Explore Career Opportunities with GSV’s world-class partners

Powered By

Nu Advisory Partners

Cyber Defense Automation Engineer, Mandiant, Google Cloud



Software Engineering
United States
Posted on Wednesday, May 24, 2023

Note: Google’s hybrid workplace includes remote roles. By applying to this position you will have an opportunity to share your preferred working location from the following:

Remote locations: Texas, USA; United States.


Minimum qualifications:

  • 3 years of experience configuring and maintaining SOAR Technologies as part of Security Engineering, System Administration, or a similar role
  • 3 years of experience with networking, including TCP/IP and network topology
  • 2 years of experience scripting
  • 1 year of experience working with SOC/CSIRT or other incident response related teams

Preferred qualifications:

  • One or more of the following certifications or similar: CompTIA Security+, CompTIA Network+, CISCO (CCNA), ISC2 (CISSP), SANS (GSEC, GCIH, GCED, GCFA, GCIA, GNFA, GPEN)
  • Knowledge of scripting languages, especially Python
  • Fundamental understanding of security controls for common platforms and devices, including Windows, Linux and network equipment
  • Understanding of SOAR and its dependencies with experience managing and maintaining SOAR platforms; as well as working with/integrating APIs into automation playbooks
  • Understanding of the incident response, containment, and remediation process
  • Good written, verbal, and people management skills and the ability to simplify and communicate complex ideas

About the job

As a Cyber Defense Automation Engineer, you will be responsible for enabling the technology and tools required to effectively automate and orchestrate daily tasks within a Cyber Defense Center (CDC). You will collaborate with multiple cross-functional teams like Mandiant Architects, Mandiant Analysts, Client Information Technology (IT) resources, and other business resource owners, to define requirements and deliver recommendations focused on technologies, processes, scripting, and improvements required to support automation tasks within a CDC.

Google Cloud accelerates organizations’ ability to digitally transform their business with the best infrastructure, platform, industry solutions and expertise. We deliver enterprise-grade solutions that leverage Google’s cutting-edge technology – all on the cleanest cloud in the industry. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.

The US base salary range for this full-time position is $103,000-$151,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.


  • Identify challenges in customer Cyber Defense Centers and formulate strategies for improvement, identify candidates for automation, plan implementation of improvements, and execute/oversee plans to completion.
  • Advise on technologies relied upon by the client CDC, CSIRT, and SOC.
  • Provide expertise for SOAR and other SOC technologies that assist in incident response.
  • Create and modify SOAR playbooks written in Python.
  • Engage and collaborate with client stakeholders and other groups within customer environment to drive resolution for security issues.

Information collected and processed as part of your Google Careers profile, and any job applications you choose to submit is subject to Google's Applicant and Candidate Privacy Policy.

To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees or any other organization location. Google is not responsible for any fees related to unsolicited resumes.

At Google, we’re committed to building a workforce that is more representative of the users we serve and creating a culture where everyone feels like they belong. To learn more about our diversity, equity, inclusion commitments and how we’re building belonging, please visit our Belonging page for more information.

We welcome and encourage people who are expecting and/or parents-to-be to apply to this or any other role at Google.

Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles.