Principal Defense Cyber Operations Engineer, Mandiant, Public Sector
- linkCopy link
- emailEmail a friend
Remote location: Ohio, USA.
Minimum qualifications:
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, related technical field, or equivalent practical experience.
- 8 years of experience in a Detection Engineering or related role.
- 6 years of experience with detection tuning and creation leveraging various security tools (e.g., SIEM, EDR, or NDR tools).
- Active US Government Top Secret/Sensitive Compartmentalized Information security clearance.
Preferred qualifications:
- GIAC Certified Intrusion Analyst (GCIA), GIAC Certified Incident Handler (GCIH), CompTIA PenTest+, CompTIA Cloud+, or equivalent qualifications listed in DoD 8140.3's Cyber Defense Analyst role.
- Experience with SPL, KQL, YARA-L, Kusto or similar SIEM query languages, with an understanding of SIEM log flow, aggregation, and forwarding.
- Ability to engage and collaborate with client stakeholders and other groups within the customer environment to drive resolution for security issues.
- Completed relevant military cyber training, such as the Joint Cyber Analysis Course (JCAC), Intermediate Cyber Core (CTN), or Navy Interactive ON-NET Operator.
About the job
In this role, you will join Google Public Sector as a Defensive Cyber Operations (DCO) Engineer, serving as a key component of a U.S. government defense customer's team. This position will be on-site full-time in Columbus, OH, 5 days a week. Your mission is to provide integrated cyber defense support. You will act as a versatile defender responsible for both proactive security, from continuous threat hunting and security control validation to hardening countermeasures and reactive duties like time-sensitive incident response, digital forensics, and malware analysis. A key part of your role will be operationalizing Google Threat Intelligence into custom detection signatures (e.g., Snort, Yara), providing a direct and tangible impact on the client's defensive posture. Success requires a deep understanding of computer networking, cyber threats and TTPs, and countermeasures development.Responsibilities
- Analyze network traffic, use SIEM platforms, and hunt for active and dormant threats to strengthen cyber defenses. This also involves operationalizing threat intelligence and developing custom detection signatures.
- Perform initial breach detection, assess threats, and provide comprehensive support during security incidents. This includes conducting deep technical analysis and performing root cause analysis of incidents.
- Configure and manage enterprise firewalls, and apply cybersecurity principles to organizational requirements to improve defenses.
- Use security validation tools for continuous testing of security controls. Identify systemic issues based on vulnerability and configuration data.
- Assist with government Authorization to Operate (ATO) efforts, create documentation, and deliver on-the-job training and cyber exercises to improve team readiness.
Information collected and processed as part of your Google Careers profile, and any job applications you choose to submit is subject to Google's Applicant and Candidate Privacy Policy.
Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See also Google's EEO Policy, Know your rights: workplace discrimination is illegal, Belonging at Google, and How we hire.
If you have a need that requires accommodation, please let us know by completing our Accommodations for Applicants form.
Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.
To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes.