Sr. SOC Engineer (Google SecOps)

Posted 6 Days Ago
Be an Early Applicant
Dallas, TX, USA
Hybrid
Senior level
Machine Learning • Mobile • Security
The Role
Own and engineer the Google SecOps platform, including log ingestion, detection rules, alert routing, SOAR workflows, integrations, and automation. Lead complex incident investigations, root-cause analysis, containment, remediation, and post-incident reporting. Build SOC tooling with Python, Go, or Bash; integrate CNAPP and security tools; define SOC metrics and dashboards; support audits; and serve as incident commander for high-severity events.
Summary Generated by Built In

Zimperium® is the world leader in mobile security, purpose-built to protect the modern mobile enterprise. Trusted by leading organizations and governments, our AI-driven platform delivers real-time, on-device protection for mobile applications and devices. We help organizations stay ahead with proactive defense against evolving threats—including mobile-targeted phishing (mishing), malware, app vulnerabilities, and zero-day exploits. Our mission is to empower organizations to operate securely and confidently in today’s dynamic digital environment.

We are looking for a Sr. SOC Engineer to own and operate our Google SecOps platform end-to-end. You will architect log ingestion, author threat detection rules, design agentic AI-powered triage and response automation, integrate our CNAPP platform with security operations workflows, and lead investigative response to high-severity incidents. This is a hands-on engineering role: you will execute the work yourself, not manage others' execution. You will own the detection strategy, platform architecture, automation design, and incident response quality. You will be the person your team calls when a new log source needs to be ingested and routed, when detection rules aren't firing, or when a complex incident demands technical leadership.

You will own the outcomes and drive how the SOC operates. You will work in close collaboration with our DevOps, Cloud Security, and Product Security teams. You are expected to operate independently, make architectural decisions, and have the judgment to act without direction. Your technical and strategic decisions will drive Zimperium's security posture directly.

Location: Dallas, TX preferred

Key Responsibilities:
  • 8+ years in security operations, threat detection, or incident response, with at least 4 years in a SIEM/SOC engineering or detection engineering role.

  • Deep hands-on experience with at least one major SIEM platform (Splunk, ELK, Chronicle/Google SecOps, Sentinel, Sumo Logic). Production experience with detection authoring and tuning.

  • Strong understanding of log types and sources—OS logs, application logs, network flow, DNS, proxy, endpoint telemetry, CNAPP/runtime security events. Ability to interpret and normalize heterogeneous data.

  • Experience building or tuning threat detection rules and correlation logic. Working knowledge of attack frameworks (MITRE ATT&CK) and how to operationalize them.

  • Proficiency in at least one scripting/programming language (Python, Go, Bash) sufficient to build and maintain automation, not just modify examples.

  • Experience integrating security tools—APIs, webhooks, orchestration platforms (Zapier, Make, native SOAR). Comfortable debugging API calls and data flow.

  • Hands-on incident investigation experience—evidence collection, root cause analysis, timeline reconstruction, scope determination.

  • Familiarity with mobile threat detection, CNAPP, or endpoint threat detection. Understanding of how mobile/app security signals differ from infrastructure security.

  • Strong written and verbal communication—ability to explain technical findings to non-technical stakeholders and brief executives on incidents and trends.

  • Proven ability to operate independently, take ownership, and make decisions with sound judgment to non-technical stakeholders and brief executives on incidents and trends.

  • Proven ability to operate independently, take ownership, and make decisions with sound judgment.

  • Strong written and verbal communication—ability to explain technical findings to non-technical stakeholders and brief executives on incidents and trends.

Required Qualifications:
  • CNAPP & SecOps Integration. Orchestrate data flow from Zimperium's CNAPP platform into Google SecOps and other security tools. Build and own integrations to coordinate threat notifications, ensure consistent severity assignment, and enable unified response across mobile and cloud/infrastructure security.

  • Google SecOps Platform Engineering. Own and maintain Google SecOps as the operational hub—SOAR workflows, alert routing logic, case management, automation rules, integrations with ticketing systems (Jira), notification channels, and escalation procedures. You make architectural decisions on how alerts flow through the system and how the team works.

  • Investigative Leadership. Lead investigations into high-severity and complex incidents. Conduct root cause analysis, determine scope and impact, coordinate containment and remediation, and produce clear post-incident reports. You own the investigative strategy and mentor junior analysts on tradecraft.

  • SOC Automation & Tooling. Write or adapt tools and scripts (Python, Go, Bash) to automate SOC workflows—bulk event analysis, data enrichment, response actions, reporting. Integrate third-party tools and APIs into Google SecOps workflows. You own the efficiency and scale of the SOC's technical operations.

  • Metrics & Reporting. Define, instrument, and own SOC KPIs—detection latency, mean time to respond (MTTR), investigation duration, false positive rate, automation coverage. Build dashboards and reports for leadership. You are accountable for continuous improvement in SOC performance.

  • On-Call & Incident Response. Serve as incident commander or key investigator for high-priority events. Drive incidents to root cause, not just closure. You own the incident response quality.

  • Compliance & Audit Support. Generate evidence and documentation for security audits (ISO 27001, FedRAMP). Translate technical findings into auditor-readable format.

