, including at least 4 years in SIEM, SOC engineering, or detection engineering.
- Deep hands-on experience with a major SIEM platform and production detection authoring and tuning; Google SecOps or Chronicle experience is especially relevant.
- Strong knowledge of log normalization, MITRE ATT&CK, threat detection, incident investigation, and security tool integrations.
- Ability to build and maintain automation using Python, Go, or Bash and debug APIs, webhooks, and data flows.
- Experience with mobile threat detection, CNAPP, endpoint detection, or cloud and container runtime security.
- Ability to operate independently, make architectural decisions, lead high-priority incidents, and communicate findings to technical and executive audiences.
Nice to have
- Experience with AI/ML-based alert triage, anomaly detection, or automated incident response.
- Experience in regulated environments such as FedRAMP, DoD, PCI-DSS, or HIPAA.
- Mobile application security, Kubernetes runtime security, threat modeling, vulnerability disclosure, or security research experience.
- Relevant GIAC, Google Cloud Security, AWS Security, or other security certifications.
- Prior DevSecOps, security engineering, or cloud security experience.
Culture & Benefits
- Hands-on ownership of SOC architecture, detection strategy, automation, and incident response quality.
- Close collaboration with DevOps, Cloud Security, and Product Security teams.
- On-call participation as an incident commander or key investigator for high-priority events.
- Work in a mobile security environment focused on proactive defense against evolving threats.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
SOC Engineer (Cybersecurity)
Microsoft AI
6 дней назад
Sr. Security Operations Engineer (AI)
119 800 - 234 700$
10 дней назад
Sr. Detection Engineer
130 900 - 169 400$
5 дней назад
Threat Detection Analyst III (Cybersecurity)
145 000 - 170 000$
7 дней назад
Security Operations Engineer (Cybersecurity)
91 200 - 118 600$
5 дней назад
Cyber Threat Hunter
80 000 - 110 000$