Remote location: Illinois, USA
Minimum qualifications:
- 4 years of experience working in an Engineering, System Administrator, or a related role.
- 4 years of experience configuring and maintaining SIEM technologies.
- 4 years of experience with networking, including TCP/IP protocols and network topology.
- 3 years of experience in server compute, directory and email services.
Preferred qualifications:
- Certification in one or more of the following: CompTIA Security+, CompTIA Network+, CISCO (CCNA), ISC2 (CISSP), SANS (GSEC, GCIH, GCED, GCFA, GCIA, GNFA, GPEN).
- Experience with SPL, KQL, Kusto or similar SIEM query languages, with an understanding of SIEM log flow, aggregation, and forwarding.
- Experience managing and maintaining EDR, NDR, or other incident response technologies.
- Understanding of security controls for common platforms and devices, including Windows, Linux and network equipment.
- Knowledge of scripting languages such as PowerShell and Python.
- Excellent written/verbal and people management skills, with the ability to simplify and communicate complex ideas.
About the job
In this role, you will collaborate with multiple cross-functional teams to define requirements and deliver recommendations focused on technologies required to support the client Cyber Security. You will be responsible for maintaining the operational readiness of client Security Information and Event Management (SIEM), creating detection content, identifying areas for improvement, and setting appropriate configurations of the SIEM or related response technologies required for a client SoC to maintain effective incident detection and response capabilities.
Google Cloud accelerates organizations’ ability to digitally transform their business with the best infrastructure, platform, industry solutions and expertise. We deliver enterprise-grade solutions that leverage Google’s cutting-edge technology – all on the cleanest cloud in the industry. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.
The US base salary range for this full-time position is $128,000-$192,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.
Responsibilities
- Identify issues in customer Cyber Centers and formulate strategies for improvement, plan implementation of improvements, and execute/oversee plans to completion.
- Advise on technologies relied upon by the client Change Data Capture (CDC), Computer Security Incident Response Team (CSIRT), and SoC.
- Provide expertise for SIEM and other SoC technologies that assist in incident response.
- Create and modify SIEM use cases written in technology specific query language and Sigma open signature format.
- Engage and collaborate with client stakeholders and other groups within customer environment to drive resolution for security issues.