Cyber - Google SecOps - Manager
About the role
Deloitte's Cyber team helps clients address evolving cybersecurity challenges and opportunities by delivering solutions and managed services that reduce complexity, strengthen resilience, and support confident growth. As a Google SecOps Manager supporting Google SecOps engagements, you will contribute to high-visibility projects by applying advanced SOC engineering experience and knowledge of Google SecOps, threat detection engineering, SIEM, SOAR, and automation development. You will design, implement, and optimize secure, outcome-focused solutions while collaborating across teams to deliver reliable and efficient security operations capabilities. In this role, you will also mentor practitioners and help advance modern Google SecOps methods across the team.
Responsibilities
- Lead the design and implementation of secure, scalable Google SecOps architectures, including SIEM and SOAR capabilities aligned to client security requirements and regulatory obligations such as General Data Protection Regulation (GDPR) and Payment Card Industry Data Security Standard (PCI DSS).
- Lead end-to-end deployment of log ingestion pipelines using data fabric technologies and integrations such as Bindplane, Cloud Feeds, and application programming interfaces (APIs).
- Collaborate with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious behavior across enterprise environments.
- Translate SOC processes into SOAR automation playbooks to reduce alert fatigue and scale alert triage and response.
- Develop and manage integrations across third-party platforms, security tools, and Google SecOps to support automated data ingestion, alert enrichment, response actions, and case management workflows.
- Lead and mentor junior team members in SOC engineering, including SIEM, SOAR, and process development.
Skills
- Ability to work independently and collaborate as part of a team.
- Effective written and verbal communication skills.
- Meticulous attention to detail and quality of work product.
- Ability to build and sustain professional relationships.
- Ability to lead projects or workstreams.
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment.
- Strong interpersonal skills and professional demeanor.
- Ability to meet deadlines.
- Ability to mentor and provide clear guidance to others.
About the team
Our Cyber Defense & Resilience offering helps organizations defend against advanced threats by transforming security operations, monitoring technologies, data analytics, and threat intelligence capabilities. The team supports clients in managing and protecting dynamic attack surfaces while providing rapid crisis and cyber incident response. Through this work, we help clients strengthen readiness, response, and recovery across business disruptions.
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or another technical field, or equivalent work experience.
- 9+ years of experience in security operations, threat detection engineering, or enterprise information technology security.
- Experience with Google Cloud SecOps tool stack and architecture, including Google Chronicle SIEM, Google SecOps SOAR, Google Siemplify SOAR, threat detection engineering, and security operations center workflows.
- Experience with Python scripting and GoStash or Logstash for automation, integration development, log normalization, and parsing, as well as with extract, transform, load (ETL) pipelines and technologies such as Cribl, Bindplane, NXLog, Kafka, Cloud Feeds, and APIs.