Principal Incident Response Security Consultant, Mandiant, Google Cloud
US: $168000 - $243000 (USD) + 20% bonus target + equity + benefits
Learn more about benefits at Google.
- Collaborate with internal and customer teams to investigate and contain incidents.
- Conduct host forensics, network forensics, log analysis, and malware triage in support of incident response investigations.
- Lead complex client-facing investigations and examine cloud, endpoint, and network-based sources of evidence.
- Recognize and codify attacker tools, tactics, and procedures (TTPs) and indicators of compromise (IOCs); Build scripts, tools, or methodologies to enhance Mandiant’s incident investigation processes that can be applied to current and future investigations.
- Develop and present comprehensive and accurate reports and presentations for both technical and executive audiences.
Minimum qualifications:
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity or related technical field or equivalent practical experience.
- 8 years of experience assessing and developing cybersecurity solutions across multiple security domains.
- 8 years of investigative experience with network forensics, malware triage analysis, cloud forensics, or disk and memory forensics.
- 8 years of experience working end-to-end incident response investigations, analysis, or containment actions.
- Experience with incident management, customer-facing and computer forensics.
- Ability to travel up to 20% of the time as needed.
Preferred qualifications:
- Certifications in cloud platforms.
- Experience in security competitions, Capture the Flags (CTFs) or testing platforms such as Hack the Box, TryHackMe, Overthewire, etc.
- People Management experience
- Ability to communicate investigative findings and strategies to technical staff, executive leadership, legal counsel, and internal and external clients.
- Excellent time and project management skills.