New York - Hybrid•United States - Remote
Hybrid
Mid Level
Full Time
about 2 months ago
security engineerSIEMGoogle SecOpscybersecurityincident responsesecurity operationsremotehybrid
Requirements
- •2-3 years experience in cybersecurity, ideally in security operations or SOC
- •Expertise in incident management, SIEM, DLP, threat intelligence, VPN, and email security
- •At least 1 year experience with Google SecOps SIEM
- •Experience building detection content including rule logic and correlation; YARA-L preferred
- •Experience integrating security tools via APIs and automation (EDR, NDR, ticketing)
- •Scripting skills in Python or Bash for automation and troubleshooting
- •Strong understanding of cybersecurity principles and best practices
- •Strong knowledge of network, endpoint, identity, and cloud security fundamentals
- •Excellent analytical and problem-solving skills
- •Ability to work effectively under pressure and handle multiple incidents simultaneously
- •Strong communication and interpersonal skills
What You'll Do
- •Design and implement Google SecOps SIEM platform integration and improvements
- •Write custom actions, scripts, and integrations to extend SIEM functionality
- •Create SIEM assets such as detection rules, dashboards, and parsers
- •Test and deploy SIEM assets including rules, playbooks, alerts, and dashboards
- •Monitor and scale SIEM deployment performance
- •Develop SOAR playbooks for case handling and incident response
- •Design solutions to handle alert fatigue in SIEM correlation
- •Act as L2 Incident Responder participating in all incident stages
- •Lead incident investigations and response
- •Serve as primary SOC contact for SIEM investigations and troubleshooting
- •Translate incident learnings into improved detections and playbooks
Nice to Have
- •Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience)
- •Experience with security frameworks such as ISO 27001, SOC 2, and PCI-DSS
- •Practical incident response experience including triage, investigation, containment, and communications
- •Experience in vulnerability management including prioritization and automation of remediation
- •Certifications such as CISSP, CISM, or equivalent
- •Google Cloud Certified Professional Security Operations Engineer
- •Experience with Google Cloud Platform, Okta, Crowdstrike, Cloudflare Zero Trust, Tenable Nessus, ZeroFox, Code42
Benefits
- •Competitive salary package
- •Equity package with employee ownership
- •Pay for performance equity bonus
- •Moonshot award with $250,000 equity grant twice a year
- •Unlimited holidays
- •Hybrid working schedule with remote or office options
- •Private healthcare benefits
- •Enhanced parental leave
- •Annual training budget
- •Home office setup allowance
- •Remote working allowance
- •Monthly budget for company products and zero fee crypto transactions
- •Employee referral program with $10K USDC reward
- •Regular remote company offsites
- •Working in a disruptive and fast-growing company where excellence is rewarded
