19 Sep
|
Tata Consultancy Services
|
Ahmedabad
19 Sep
Tata Consultancy Services
Ahmedabad
GOOGLE SECOPS
Primary Skill
As a Google SecOps SIEM Engineer, you will be responsible for strategic delivery helping our customers securely adopt Google SecOps. You will provide best practices on secure build of Google SecOps platform, foundational cloud implementation for Google SecOps, tackle difficult problems that businesses are facing when building Google SecOps, and more. You will provide prescriptive guidance in ensuring customers receive the best of what Google SecOps can offer and you will ensure that customers have the best experience in migrating, building, modernising, and maintaining Google SecOps.
Additionally, you will work closely with Product Management and Product Engineering to drive excellence of Google SecOps and features.
Lead the design and implementation of Google SecOps data ingestion from diverse sources, various mechanisms for integration and normalization of logs.
- Extension of pre-built UDMs in Google SecOps and creation of custom parsers where required for log sources.
- Integration of Google SecOps SIEM with other security capabilities and tools such as SOAR, EDR, NDR, threat intelligence platform, and ticketing systems.
- Write custom actions, scripts and/or integrations to extend SIEM platform functionality.
- Monitor performance and perform timely actions to scale SIEM deployment, especially in a very high-volume security environment.
- Creation of SIEM assets such as: detection rules using YARA-L, dashboards, parsers etc.
- Migration of existing assets from existing customers SIEM/SOAR to SecOps and assisting in implementing the SIEM/SOAR phase-out, phase-in approach.
- Testing and deployment of newly created and migrated assets such as rules, playbooks, alerts, dashbords etc
- Design and implement solutions to handle alert fatigue encountered in SIEM correlation.
- Creation of custom SIEM dashboards to meet customer requirements.
- Guide on building or maturing cloud security programs and the implementation of tools and approaches used for improving cloud security.
- Debug and solve customer issues in ingestion, parsing, normalization of data etc
- Develop SOAR playbooks to provide case handling and Incident response as per triage needs
- Lead the design and implementation of Google SecOps SOAR playbooks for security use cases, such as phishing incident response, vulnerability triage, or threat hunting on Google SecOps based on specific threat models.
- Integration of Google SecOps SOAR with other security capabilities and tools such as SIEM, EDR, NDR threat intelligence platform, and ticketing systems.
- Design testing and conduct validation of SOAR playbooks before deployment to live environment.
- Write custom actions, scripts and/or integrations to extend SOAR platform functionality.
- Monitor performance and perform timely actions to scale SOAR deployment, especially in a high-volume security workplace.
- Migration of existing assets from existing customers SIEM/SOAR to SecOps and assisting in implementing the SIEM/SOAR phase-out, phase-in approach.
- Develop SOAR playbooks to provide case handling and Incident response as per triage needs
- Creation of SOAR assets such as reports etc.
- Guide on building or maturing cloud security programs
📌 Google SecOps (Ahmedabad)
🏢 Tata Consultancy Services
📍 Ahmedabad