Posted on: 07/07/2026
Job Description:
Role & Responsibilities:
- 5-8 years of experience in cybersecurity with strong focus on Google SecOps SIEM engineering.
- Hands-on expertise with at least one major SIEM platform.
- Strong understanding of: log management and event correlation, network security (Firewalls, IDS/IPS, VPNs), operating systems (Linux, Windows), and cloud platforms (AWS, Azure, GCP).
- Experience with regex, log parsing, and data normalization.
- Knowledge of threat intelligence and attack techniques (MITRE ATT&CK).
- Scripting experience (Python, PowerShell, Shell).
- Familiarity with SOC operations and incident response workflows.
- SIEM certifications (Google SecOps, Splunk Certified Architect, QRadar Admin, Azure Sentinel, etc.).
- Security certifications (CEH, GCED, GCIH, CISSP).
- Experience with SOAR platforms and automation.
- Exposure to DevSecOps and CI/CD security integrations.
- Education: Bachelors/Masters degree, BCA or relevant qualification.
Preferred Candidate Profile:
- Design, deploy, configure, and maintain SIEM solutions - Google SecOps.
- Onboard and normalize log sources from servers, network devices, cloud platforms, applications, and security tools.
- Develop and fine-tune correlation rules, alerts, dashboards, and reports.
- Perform SIEM performance tuning and optimization to reduce false positives.
- Support SOC teams in incident detection, analysis, and response.
- Integrate SIEM with SOAR, EDR, IAM, cloud security, and threat intelligence feeds.
- Conduct use-case development aligned with MITRE ATT&CK framework.
- Ensure compliance with security standards and regulations (ISO 27001, SOC 2, PCI-DSS, HIPAA, etc.).
- Troubleshoot SIEM ingestion, parsing, and data quality issues.
- Automate repetitive tasks using scripting (Python, PowerShell, Bash).
- Participate in security audits, threat hunting, and continuous improvement initiatives.
- Document SIEM architecture, procedures, and operational runbooks.
Did you find something suspicious?