Security Infrastructure Engineer (Google SecOps)

Talent Leaders Inc.

Doha

On-site

QAR 254,823 - 327,629

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

A leading tech staffing company is looking for a Security Engineer to architect data ingestion pipelines, develop automation playbooks, and ensure the integrity of data across multi-cloud environments. The ideal candidate will have a Bachelor's degree in IT or Cybersecurity, relevant SIEM certifications, and 3–5 years of hands-on experience in security engineering. Strong skills in Google SecOps, Python, and cloud infrastructure management are essential for success in this role.

Qualifications

  • 3–5 years of hands‑on experience in Security Engineering, SOC Automation, or Infrastructure Security.
  • Proven experience architecting and managing enterprise‑grade platforms like Splunk or Azure Sentinel.
  • Professional experience using Python to automate security workflows.

Responsibilities

  • Architect and maintain data ingestion pipelines for multi-cloud environments.
  • Design and code automated incident response playbooks in Google SOAR.
  • Monitor data ingestion health to ensure high-quality data.

Skills

Google SecOps
Python
Analytical Thinking
Communication Skills

Education

Bachelor’s degree in computer science, IT, Cybersecurity, or equivalent
SIEM Certification (e.g., Google SecOps, Splunk, Azure Sentinel)

Tools

Docker/Kubernetes
Git
Terraform

Job description

Functional Responsibilities
Data Ingestion and Normalization
  • Pipeline Management: Architect and maintain the ingestion of telemetry from multi-cloud (GCP, AWS, Azure) and on-premises environments using Bind Plane Forwarders, Cloud-to-Cloud (C2C) connectors, and Webhooks.
  • Parser Development: Design, build, and troubleshoot custom parsers (CBN) to ensure non-standard log sources are correctly normalized into the Unified Data Model (UDM).
  • Data Health Monitoring: Build dashboards to monitor ingestion rates, latency, and data drops to ensure the SIEM is always receiving high-quality, actionable data.
SOAR & Automation Engineering
  • Playbook Development: Design and code automated incident response playbooks in Google SOAR using Python and visual builders.
  • Connector Engineering: Build and maintain API integrations between Google SOAR and third‑party tools (Firewalls, EDR, IAM, Ticketing systems).
  • Workflow Optimization: Automate repetitive manual tasks such as artifact enrichment, evidence gathering, and initial containment actions.
  • Case Management Configuration: Tailoring the SOAR environment to fit the SOC’s operational needs, including custom fields, stages, and SLA tracking.
Platform Administration and Optimization
  • System Health Monitoring: Monitoring the ingestion health to ensure no data is dropped and that latency stays within acceptable limits.
  • Access Control: Managing Role-Based Access Control (RBAC) to ensure analysts have the correct level of access to sensitive data.
  • Threat Intel Ingestion: Managing the integration of Mandiant, Virus Total, and other third‑party threat intelligence feeds to ensure detections are always up to date with the latest global threats.
Collaboration with SOC Team
  • Feedback Loops: Collaborating with Tier 1 and Tier 2 analysts to tune YARA-L rules based on real-world alert performance and "noise" levels.
  • Requirements Gathering: Interviewing incident responders to understand their manual workflows, then translating those into Google SOAR playbooks.
  • Training & Enablement: Conducting knowledge transfer sessions on how to use UDM Search and the Google SecOps interface to speed up investigations.
Alignment with Infrastructure Team
  • Data Ingestion Strategy: Working with GCP/AWS/Azure Architects to ensure that Cloud Logging and Pub/Sub are configured correctly for seamless export to Google SecOps platform.
  • Agent Deployment: Coordinating with IT Infrastructure teams to deploy and maintain Bind Plane Forwarders on on‑premises servers and virtual machines.
  • Troubleshooting: Collaborating with Network Engineers to resolve connectivity issues or firewall blocks that prevent telemetry from reaching the Google SecOps platform.
Knowledge, Skills & Experience
Academic & Professional Qualifications:
  • Bachelor’s degree in computer science, IT, Cybersecurity, or equivalent.
  • SIEM Certification (e.g., Google SecOps, Splunk, Azure Sentinel).
Preferred:
  • Security certifications such as Security+, CySA+, CEH, CISSP, GCIH
Experience:
  • 3–5 years of hands‑on experience in Security Engineering, SOC Automation, DevOps Engineer, Security Operations, or Infrastructure Security.
Skills and Requirements:
Technical Skills (Must Have)
  • SIEM/SOAR Mastery: Proven experience architecting and managing enterprise‑grade platforms (e.g., Splunk, Azure Sentinel, or QRadar), with at least 1–2 years specifically focused on Google SecOps (Chronicle).
  • Key Requirement: Required skills: Google SecOps.
  • Coding & Scripting: Professional experience using Python to automate security workflows or build custom API connectors.
  • Cloud Infrastructure: Hands‑on experience managing security within Google Cloud Platform (GCP), including VPC service controls, IAM, and Cloud Logging.
  • Languages: Python (Advanced), SQL (BigQuery), YARA/YARA-L, and Bash.
  • Frameworks: MITRE ATT&CK, NIST Cybersecurity Framework.
  • Tools: Git (Version Control), Terraform (Infrastructure as Code), Docker/Kubernetes (Containerization).
  • Data Standards: Deep knowledge of JSON, Protobuf, and Regex for log parsing and normalization.
Soft Skills
  • Strong analytical thinking and problem‑solving capability.
  • Excellent communication skills, able to explain technical findings to non‑technical stakeholders.
  • Ability to work independently, manage multiple priorities, and meet deadlines.
  • Attention to detail and a structured, documentation‑driven mindset.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Infrastructure Engineer - Google SecOps
Security Infrastructure Engineer - Google SecOps

Meeza Qstp LLC • Qatar

On-site
QAR 180,000 - 300,000
Security Infra Engineer: Cloud SOAR & Data Automation
Security Infra Engineer: Cloud SOAR & Data Automation

Meeza Qstp LLC • Qatar

On-site
QAR 180,000 - 300,000
SecOps Security Infra Engineer — SIEM & SOAR Automation
SecOps Security Infra Engineer — SIEM & SOAR Automation

Talent Leaders Inc. • Doha

On-site
QAR 254,823 - 327,629
Security Infrastructure Engineer – Google SecOps | Doha, Qatar
Security Infrastructure Engineer – Google SecOps | Doha, Qatar

WorkWavez • Qatar

On-site
QAR 190,000 - 246,000
SOC Engineer
SOC Engineer

Experience • Doha

On-site
QAR 100,000 - 167,000
Senior SOC Engineer
Senior SOC Engineer

Tanqeeb • Doha

On-site
QAR 180,000 - 240,000
Lead SOC Analyst
Lead SOC Analyst

KalSoft • Doha

On-site
QAR 180,000 - 300,000
Senior SOC Engineer
Senior SOC Engineer

Black & Grey | People Advisory, Executive Search & Employer Branding • Doha

On-site
QAR 240,000 - 420,000
Security Infrastructure Engineer - Sentinel at Qatar Advanced Technology
Security Infrastructure Engineer - Sentinel at Qatar Advanced Technology

Qatar Advanced Technology • Qatar

On-site
QAR 112,000 - 145,000
Security Infrastructure Engineer: SIEM & SOAR Automation
Security Infrastructure Engineer: SIEM & SOAR Automation

Qatar Advanced Technology • Qatar

On-site
QAR 112,000 - 145,000