Senior Security Engineer
- תל אביב
- משרה קבועה
- משרה מלאה
- - Design, implement, and optimize Chronicle-based SIEM/SOAR solutions for enterprise customers.
- - Develop and test custom parsers and normalization rules for diverse log sources.
- - Integrate various log types (network, endpoint, cloud, application) into Chronicle and other security platforms.
- - Customize playbooks, detection rules, and response workflows based on client-specific use cases.
- - Collaborate with Client GCP security consultants, threat analysts, and client security teams to improve incident response processes.
- - Lead engineering aspects of security data onboarding and parsing optimization projects.
- - Maintain documentation and technical guides for client SOC (Security Operations Center) teams.
- - Stay up to date with evolving log formats, security threats, and GCP security capabilities.
- - Bachelor's degree in Computer Science, Cybersecurity, or related field (or equivalent practical experience).
- 5+ years of experience in cloud security engineering, with a strong focus on Google Cloud Platform (GCP).
- Proven experience with DevSecOps methodologies and integrating security into CI/CD pipelines.
- Hands-on experience with GCP security services including IAM, VPC Service Controls, Cloud Armor, KMS, Security Command Center.
- Strong understanding of network security principles (firewalls, VPNs, load balancing, DNS) and their implementation on GCP.
- Proficiency in at least one scripting language (e.g., Python, Go, Bash) for automation and security tool development.
- Experience with Infrastructure as Code (IaC) tools, particularly Terraform.
- Solid understanding of security monitoring, logging, and alerting concepts.
- Familiarity with common security frameworks (e.g., NIST, MITRE ATT&CK, OWASP Top 10).
- - Strong scripting skills (e.g., Python, Bash) and familiarity with API integrations.
- - Fluent in English, with excellent written and verbal communication skills.
- - Certification: PCSE (Google Professional Cloud Security Engineer) or equivalent (CISSP, CEH, etc.).
- - Overall 8+ years of experience
- Google Cloud Professional Cloud Security Engineer certification.
- Experience with SIEM/SOAR platforms (e.g., Chronicle Security Operations, Splunk, Sentinel).
- Hands-on experience with container security (Docker, Kubernetes/GKE) and service mesh security (e.g., Istio).
- Experience with advanced threat detection techniques, including behavioral analytics and machine learning for security.
- Familiarity with compliance automation tools and security scorecards.
- Experience in a highly regulated industry.
- Strong understanding of incident response processes and forensic analysis in a cloud environment.
Mploy