Google logo
Google
Posted 24 days agoVerified live 12h ago

Security Consultant, SOAR, Mandiant, Google Cloud

Brief overview

Remote
UndergradOr in progress
$112k–$161k/yrStated range
3+ yrsMinimum
3,481 H-1B approvalsDept. of Labor
5,988 green cardsCertified filings
Security Orchestration, Automation, and Response (SOAR)Security Information and Event Management (SIEM)SOC/CSIRT Incident ResponseSOAR Platform AdministrationAPI Integration and RESTful ProgrammingPythonPandasSecurity Controls for Windows and LinuxIncident Response, Containment, and RemediationCompTIA Security+CISSPCCNA

Visa sponsorship history

4 years sponsoring, last filed FY2026

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
3,481H-1B approved
95%approval rate
491new H-1B hires
5,988PERM certified
$189,000median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
2023727
2024462
20251,252
20261,040
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20231,408
20241,414
2025941
2026794
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
20234,381
20241,607
Top sponsored roles
Software EngineerProgram ManagerTechnical Program ManagerProduct Manager
Sponsored employees from
ChinaIndiaCanadaTaiwanSouth Korea

Job description

Summary

Google, through its Mandiant cybersecurity organization within Google Cloud, provides cyber defense, threat intelligence, and incident response services. The Security Consultant will enable and improve the technologies, processes, and automation used within customer Cyber Defense Centers by administering security tools, developing SOAR playbooks, and collaborating with cross-functional stakeholders.

Responsibilities

  • Identify issues in customer Cyber Defense Centers, formulate strategies for improvement, identify candidates for automation, plan implementation of improvements, and execute/oversee plans to completion
  • Advise on technologies relied upon by the client CDC, CSIRT, and SOC
  • Provide expertise for SOAR and other SOC technologies that assist in incident response
  • Create and modify SOAR playbooks written in Python
  • Engage and collaborate with client stakeholders and other groups within the customer environment to drive resolution for security issues

Skills

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, a related technical field, or equivalent practical experience
  • 3 years of experience configuring and maintaining Security Orchestration, Automation, and Response (SOAR) Technologies as part of Security Engineering, System Administration, or a similar role
  • 3 years of experience working with SOC/CSIRT or other incident response related teams
  • Experience with Security Information and Event Management (SIEM) solutions (e.g., writing queries, searches, alerts, dashboards)
  • One or more of the following certifications or similar: CompTIA Security+, CompTIA Network+; CISCO (CCNA); ISC2 (CISSP); SANS (GSEC, GCIH, GCED, GCFA, GCIA, GNFA, GPEN)
  • Experience managing and maintaining SOAR platforms and its dependencies, and working with/integrating APIs into automation playbooks
  • Experience with commercial SIEM technologies (e.g., Google SecOps, Splunk, Helix, Devo, Sentinel)
  • Working knowledge of scripting languages (e.g., Python)
  • Understanding of security controls for platforms/devices (e.g., Windows, Linux, network equipment), web-based APIs/RESTful programming (e.g., Python libraries), and data manipulation/analysis libraries (e.g., Pandas)
  • Understanding of the incident response, containment, and remediation process

Qualifications

Must Haves

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, a related technical field, or equivalent practical experience
  • 3 years of experience configuring and maintaining Security Orchestration, Automation, and Response (SOAR) Technologies as part of Security Engineering, System Administration, or a similar role
  • 3 years of experience working with SOC/CSIRT or other incident response related teams
  • Experience with Security Information and Event Management (SIEM) solutions (e.g., writing queries, searches, alerts, dashboards)

Nice to Haves

  • One or more of the following certifications or similar: CompTIA Security+, CompTIA Network+; CISCO (CCNA); ISC2 (CISSP); SANS (GSEC, GCIH, GCED, GCFA, GCIA, GNFA, GPEN)
  • Experience managing and maintaining SOAR platforms and its dependencies, and working with/integrating APIs into automation playbooks
  • Experience with commercial SIEM technologies (e.g., Google SecOps, Splunk, Helix, Devo, Sentinel)
  • Working knowledge of scripting languages (e.g., Python)
  • Understanding of security controls for platforms/devices (e.g., Windows, Linux, network equipment), web-based APIs/RESTful programming (e.g., Python libraries), and data manipulation/analysis libraries (e.g., Pandas)
  • Understanding of the incident response, containment, and remediation process

Benefits

  • 15% bonus target
  • Equity

More jobs like this