Job Title: Google Chronicle SIEM Engineer
Experience: 8 – 10 Years
Location: Hyderabad or Mumbai
Job Type: Full-Time
Position Overview:
We are seeking a Google Chronicle SIEM Engineer to lead and enhance our Security Operations Center (SOC) capabilities. This hands-on role involves:
- SIEM administration
- Security alert monitoring
- Threat intelligence integration
- Automation development
...to strengthen our cybersecurity posture.
Key Responsibilities:
SIEM Administration:
- Deploy, configure, and manage Google Chronicle SIEM.
- Manage user access, upgrades, log sources, and report generation.
- Troubleshoot and resolve SIEM-related issues to maintain optimal performance.
Security Alert Monitoring & Incident Response:
- Continuously monitor security alerts generated by Google Chronicle SIEM.
- Perform log analysis, correlation, and investigation of security events.
- Prioritize, escalate, and respond to security incidents as per incident response playbooks.
- Collaborate with SOC analysts and security teams to mitigate threats effectively.
Security Use Case Development:
- Develop and optimize detection rules, correlation queries, and dashboards to enhance threat visibility.
- Create custom parsers, playbooks, and automation workflows to improve SOC efficiency.
- Align security alerts and detection mechanisms with the MITRE ATT&CK framework.
Threat Intelligence & Forensics:
- Integrate threat intelligence feeds with Google Chronicle SIEM to detect emerging threats.
- Conduct forensic analysis on compromised systems and investigate Indicators of Compromise (IoCs).
- Collaborate with red team/blue team exercises to enhance security defenses.
SOAR Platform Administration:
- Develop automated security workflows and playbooks to accelerate threat response.
- Integrate Google Chronicle SIEM with SOAR tools for enhanced incident automation.
Technical Troubleshooting & Vendor Coordination:
- Collaborate with Google Chronicle support and other third-party vendors for issue resolution.
- Continuously improve SIEM performance, scalability, and security operations workflows.
Qualifications:
Education & Experience:
- Bachelor's degree in Computer Science, Information Security, or a related field.
- Minimum of 1 year of experience in SIEM administration, security monitoring, and incident response.
Technical Skills:
- Strong knowledge of network protocols, security architectures, and cloud security principles.
- Proficiency in log analysis, correlation, and threat hunting.
- Experience with programming/scripting languages (Python, PowerShell, or Bash) for automation.
- Familiarity with MITRE ATT&CK, NIST, and SOC best practices.
Certifications (Preferred):
- Google Chronicle SIEM
- Security certifications such as CISSP, CISM, GIAC, CEH, or Security+