Security Consultant, SOAR, Mandiant, Google Cloud

Google LLC
Mountain View, CA, United States
9 days ago
Apply on www.techcareers.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$112,000.0 - $161,000.0
Working hours
Regular working hours
Languages
English

Tech stack

Microsoft Windows Application Programming Interfaces (APIs) Artificial Intelligence Bioinformatics CompTIA Network+ CompTIA Security+ Cyber Security Information Systems Computer Programming Customer Data Management Database Queries Linux
+15 more
Networking Hardware Python (Programming Language) Security Information and Event Management Web Applications Data Processing Scripting Google Cloud Cyber Threat Analysis Pandas Information Technology Restful APIs Cyber Warfare Splunk Cisco Security Orchestration, Automation & Response

Job description

In this role, you will be responsible for enabling the technology and tools required to effectively automate and orchestrate daily tasks within a Cyber Defense Center (CDC). You will collaborate with multiple cross-functional teams like Mandiant Architects, Mandiant Analysts, Client Information Technology (IT) resources, and other business resource owners, to define requirements and deliver recommendations focused on technologies, processes, scripting, and improvements required to support automation tasks within a CDC.

You will work as a member of a highly technical team in a rapidly changing environment, administer a variety of information security technologies, learn new emerging technologies, and be passionate about protecting customer data and corporate assets from the various threats facing multiple industries.

Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant’s cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry’s best security validation ensures that Mandiant knows more about today’s advanced threats than anyone.Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

US: $112000 - $161000 (USD) + 15% bonus target + equity + benefits, * Identify issues in customer Cyber Defense Centers, formulate strategies for improvement, identify candidates for automation, plan implementation of improvements, and execute/oversee plans to completion.

  • Advise on technologies relied upon by the client CDC, CSIRT, and SOC.
  • Provide expertise for SOAR and other SOC technologies that assist in incident response.
  • Create and modify SOAR playbooks written in Python.
  • Engage and collaborate with client stakeholders and other groups within the customer environment to drive resolution for security issues.

Information collected and processed as part of your Google Careers profile, and any job applications you choose to submit is subject to Google’sApplicant and Candidate Privacy Policy (./privacy-policy) .

Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See alsoGoogle’s EEO Policy (https://www.google.com/about/careers/applications/eeo/) ,Know your rights: workplace discrimination is illegal (https://careers.google.com/jobs/dist/legal/EEOC_KnowYourRights_10_20.pdf) ,Belonging at Google (https://about.google/belonging/) , andHow we hire (https://careers.google.com/how-we-hire/) .

If you have a need that requires accommodation, please let us know by completing ourAccommodations for Applicants form (https://goo.gl/forms/aBt6Pu71i1kzpLHe2) .

Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.

To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes.

Equity is granted exclusively and discretionarily by Alphabet Inc. on the basis of an agreement concluded between you and Alphabet Inc. Alphabet Inc. is your sole contractual partner with respect to equity grants. GSU grants are not guaranteed, are discretionary, are subject to approval by the Alphabet Inc. board of directors or its delegate, the terms of the relevant Alphabet Inc. stock plan, and your grant agreement. They have no impact on statutory payments. Current or past grants do not confer an acquired right.

Requirements

Experience driving progress, solving problems, and mentoring more junior team members; deeper expertise and applied knowledge within relevant area., * Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, a related technical field, or equivalent practical experience.

  • 3 years of experience configuring and maintaining Security Orchestration, Automation, and Response (SOAR) Technologies as part of Security Engineering, System Administration, or a similar role.
  • 3 years of experience working with SOC/CSIRT or other incident response related teams.
  • Experience with Security Information and Event Management (SIEM) solutions (e.g., writing queries, searches, alerts, dashboards)., * One or more of the following certifications or similar: CompTIA Security+, CompTIA Network+; CISCO (CCNA); ISC2 (CISSP); SANS (GSEC, GCIH, GCED, GCFA, GCIA, GNFA, GPEN).
  • Experience managing and maintaining SOAR platforms and its dependencies, and working with/integrating APIs into automation playbooks.
  • Experience with commercial SIEM technologies (e.g., Google SecOps, Splunk, Helix, Devo, Sentinel).
  • Working knowledge of scripting languages (e.g., Python).
  • Understanding of security controls for platforms/devices (e.g., Windows, Linux, network equipment), web-based APIs/RESTful programming (e.g., Python libraries), and data manipulation/analysis libraries (e.g., Pandas).
  • Understanding of the incident response, containment, and remediation process.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.techcareers.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:03 min

Accelerating pandas dataframes using cudf module plugins

Ankit Patel Ankit Patel · World Congress 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:45 min

Prototyping deterministic agents with n8n and PyATS

Alfonso Sandoval Rosas Alfonso Sandoval Rosas · Europe 2026 Virtual

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all