HireFT
Browse JobsHow it worksPricingAboutSuccess Stories
    Back to jobs
    GO

    Google

    Technology

    Detection and SOAR Engineer, Mandiant Consulting, Google Cloud

    Canberra, AustraliaOn-SiteFull-time3+ yrs experiencePosted 1w ago
    All Google jobs

    Job description

    info_outline
    XGoogle will be prioritizing applicants who have a current right to work in Australia, and do not require Google’s sponsorship for a visa.

    At Google, we have a vision of empowerment and equitable opportunity for all Aboriginal and Torres Strait Islander peoples and commit to building reconciliation through Google’s technology, platforms and people and we welcome Indigenous applicants. Please see our Reconciliation Action Plan for more information.

    Note: By applying to this position you will have an opportunity to share your preferred working location from the following:
    In-office locations: Canberra ACT, Australia; Melbourne VIC, Australia; Sydney NSW, Australia.
    Remote location(s): Australia.

    Minimum qualifications:

    • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, a related technical field, or equivalent practical experience.
    • 3 years of experience in detection engineering, SOAR automation, or a related role.
    • 3 years of experience working with SOC/CSIRT or other incident response related teams.
    • Experience with detection tuning and creation leveraging various security tools (e.g., SIEM, EDR, or NDR tools).
    • Experience with scripting Security Information and Event Management (SIEM) solutions (e.g., writing queries, searches, alerts, dashboards) in Python or Powershell.

    Preferred qualifications:

    • Certifications in one or more of the following: CompTIA Security+, CompTIA Network+; CISCO (CCNA); ISC2 (CISSP); SANS (GSEC, GCIH, GCED, GCFA, GCIA, GNFA, GPEN).
    • Experience with SOAR and its dependencies, managing and maintaining SOAR platforms, as well as integrating APIs into automation playbooks.
    • Experience with content engineering inside SIEM platforms (e.g., rule creation, advanced correlation searching, etc.).
    • Experience with SPL, KQL, YARA-L or similar SIEM query languages, with an understanding of SIEM log flow, aggregation, and forwarding.
    • Understanding of logging for common platforms and devices, including Linux and network equipment.

    About the job

    In this role, you will collaborate with multiple cross-functional teams like Mandiant Architects, Mandiant Analysts, Client Information Technology (IT) resources, and other business resource owners. You will be responsible for enabling the technology and tools required to effectively accomplish daily tasks within a Cyber Defense Center (CDC). This includes maintaining operational readiness of the client Security Information and Event Management (SIEM) and Security Orchestration, Automation and Response (SOAR) platform, creating detection content and automations to support the daily tasks within the CDC. In addition, you may be responsible for setting appropriate configurations of the SIEM and SOAR or related response technologies required for a client's SOC to maintain effective incident detection and response capabilities.

    Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.

    Responsibilities

    • Identify challenges in customer Cyber Defense Centers (CDC) and formulate strategies for improvement, plan implementation of improvements, and execute/oversee plans to completion.
    • Advise on technologies relied upon by the client CDC, Computer Security Incident Response Team (CSIRT), and SOC.
    • Create and modify SIEM use cases written in both technology specific query language and Sigma open signature format. Create and modify SOAR playbooks written in Python.
    • Engage and collaborate with client stakeholders and other groups within customer environment to drive resolution for security issues.
    • Provide expertise for SIEM, SOAR and other SOC technologies that assist in incident response, and provide surge support for analyst T1-3 capabilities when required.

    Job details are sourced from the employer's original posting.

    Open job posting
    GO

    About the company

    Google

    Google is a multinational technology company focusing on search, artificial intelligence, cloud computing, and online advertising. It develops and provides a wide range of internet-related services and products.

    View all Google jobsabout.google
    Industry
    Technology
    Founded
    1998
    Open roles
    2893

    Interested in this role?

    Apply with HireFT

    Free to start — no card required.

    Your fit

    How well do you match?

    Sign in to see how your résumé lines up with this role.