π Google SecOps Engineer | Cybersecurity Hiring in Bangalore
π Job Description
We are hiring an experienced Google SecOps Engineer for a cybersecurity opportunity in Bangalore. The role requires 7+ years of overall experience, including a mandatory 3–4 years of hands-on experience working with Google SecOps.
The ideal candidate should have strong expertise in Chronicle SIEM and SOAR, YARA-L rule development, Unified Data Model (UDM), log ingestion, parser development, threat detection, threat hunting, security investigations, incident response automation, API integrations, and Google Threat Intelligence.
π Key Responsibilities
- Manage and optimize security monitoring capabilities using Google SecOps
- Work extensively with Google Chronicle SIEM and SOAR capabilities
- Develop, test, tune, and maintain YARA-L detection rules
- Work with Unified Data Model (UDM) for security event normalization and analysis
- Configure and manage security log ingestion from multiple enterprise data sources
- Develop and troubleshoot parsers for effective security telemetry ingestion
- Perform proactive threat detection and threat hunting across security datasets
- Investigate security alerts, suspicious activities, and potential security incidents
- Develop automated incident response workflows and SOAR playbooks
- Integrate security platforms and external systems using APIs
- Leverage Google Threat Intelligence to improve threat detection and investigation capabilities
- Continuously tune detection logic to improve accuracy and reduce false positives
π Eligibility Criteria
- 7+ years of overall professional experience
- 3–4 years of hands-on Google SecOps experience is mandatory
- Strong practical experience with Chronicle SIEM and SOAR
- Hands-on knowledge of YARA-L rule development and detection engineering
- Strong understanding of Google SecOps Unified Data Model (UDM)
- Experience with security log ingestion and parser development
- Hands-on exposure to threat detection, threat hunting, and security investigations
- Experience developing incident response automation and SOAR playbooks
- Knowledge of API-based security integrations
- Familiarity with Google Threat Intelligence
- Google Cloud Professional Security Engineer certification is preferred
⭐ Key Skills
- Google SecOps
- Chronicle SIEM & SOAR
- YARA-L Rule Development
- Unified Data Model (UDM)
- Log Ingestion
- Parser Development
- Threat Detection
- Threat Hunting
- Incident Response Automation
- SOAR Playbooks
- Security Monitoring & Investigations
- API Integrations
- Google Threat Intelligence
π° Benefits
- Opportunity to work extensively with the Google SecOps security ecosystem
- Hands-on exposure to enterprise-scale SIEM, SOAR, and security automation
- Opportunity to build advanced threat detection and hunting capabilities
- Work on security engineering, incident response automation, and threat intelligence use cases
- Career growth opportunities in cybersecurity engineering, detection engineering, and security operations
⭐ Why Consider This Opportunity?
- Work on advanced Google SecOps, Chronicle SIEM, and SOAR technologies
- Build and optimize enterprise-scale security detection capabilities
- Gain deeper expertise in YARA-L, UDM, threat hunting, and detection engineering
- Develop automated security response workflows and SOAR playbooks
- Strengthen your career in cloud security, SecOps engineering, and cybersecurity automation
π§ Core Skills Required
- Google SecOps: Strong hands-on expertise with the Google SecOps ecosystem, including Chronicle SIEM and SOAR capabilities.
- YARA-L Development: Ability to develop, test, tune, and maintain detection rules for identifying suspicious security events and threats.
- Unified Data Model: Strong understanding of UDM concepts for normalized security telemetry, querying, and detection engineering.
- Log Ingestion & Parsers: Experience onboarding security data sources, managing log ingestion, and developing or troubleshooting parsers.
- Threat Detection & Hunting: Ability to proactively identify suspicious patterns, investigate threats, and develop effective detection use cases.
- SOAR & Automation: Experience designing automated incident response workflows and security orchestration playbooks.
- Security Investigations: Strong capability to investigate alerts, correlate security events, analyze incidents, and support response activities.
- API Integration: Ability to integrate security platforms, data sources, and external tools using APIs.
- Threat Intelligence: Ability to leverage threat intelligence for detection enhancement, investigation, and proactive security monitoring.
π€ How to Prepare for the Interview
- Prepare detailed examples of your hands-on experience with Google SecOps and Chronicle SIEM/SOAR.
- Revise YARA-L rule syntax, rule development, tuning, false-positive reduction, and practical detection use cases.
- Understand UDM normalization, event mapping, querying, and how security telemetry is structured within Google SecOps.
- Be ready to explain how you onboard new log sources and troubleshoot ingestion or parser-related issues.
- Prepare practical examples of threat hunting and security investigations you have performed.
- Review incident response automation concepts and prepare examples of SOAR playbooks you have designed or maintained.
- Be ready to discuss API integrations between SIEM/SOAR platforms and other security tools.
- Prepare examples demonstrating how threat intelligence can improve detection rules, investigations, and security monitoring.
- Expect scenario-based questions involving suspicious events, detection gaps, false positives, compromised accounts, and incident response workflows.
π© How to Apply
Interested candidates with 7+ years of overall experience and the mandatory 3–4 years of hands-on Google SecOps experience can apply through the application form below. Candidates should clearly highlight their Chronicle SIEM/SOAR, YARA-L, UDM, log ingestion, parser development, threat hunting, and security automation experience in their resume.