Posted 23 August, 2026
Google SecOps / SIEM Engineer _ Infosys
Rickenbacker Aviation
India
Full Time
Reference: 365_463510_26-01944
Role: Google SecOps / SIEM Engineer
Experience: 5+ Years
Location: Pan India
Domain: Cyber Security / SIEM / SOC
Primary Skill: Google SecOps (Chronicle SIEM)
Vendor Rate: 8,330 – 9,330
Detailed Job Description:
Key Responsibilities
- Experience migrating from an incumbent SIEM/SOAR platform to Google SecOps is preferred.
- Familiarity with mapping Radar rules, Building Blocks (BBs), and Reference Sets (RS) to Google SecOps equivalents.
- Migrate Network Flow Data (NetFlow, sFlow, J-Flow) to the Google SecOps equivalent.
- Conduct requirements gathering and security use-case assessments.
- Configure and validate log source onboarding into Google SecOps.
- Perform UDM normalization and data validation activities.
- Develop and customize parsers for new log source integrations.
- Migrate SIEM content from Splunk, QRadar, ArcSight, Sentinel, etc., to Google SecOps.
- Map existing use cases/rules to Google SecOps detections.
- Perform gap analysis and monitoring coverage assessments.
- Design, develop, and optimize detection rules and correlation logic.
- Create security use cases aligned to MITRE Telecommunication&CK and Cyber Kill Chain frameworks.
- Review and tune SIEM content to improve detection effectiveness and reduce false positives.
- Integrate security tools, cloud platforms, and third-party solutions with Google SecOps.
- Build dashboards, reports, KPIs, and operational metrics.
- Conduct threat hunting using Google SecOps and threat intelligence.
- Perform threat modeling and identify monitoring opportunities.
- Recommend improvements to SOC processes, detection coverage, and platform utilization.
- Develop SOPs, runbooks, playbooks, and engineering documentation.
- Support KT, reverse KT, shadowing, and go-live activities.
- Drive security monitoring modernization and automation initiatives.
Mandatory Skills:
- 5+ years of Information Security and SIEM Engineering experience.
- Strong hands-on experience with Google SecOps (Chronicle SIEM).
- Experience with Splunk, IBM QRadar, ArcSight, Microsoft Sentinel, or similar SIEM platforms.
- Expertise in SIEM onboarding, content engineering, and platform transformation.
- Experience with parser development and log source integrations.
- Strong knowledge of Detection Engineering and Threat Hunting.
- Knowledge of MITRE Telecommunication&CK, Cyber Kill Chain, and Threat Intelligence.
- Scripting knowledge (Python/PowerShell) preferred.
- Experience working with cloud security environments (AWS/Azure/GCP) preferred.