Detection and SOAR Engineer, Mandiant Consulting, Google Cloud
Core
Design and maintain detection content and automation playbooks for client Cyber Defense Centers (CDC) to enable effective incident detection and response.
Role type
Senior IC detection and SOAR engineer
Builds
SIEM use cases, SOAR playbooks, and automated response workflows for client security operations
Domain
Cybersecurity, Threat Detection, Incident Response
Required skills
SIEM tuning, SOAR automation, Python scripting, incident response, detection engineering, query language (SPL/KQL/YARA-L), log analysis
Preferred skills
SIEM content engineering, API integration, threat intelligence, surge support for analyst capabilities
Technologies
SIEM, EDR, NDR, Python, Powershell, Sigma, SPL, KQL, YARA-L
Responsibilities
Identify CDC challenges and formulate improvement strategies; Create and modify SIEM use cases and SOAR playbooks; Engage with client stakeholders to drive security issue resolution; Provide expertise for SOC technologies and surge support for analysts