Aviato Consulting
Website:
aviato.consulting
Job details:
We are a Google Cloud services firm delivering security operations transformations for enterprise customers across Australia. We are looking for a hands-on Google SecOps (Chronicle) engineer who can build, deploy, and operate modern SIEM and SOAR capabilities, and do so directly in front of the customer. You will own technical delivery end to end: from data onboarding and detection engineering through to automated response and ongoing operations.
This is a customer-facing engineering role. You will spend significant time with Australian customers, running workshops, gathering requirements, and explaining your work clearly to both technical and non-technical stakeholders.
Key Responsibilities
Platform Build & Deployment: Deploy and configure Google SecOps, including log source onboarding, data ingestion pipelines, parser development, and normalisation to the Unified Data Model (UDM).
Detection Engineering: Design, build, and tune detection content using YARA-L. Develop threat-hunting queries, reduce false positives, and align detection coverage to frameworks relevant to Australian customers (for example, MITRE ATT&CK and the ACSC Essential Eight).
SOAR Automation: Build and maintain SOAR playbooks and response automation in Google SecOps. Integrate with customer tooling (ticketing, identity, cloud, email, endpoint) via APIs and out-of-the-box connectors to streamline triage and response.
Operate & Optimise: Monitor platform health, ingestion, and detection performance. Tune rules and pipelines over time, support incident investigation, and keep the deployment reliable and cost-effective.
Customer Delivery: Serve as the technical point of contact for customer engagements. Run onboarding sessions and workshops, translate security requirements into working configuration, and communicate progress, constraints, and trade-offs clearly to customer stakeholders.
Integration & Data Engineering: Connect diverse log sources and feeds, build and maintain parsers, and ensure data quality and coverage across the customer environment.
Mandatory Experience & Qualifications
SIEM Engineering: Hands-on experience deploying and operating a modern SIEM. Direct Google SecOps / Chronicle experience is strongly preferred; equivalent experience with Splunk, Microsoft Sentinel, or similar will be considered where transferable.
Detection Engineering: Practical experience writing and tuning detection rules (YARA-L, SPL, KQL, or equivalent) and working with a normalised data model such as UDM.
SOAR & Automation: Experience building SOAR playbooks and response automation (Google SecOps SOAR / Siemplify, Splunk SOAR, or similar), including integrating third-party tools via APIs.
Log Onboarding & Parsing: Proven ability to onboard log sources, develop parsers, and manage ingestion pipelines.
Customer-Facing Skills: Strong communication skills and the ability to lead technical sessions with customers, gather requirements, and explain complex security concepts to non-technical stakeholders.
Scripting: Working proficiency in Python (or similar) for automation, integration, and tooling.
Beneficial / Optional Experience
Experience with Google Cloud Platform (GCP) and cloud security operations. Familiarity with Australian security frameworks and guidance, including the ACSC Information Security Manual (ISM), and IRAP-assessed environments. Relevant certifications such as Google Cloud Security Engineer, or SANS GIAC credentials (GCIA, GCDA, GDAT). Experience with CI/CD and detection-as-code practices for managing content in version control. A background in SOC operations, incident response, or threat hunting.
Our Core Values:
We operate with radical transparency, believe in rigorous teamwork , prioritize continuous excellence and growth, and deliver exceptional value as dedicated client partners.
Click on Apply to know more.