Security Infrastructure Engineer - Google SecOps

Meeza Qstp LLC

Qatar

On-site

QAR 180,000 - 300,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Meeza Qstp LLC is seeking a Security Infrastructure Engineer with Google SecOps focus to design, implement, and optimize data ingestion pipelines across GCP, AWS, Azure and on-prem environments. You will build parsers, dashboards, playbooks, and API integrations to ensure high-quality telemetry and rapid incident response.

The role requires hands-on experience with SIEM/SOAR platforms, cloud security, and scripting to automate repetitive tasks, collaborate with SOC teams, and improve data

Qualifications

  • Bachelor's degree in computer science, IT, cybersecurity, or equivalent.
  • SIEM Certification (Google SecOps, Splunk, Azure Sentinel).
  • Security certifications such as Security+, CySA+, CEH, CISSP, GCIH.

Responsibilities

  • Data Ingestion and Normalization Pipeline Management.
  • Architect and maintain ingestion of telemetry from multi-cloud environments.
  • Parser development to normalize non-standard log sources into the Unified Data Model.
  • Data health monitoring with dashboards for ingestion rates and latency.
  • SOAR & automation engineering; develop incident response playbooks in Google SOAR.
  • Connector engineering and API integrations with third-party tools.
  • Automate repetitive tasks and manage RBAC for analysts access.

Skills

Python (Advanced)
SQL (BigQuery)
YARA/YARA-L
Bash
Regex
Git
Terraform
Docker/Kubernetes
Incident response
SOAR
Google SecOps
Cloud platforms (GCP AWS Azure)
RBAC
Log parsing & normalization
System health monitoring

Education

Bachelor's degree in computer science, IT, Cybersecurity, or equivalent
SIEM Certification (Google SecOps, Splunk, Azure Sentinel)
Security certifications (Security+, CySA+, CEH, CISSP, GCIH)

Tools

Git
Terraform
Docker/Kubernetes

Job description

The primary responsibilities of the Security Infrastructure Engineer Google SecOps Functional Responsibilities
  • Data Ingestion and Normalization Pipeline Management
  • Architect and maintain the ingestion of telemetry from multi-cloud GCP AWS Azure and on-premises environments using Bind Plane Forwarders Cloud-to-Cloud C2C connectors and Webhooks
  • Parser Development Design build and troubleshoot custom parsers CBN to ensure non-standard log sources are correctly normalized into the Unified Data Model UDM
  • Data Health Monitoring Build dashboards to monitor ingestion rates latency and data drops to ensure the SIEM is always receiving high-quality actionable data
  • SOAR amp Automation Engineering
  • Playbook Development Design and code automated incident response playbooks in Google SOAR using Python and visual builders
  • Connector Engineering
  • Build and maintain API integrations between Google SOAR and third-party tools Firewalls EDR IAM Ticketing systems
  • Workflow Optimization
  • Automate repetitive manual tasks such as artifact enrichment evidence gathering and initial containment actions
  • Case Management Configuration
  • Tailoring the SOAR environment to fit the SOC s operational needs including custom fields stages and SLA tracking
  • Platform Administration and Optimization
  • System Health Monitoring
  • Monitoring the ingestion health to ensure no data is dropped and that latency stays within acceptable limits
  • Access Control
  • Managing Role-Based Access Control RBAC to ensure analysts have the correct level of access to sensitive data
  • Threat Intel Ingestion
  • Managing the integration of Mandiant Virus Total and other third-party threat intelligence feeds to ensure detections are always up to date with the latest global threats
  • Collaboration with SOC Team
  • Feedback Loops
  • Collaborating with Tier 1 and Tier 2 analysts to tune YARA-L rules based on real-world alert performance and noise levels
  • Requirements Gathering
  • Interviewing incident responders to understand their manual workflows then translating those into Google SOAR playbooks
  • Training amp Enablement
  • Conducting knowledge transfer sessions on how to use UDM Search and the Google SecOps interface to speed up investigations
  • Alignment with Infrastructure Team
  • Data Ingestion Strategy
  • Working with GCP AWS Azure Architects to ensure that Cloud Logging and Pub Sub are configured correctly for seamless export to Google SecOps platform
  • Agent Deployment
  • Coordinating with IT Infrastructure teams to deploy and maintain Bind Plane Forwarders on on-premises servers and virtual machines
  • Troubleshooting
  • Collaborating with Network Engineers to resolve connectivity issues or firewall blocks that prevent telemetry from reaching the Google SecOps platform
Knowledge, Skills & Experience

