Cyber - Google SecOps - Manager
Indexed description
Recruiting for this role ends on 12/31/2026.
Work you'll do
As a Google SecOps Manager on the Cyber Defense & Resilience team, you will be responsible for:
- Leading the design and implementation of secure, scalable Google SecOps architectures, including SIEM and SOAR capabilities aligned to client security requirements and regulatory obligations such as General Data Protection Regulation (GDPR) and Payment Card Industry Data Security Standard (PCI DSS)
- Leading end-to-end deployment of log ingestion pipelines using data fabric technologies and integrations such as Bindplane, Cloud Feeds, and application programming interfaces (APIs)
- Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious behavior across enterprise environments
- Translating SOC processes into SOAR automation playbooks to reduce alert fatigue and scale alert triage and response
- Developing and managing integrations across third-party platforms, security tools, and Google SecOps to support automated data ingestion, alert enrichment, response actions, and case management workflows
- Leading and mentoring junior team members in SOC engineering, including SIEM, SOAR, and process development
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to mentor and provide clear guidance to others
Qualifications
Required:
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or another technical field, or equivalent work experience
- 9+ years of experience in security operations, threat detection engineering, or enterprise information technology security
- Experience with Google Cloud SecOps tool stack and architecture, including Google Chronicle SIEM, Google SecOps SOAR, Google Siemplify SOAR, threat detection engineering, and security operations center workflows
- Experience with Python scripting and GoStash or Logstash for automation, integration development, log normalization, and parsing, as well as with extract, transform, load (ETL) pipelines and technologies such as Cribl, Bindplane, NXLog, Kafka, Cloud Feeds, and APIs
- Experience with MITRE ATT&CK, the Cyber Kill Chain, VirusTotal, Mandiant, Google Threat Intelligence, Splunk, Cortex XSOAR, and AI agentic frameworks, including Model Context Protocol (MCP) or Agent Development Kit (ADK), for workflow development or integration across security information and event management (SIEM), security orchestration, automation, and response (SOAR), Google Threat Intelligence (GTI), or attack surface management (ASM)
- Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
- Certifications such as Google Cloud Professional Cloud Architect, Google Cloud Professional Security Engineer, or Certified Cloud Security Professional (CCSP)
- Experience monitoring cybersecurity threats, vulnerabilities, or compliance trends to support security operations or security engineering activities
- Experience facilitating scope or build requirement discussions with internal or external stakeholders
- Experience with threat hunting or cyber threat intelligence fundamentals
- Experience with data fabric technologies such as Bindplane or Cribl
- Experience with infrastructure and networking concepts such as internet protocol (IP) networking, virtual private networks (VPNs), domain name system (DNS), load balancing, firewall technologies, or cloud environments such as Amazon Web Services (AWS) or Microsoft Azure
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search