Responsibilities
- Monitor enterprise-wide security alerts and events using conventional cybersecurity platforms and artificial intelligence or machine learning-based threat detection systems.
- Conduct initial assessment, investigation, and correlation of security events to evaluate threat severity and potential business impact.
- Use Google Chronicle for threat intelligence gathering and log analysis to improve detection capabilities and investigative insights.
- Apply artificial intelligence techniques to detect behavioral anomalies and patterns that may signal security incidents, improving detection precision and reducing false alarms.
- Participate in on-call schedules to respond to high-priority security events as required.
- Analyze security breaches and incidents with AI-assisted tools to accelerate initial investigations and support proactive threat hunting.
- Respond to confirmed security incidents by executing predefined procedures for containment, threat removal, and system recovery.
- Perform root cause analysis and digital forensics to identify attack methods and suggest effective countermeasures.
- Utilize Google SecOps and Chronicle tools to aggregate security data, correlate events across systems, and speed up incident response processes.
- Employ machine learning models to detect new and evolving threats, delivering practical intelligence for incident handling.
- Work within the Google SecOps environment to enhance operational efficiency, visibility, and automation in security workflows.
- Coordinate with IT, security, and data science teams to embed Google Chronicle functionalities into the security operations center for improved detection and response.
- Fine-tune Google Chronicle configurations for optimal log handling, proactive threat searches, and advanced data analysis.
- Design and maintain automated response workflows for recurring security incidents, using AI to support decision-making and reduce response time.
- Automate standard SOC activities such as log review, incident categorization, and threat data enrichment through integrations with Google SecOps and Chronicle.
- Produce comprehensive incident reports and threat intelligence summaries that incorporate findings from AI-powered analysis.
- Deliver periodic reports on security performance and posture to internal teams, emphasizing AI-driven enhancements and risk reduction results.
- Generate and communicate reports on emerging threat patterns and SOC operations to both internal and external stakeholders.
- Suggest security enhancements and assist in developing standardized response playbooks for the SOC.
- Partner with cross-functional groups including IT, Customer Success, and Engineering to advance AI-integrated security programs and strengthen client security outcomes.
Benefits
- Access to advanced AI-powered cybersecurity tools and Google SecOps technologies.
- Collaboration with a skilled, forward-thinking team dedicated to enhancing security operations.
- Competitive compensation and comprehensive benefits.
- A supportive environment focused on professional growth, with opportunities to deepen expertise in AI, cybersecurity, and emerging tech.
Compensation
Competitive salary and benefits package
Work Arrangement
On-site — Overland Park, KS, Sarasota, FL
Other
- Shift options include Monday-Friday, Thursday-Sunday, or Friday-Monday.
- Third shift hours are 12AM to 10AM, consisting of four 10-hour workdays.
- The organization emphasizes in-person collaboration and values team cohesion fostered through on-site work.
- As an early team member, you will help shape the company culture and contribute to foundational development.
- Join a small, well-funded team recently backed by significant investment, offering low risk and high potential for growth.