Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will design and tune threat detections, lead high-severity incident investigations, and build automation for detection, triage, and response. You will maintain SIEM and data-pipeline health, improve security tooling and playbooks, use AI coding tools responsibly, and mentor less experienced engineers.
Requirements
- 5+ years of security operations, detection engineering, or incident response experience
- Advanced knowledge of detection and response security principles, tools, and practices
- Python or SOAR scripting and automation skills
- Experience with REST APIs
- Experience with SIEM platforms and security data pipelines
- Experience with Google SecOps
- Experience with EDR, identity, email-security, and network-security tooling
- Ability to write technical specifications and assess project risks and trade-offs
Responsibilities
- Design, build, and tune detections in Google Security Operations
- Lead high-severity incident response from triage through remediation
- Build and maintain Tines security automation workflows
- Improve SIEM and security data-pipeline health, log coverage, parsing, and alert quality
- Partner with IT and engineering to drive security-tooling adoption
- Translate threat-landscape changes into detection and response-playbook improvements
- Use and verify AI coding tools for detection engineering and automation
- Mentor less experienced engineers
Benefits
- Professional development budget
- Flexible in-office attendance determined by managers and teams
- Team offsites, bonding activities, and happy hours
- Bonuses and equity
- Healthcare, retirement, family-forming, and family-support benefits
- Employee giving match
- Mobile phone stipend
- R&R days
- Wellness reimbursement and onsite or virtual programming
- Generous vacation policy
- Parental leave and family-planning benefits
- Catered lunches and stocked kitchens