Sr. SOC Engineer
Core
Own and operate Google SecOps platform end-to-end, architecting log ingestion, threat detection rules, AI-powered triage automation, and leading investigative response to high-severity incidents.
Role type
Senior hands-on SOC Engineer (Detection & Response)
Builds
Google SecOps platform, threat detection rules, automation workflows, incident response playbooks
Domain
Cybersecurity, Cloud Security Operations, Mobile Security
Required skills
SIEM engineering, threat detection rule authoring, log analysis, incident investigation, Python/Go/Bash scripting, API integration, CNAPP integration, MITRE ATT&CK operationalization, SOC automation, KPI definition
Preferred skills
Google Chronicle/SecOps experience, AI/ML alert triage, regulated environment compliance (FedRAMP/DoD), mobile threat detection, threat modeling, security research
Technologies
Google SecOps, Splunk, ELK, Chronicle, Sentinel, Sumo Logic, Python, Go, Bash, Zapier, Make, Jira, Kubernetes
Responsibilities
Architect log ingestion and detection rules; design AI-powered triage and response automation; lead high-severity incident investigations; build SOC automation scripts; define and report on SOC KPIs; serve as incident commander for critical events; generate compliance documentation
Seniority
Senior, hands-on IC