user avatar

Principal Defense Cyber Operations Engineer, Mandiant, Public Se

Google, Inc.

Today
Top Secret
Unspecified
Unspecified
IT - Security
Remote/Hybrid (Off-Site/Hybrid)

Note: Google's hybrid workplace includes remote roles.

Remote location: Ohio, USA.Minimum qualifications:
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, related technical field, or equivalent practical experience.
  • 8 years of experience in a Detection Engineering or related role.
  • 6 years of experience with detection tuning and creation leveraging various security tools (e.g., SIEM, EDR, or NDR tools).
  • Active US Government Top Secret/Sensitive Compartmentalized Information security clearance.

Preferred qualifications:
  • GIAC Certified Intrusion Analyst (GCIA), GIAC Certified Incident Handler (GCIH), CompTIA PenTest+, CompTIA Cloud+, or equivalent qualifications listed in DoD 8140.3's Cyber Defense Analyst role.
  • Experience with SPL, KQL, YARA-L, Kusto or similar SIEM query languages, with an understanding of SIEM log flow, aggregation, and forwarding.
  • Ability to engage and collaborate with client stakeholders and other groups within the customer environment to drive resolution for security issues.
  • Completed relevant military cyber training, such as the Joint Cyber Analysis Course (JCAC), Intermediate Cyber Core (CTN), or Navy Interactive ON-NET Operator.

About the job
In this role, you will join Google Public Sector as a Defensive Cyber Operations (DCO) Engineer, serving as a key component of a U.S. government defense customer's team. This position will be on-site full-time in Columbus, OH, 5 days a week. Your mission is to provide integrated cyber defense support. You will act as a versatile defender responsible for both proactive security, from continuous threat hunting and security control validation to hardening countermeasures and reactive duties like time-sensitive incident response, digital forensics, and malware analysis. A key part of your role will be operationalizing Google Threat Intelligence into custom detection signatures (e.g., Snort, Yara), providing a direct and tangible impact on the client's defensive posture. Success requires a deep understanding of computer networking, cyber threats and TTPs, and countermeasures development.

Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.

The US base salary range for this full-time position is $164,000-$243,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.

Responsibilities
  • Analyze network traffic, use SIEM platforms, and hunt for active and dormant threats to strengthen cyber defenses. This also involves operationalizing threat intelligence and developing custom detection signatures.
  • Perform initial breach detection, assess threats, and provide comprehensive support during security incidents. This includes conducting deep technical analysis and performing root cause analysis of incidents.
  • Configure and manage enterprise firewalls, and apply cybersecurity principles to organizational requirements to improve defenses.
  • Use security validation tools for continuous testing of security controls. Identify systemic issues based on vulnerability and configuration data.
  • Assist with government Authorization to Operate (ATO) efforts, create documentation, and deliver on-the-job training and cyber exercises to improve team readiness.

Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Google's EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our Accommodations for Applicants form.
group id: RTX191830
Find Google, Inc. on Social Media
Network Employers
user avatar
About Us
Since our founding in 1998, Google has grown by leaps and bounds. Starting from two computer science students in a university dorm room, we now have over a hundred thousand employees, and multiple divisions within the company all focused on our mission of organizing the world‘s information and making it universally accessible and useful. Google Public Sector, a Google division, plays a critical role in applying cloud technology to solve complex problems for our nation—across U.S. federal, state, and local governments, and educational institutions. We are proud to have served the U.S. public sector for many years, and are looking for cleared professionals to join our team to help us rapidly expand our services to the government, now and into the future.

Google, Inc. Jobs


Job Category
IT - Security
Clearance Level
Top Secret
Employer
Google, Inc.