Preferred Qualifications:
  • Prior experience with Google Chronicle, Google SecOps, or similar cloud-native SIEM platforms.

  • Experience with AI/ML-based alert triage, anomaly detection, or automated incident response.

  • Experience operating in regulated or compliance-heavy environments—FedRAMP, DoD, PCI-DSS, HIPAA.

  • Hands-on experience with mobile threat detection, mobile app security, or container/Kubernetes runtime security.

  • Experience with threat modeling, vulnerability disclosure coordination, or security research.

  • Relevant certifications (GCIH, ECIH, OSINT, GIAC certifications, or vendor-specific: Google Cloud Security, AWS Security, etc.).

  • Prior DevSecOps, security engineering, or cloud security experience. A background in building systems shows a level of thinking we value.

 

Zimperium is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex including sexual orientation and gender identity, national origin, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law.

Skills Required

  • 8+ years of experience in security operations, threat detection, or incident response
  • At least 4 years of SIEM, SOC engineering, or detection engineering experience
  • Hands-on production experience with a major SIEM platform and detection authoring and tuning
  • Experience interpreting and normalizing OS, application, network, DNS, proxy, endpoint, CNAPP, and runtime security data
  • Experience building and tuning threat detection rules and correlation logic
  • Working knowledge of MITRE ATT&CK and operationalizing attack frameworks
  • Proficiency in Python, Go, or Bash for SOC automation
  • Experience integrating security tools through APIs, webhooks, orchestration platforms, or SOAR
  • Hands-on incident investigation experience, including evidence collection, root-cause analysis, timeline reconstruction, and scope determination
  • Strong written and verbal communication skills, including executive incident briefings
  • Ability to operate independently, take ownership, and make sound technical decisions
  • Experience integrating CNAPP data with Google SecOps and other security tools
  • Experience engineering and maintaining Google SecOps workflows, alert routing, case management, automations, integrations, notifications, and escalations
  • Experience leading high-severity investigations and coordinating containment and remediation
  • Experience mentoring junior analysts on investigative tradecraft
  • Experience defining SOC KPIs and building dashboards and reports
  • Ability to serve as incident commander or key investigator during on-call events
  • Experience generating security audit evidence and documentation
  • Experience with Google Chronicle, Google SecOps, or similar cloud-native SIEM platforms
  • Experience with AI/ML-based alert triage, anomaly detection, or automated incident response
  • Experience in regulated environments such as FedRAMP, DoD, PCI-DSS, or HIPAA
  • Experience with mobile threat detection, mobile application security, or container/Kubernetes runtime security
  • Experience with threat modeling, vulnerability disclosure coordination, or security research
  • GCIH, ECIH, OSINT, GIAC, Google Cloud Security, AWS Security, or similar certification
  • Prior DevSecOps, security engineering, or cloud security experience
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Dallas, TX
237 Employees
Year Founded: 2010

What We Do

Zimperium provides the only mobile security platform purpose-built for enterprise environments. With machine learning-based protection and a single platform that secures everything from applications to endpoints, Zimperium's solution provides on-device mobile threat defense to protect growing and evolving mobile environments. Our solutions include zIPS which runs locally on any mobile device and detects cyberattacks without a connection to the cloud and our first-of-its-kind Mobile Application Protection Suite (MAPS), a comprehensive solution that helps organizations protect their mobile apps throughout their entire life cycle. Zimperium’s MAPS is comprised of four solutions that help enterprises to build secure and compliant mobile applications. It is the only unified solution that combines comprehensive in-app protection with centralized threat visibility. zScan: Helps your mobile app development organization to discover and fix compliance, privacy, and security issues within the development process before you publicly release your apps; zKeyBox: Protects your secrets and keys so they cannot be discovered, extracted, or manipulated. zShield: Protects the source code, intellectual property (IP), and data from potential attacks like reverse engineering and code tampering. zDefend: Is an SDK embedded in apps to help detect and defend against device, network, phishing, and malware attacks. Zimperium was the first MTD provider to be granted an Authority to Operate (ATO) status from the Federal Risk and Authorization Management Program (FedRAMP). Headquartered in Dallas, TX, Zimperium is backed by Liberty Strategic Capital and SoftBank.

Similar Jobs

Capital One Logo Capital One

Compliance Tester III

Fintech • Machine Learning • Payments • Software • Financial Services
Hybrid
8 Locations
55000 Employees
110K-151K Annually

Capital One Logo Capital One

Principal Associate, Sourcing Manager

Fintech • Machine Learning • Payments • Software • Financial Services
Hybrid
6 Locations
55000 Employees
110K-151K Annually

Capital One Logo Capital One

Compliance Testing Sr. Manager

Fintech • Machine Learning • Payments • Software • Financial Services
Hybrid
8 Locations
55000 Employees
162K-221K Annually

Capital One Logo Capital One

Principal Risk Specialist (Auto - Data Risk)

Fintech • Machine Learning • Payments • Software • Financial Services
Hybrid
Plano, TX, USA
55000 Employees
110K-125K Annually

Similar Companies Hiring

ARB Interactive Thumbnail
Gaming • Mobile • Software
Miami, Florida
190 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account