About the Role
In this role, you will leverage your detection engineering and security operations expertise to build and maintain the log collection, alerting, and automation backbone of our security monitoring program. You will own the onboarding of log sources across cloud and endpoint platforms into Google SecOps, manage and tune alerts within our SIEM/SOAR, and develop the integrations and internal tooling that keep the security team efficient.
Direct reporting line: Lead Security Engineer
Responsibilities:
- Configure and collect logs from cloud and endpoint sources, including Azure AD, endpoint devices via Microsoft Defender for Endpoint, Google Command Center, and on-premise devices, into Google SecOps.
- Manage, triage, and tune alerts generated by the SIEM/SOAR platform (Google SecOps) using the collected log sources.
- Build and maintain integrations between Google SecOps and other cloud platforms, security tools, and internal systems (e.g., via APIs, feeds, or connectors).
- Write scripts and internal tools to automate log ingestion, alert enrichment, and other repetitive tasks for the security team.
- Continuously monitor security logs and events across integrated sources to detect and prevent threats.
- Document log source configurations, integration architecture, and alert-handling runbooks.
- Collaborate with SOC, IT, and infrastructure teams to ensure log coverage, integration reliability, and alert quality.
Qualifications:
- 3+ years of experience in security operations, detection engineering, or a related security role.
- Hands-on experience with Google SecOps (Chronicle) or equivalent SIEM/SOAR platforms.
- Experience configuring log collection from Azure AD, Microsoft Defender for Endpoint, and/or Google Command Center (Security Command Center).
- Familiar with GCP (must-have requirement).
- Proficiency in scripting (e.g., Python, PowerShell, or similar) for automation and tool development.
- Strong understanding of network security concepts, operating systems, cloud security, and log/event data.
- Experience building API-based integrations between security and cloud/enterprise systems.
- Excellent written and verbal communication skills, with the ability to explain complex technical concepts to both technical and non-technical audiences.
- Experience working within a collaborative team environment.
- Preferred Certifications: GCIH, GCDA, Google Cloud certifications, or equivalent.
Our benefit:
- Competitive compensation including a 13th-month wage and up to 3 months of performance-based bonus.
- Macbook and essential equipment are provided.
- BE Corp budget (vary from your level) is allocated for using services such as transportation, food, and passenger car bookings in Be application.
- The social insurance contribution amount will vary based on the individual's level.
- Annual health checks and premium medical healthcare (PTI) after probation.
- 15 days of annual leave is applied for the entire staff.
- Company trips, team-building activities, and happy hour events are organized on a quarterly or annual basis.