- Design, implement, and optimize Google Chronicle SIEM for scalable log ingestion, parsing, normalization, and enrichment.
- Create and updating correlation rules and use cases
- Develop and fine-tune detection rules, parsers, and correlation logic to improve threat detection accuracy.
- Integrate diverse log sources including firewalls, endpoint security, cloud services, IAM, ,network devices and etc.,.
- Build and maintain custom parsers and dashboards to enhance visibility into security events.
- Collaborate with threat hunting and detection engineering teams to identify and implement recent detection logic.
- Design and implement automation workflows (SOAR-based or API-based) to reduce analyst workload and response time.
- Automate alert triage, enrichment, and response actions using scripts, playbooks, or orchestration tools.
- Integrate Google Chronicle with automation platforms (e.g., Cortex XSOAR, Splunk SOAR, Swimlane, or custom Python-based frameworks