SI

Lead Security Engineer

Accepting applications

Searce Inc · Hyderabad, Telangana, India

Full-Time Mid_senior PythonSOC
Estimated market salary
₹40-71 LPA

This is a SiliconBoard market estimate, not an employer-posted salary.

Posted
1d ago
Category
Design
Experience
Mid_senior
Country
India
Senior / Lead Cloud Security Engineer | Google SecOps

About the Role
Are you a SIEM/SOAR expert who lives at the intersection of security engineering, platform architecture, and customer success? We are looking for a hands-on Senior / Lead Cloud Security Engineer specializing in Google SecOps (Chronicle) to join our team.

In this role, you will lead high-impact greenfield deployments and drive complex platform migrations from legacy solutions like Splunk, Exabeam, IBM QRadar, and Microsoft Sentinel. You’ll serve as a trusted technical advisor, translating threat models into native YARA-L rules, building custom UDM parsers, and automating incident response workflows. Whether you are debugging a complex log parser or presenting a multi-phase migration strategy to a CISO, you will directly shape how modern enterprises defend their cloud and hybrid environments.

What You’ll Do

Architecture & Greenfield Deployments: Lead end-to-end Google SecOps implementations, including tenant provisioning, RBAC/multi-tenancy configuration, and architecture design across GCP, AWS, Azure, and on-premises environments.

Legacy SIEM/SOAR Migrations: Perform gap analyses and migrate log sources, rules, and workflows from Splunk ES, Exabeam, and Sentinel to Google SecOps, maintaining data fidelity and detection parity during parallel-run phases.

Log Ingestion & Custom Parser Authoring: Build robust ingestion pipelines using Bindplane, forwarders, and APIs. Author and maintain custom log parsers targeting the Unified Data Model (UDM) schema.

Detection Engineering: Design, test, and tune YARA-L 2.0 detection rules (single and multi-event) aligned with the MITRE ATT&CK framework, leveraging Google Threat Intelligence (Mandiant).

SOAR & Playbook Automation: Design automated triage, enrichment, and response playbooks in Google SecOps SOAR (Siemplify), integrating with tools like Jira, ServiceNow, and EDR solutions.

UEBA & Behavioral Analytics: Operationalize UEBA features by defining risk-scoring models, baseline profiling periods, and identity use cases to detect insider threats and lateral movement.

Client Enablement: Deliver technical runbooks, MITRE heatmaps, and post-go-live hypercare support to empower customer SOC teams.

What We’re Looking For

Platform Expertise: Proven experience with Google SecOps (Chronicle) and Google SecOps SOAR (Siemplify).

Query & Rule Syntax: Hands-on proficiency in YARA-L 2.0, Sigma rules, and Splunk SPL (for conversion logic).

Data & Schema Mastery: Deep understanding of the Google UDM schema, custom parser creation, and pipeline orchestration tools (Bindplane, Syslog, APIs).

Cloud Security: Experience configuring security telemetry from GCP, AWS, and Azure.

Scripting & Integration: Strong Python and REST API skills to build custom SOAR integrations and data automation.

Threat & Security Frameworks: Practical application of MITRE ATT&CK, NIST CSF, and threat intelligence standards (STIX/TAXII).

Preferred Certifications

Google Cloud Professional Security Engineer
Google Security Operations Practitioner
Splunk Core Certified Power User / Admin
CISSP, CEH, or equivalent industry certification

Why Join Us?
You’ll work at the forefront of cloud security, solving challenging engineering problems for enterprise environments while expanding our Google SecOps delivery practice. Apply today to help build the next generation of security operations!

Show more Show less