01Responsibilities
Conduct tabletop exercises/purple-team validations to assess coverage and playbook efficacy; drive measurable improvements in MTTD/MTTR. Support sensitive data exposure assessments and CI/CD pipeline guardrails where relevant to SecOps telemetry and response. Educational qualifications Bachelors degree in Computer Science / Cyber Security / IT or related field Relevant certifications (preferred): Google Professional Cloud Security Engineer; Google Security Operations/Chronicle training Work experience 5-7 years of experience in: Incident Response / SOC / Threat Hunting / SIEM Engineering / Cloud Architecture Experience in global client engagements (US/UK/Europe) preferred. Mandatory technical & functional skills Strong understanding of: Enterprise security architecture and its alignment to business and IT strategies. Incident Response lifecycle and SOC workflows MITRE ATT&CK mapping for detections, hunts, and reporting. Hands-on experience in: SIEM tools (Google SecOps) EDR tools (Microsoft Defender, SentinelOne, CrowdStrike - exposure) Knowledge of: SIEM Engineering/YARA-L concepts, SOC/SOAR SCC concepts and integration patterns into SecOps workflows. Strong: Analytical and problem-solving skills Technical report writing and documentation skills Communication and stakeholder engagement skills Preferred technical & functional skills Exposure to: Threat intelligence integration/enrichment (STIX/TAXII, MISP, VirusTotal, commercial feeds) and IOC lifecycle management. EDR/identity/network telemetry Cloud Security Controls Familiarity with: Content-as-code, CI/CD for detections/parsers/playbooks; API-driven configuration management. Experience in: Threat hunting and hypothesis-driven analysis using Chronicle UDM Search and entity pivots. Experience Level Senior Level .