Academic & Professional Qualifications:

  • Bachelor s degree in computer science, IT, Cybersecurity, or equivalent.
  • SIEM Certification ( Google SecOps, Splunk, Azure Sentinel).
  • Preferred: Security certifications such as Security+, CySA+, CEH, CISSP, GCIH Google SecOps Engineer Experience:3 5 years of hands-on experience in Security Engineering, SOC Automation, DevOps Engineer, Security Operations, or Infrastructure Security.
Skills and Requirements
  • SIEM/SOAR Mastery: Proven experience architecting and managing enterprise-grade platforms (e.g., Splunk, Azure Sentinel, or QRadar), with at least 1 2 years specifically focused on Google SecOps (Chronicle).
  • Key Requirement: Required skills: Google SecOps.Coding & Scripting: Professional experience using Python to automate security workflows or build custom API connectors.
  • Cloud Infrastructure: Hands-on experience managing security within Google Cloud Platform (GCP), including VPC service controls, IAM, and Cloud Logging.
  • Languages: Python (Advanced), SQL (BigQuery), YARA/YARA-L, and Bash.
  • Frameworks: MITRE ATT&CK, NIST Cybersecurity Framework.
  • Tools: Git (Version Control), Terraform (Infrastructure as Code), Docker/Kubernetes (Containerization).
  • Data Standards: Deep knowledge of JSON, Protobuf, and Regex for log parsing and normalization.
  • Soft SkillsStrong analytical thinking and problem-solving capability.Excellent communication skills, able to explain technical findings to non-technical stakeholders.Ability to work independently, manage multiple priorities, and meet deadlines.Attention to detail and a structured, documentation-driven mindset.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Infra Engineer: Cloud SOAR & Data Automation
Security Infra Engineer: Cloud SOAR & Data Automation

Meeza Qstp LLC • Qatar

On-site
QAR 180,000 - 300,000
Senior SIEM Engineer
Senior SIEM Engineer

malomatia • Doha

On-site
QAR 180,000 - 360,000
Security Infrastructure Engineer - Sentinel at Qatar Advanced Technology
Security Infrastructure Engineer - Sentinel at Qatar Advanced Technology

Qatar Advanced Technology • Qatar

On-site
QAR 112,000 - 145,000
Senior SOAR Engineer
Senior SOAR Engineer

malomatia • Doha

On-site
QAR 200,000 - 350,000
Senior Engineer - Cloud Platform
Senior Engineer - Cloud Platform

Malomatia • Doha

On-site
QAR 180,000 - 300,000
Security Infrastructure Engineer: SIEM & SOAR Automation
Security Infrastructure Engineer: SIEM & SOAR Automation

Qatar Advanced Technology • Qatar

On-site
QAR 112,000 - 145,000
Security Analyst - IT Ops
Security Analyst - IT Ops

Mekdam Technical Services • Doha

On-site
Senior Cloud Network Security Engineer
Senior Cloud Network Security Engineer

Codvo Private Limited • Doha

On-site
QAR 109,000 - 164,000
Cybersecurity Detection Engineer
Cybersecurity Detection Engineer

Employment • Doha

On-site
QAR 180,000 - 240,000
Consultant - Cloud Platform Engineering
Consultant - Cloud Platform Engineering

malomatia • Qatar

On-site
QAR 180,000 - 260,000