Job Description
The Consulting business at KPMG Global Services (KGS) is a diverse team of more than 6400 professionals. We work with KPMG Firms worldwide to transform the businesses of clients across industries through the latest technology and innovation. Our technology professionals combine deep industry knowledge with strong technical experience to navigate through complex challenges and deliver real value for our clients.
Through your work, you’ll build a global network and unlock opportunities that you may not have thought possible with access to great support, vast resources, and an inclusive, supportive environment to help you reach your full potential.
•Core Delivery
•Build, tune, and maintain YARA-L detection rules (multi-event correlation, time windows, severity mapping, ATT&CK tagging, entity enrichment).
•Design and implementation of enterprise security architecture with a focus on Google SecOps (Chronicle SIEM and SOAR), aligned to business and IT strategies.
•Design, configure, and maintain Chronicle across hybrid environments; ensure complete and accurate log collection via forwarders, Pub/Sub, Ingestion API, and vendor connectors.
•Create alerting, dashboards, and investigation workflows; leverage UDM Search, entities (user/asset/IP/domain), and investigation timelines to drive effective incident triage and response.
•Integrate Security Command Center (SCC) sources (Security Health Analytics, Event Threat Detection, Web Security Scanner) and findings into SecOps workflows; configure muting, notifiers, and routing.
•Conduct regular tool health checks, troubleshooting of ingestion pipelines and parsers, and data quality/coverage validation.
•Analysis & Reporting
•Perform security incident triage, investigation, containment, eradication, and recovery leveraging UDM Search, investigation timelines, and entity pivots (user, asset, IP, domain).
•Produce investigation reports, executive summaries, RCA, and measurable recommendations; map incidents and detections to MITRE ATT&CK.
•Ensure security solutions and processes meet regulatory and compliance requirements; support evidence collection and audit readiness (SOPs, CMAs, playbooks).
•Operations & Engineering Support
•Onboard and normalize data sources (Cloud Audit Logs, VPC Flow, Cloud DNS, GKE/container logs, Google Workspace audit logs, EDR/identity/network sources) with UDM field mapping
•Engineer and operationalize Google SOAR playbooks and cases for automated response.
•Standardize content-as-code practices (Git-based workflows, review/approval, promotion between environments) for rules, parsers, and playbooks.
•Client & Stakeholder Engagement
•Provide regular briefings to executives and technical teams; collaborate across global IR/SOC, architecture, and compliance stakeholders.
•Deliver knowledge transfer, playbook/runbook documentation, and enablement for SOC analysts and engineers
•Extended Responsibilities:
•Conduct tabletop exercises/purple-team validations to assess coverage and playbook efficacy; drive measurable improvements in MTTD/MTTR.
•Support sensitive data exposure assessments and CI/CD pipeline guardrails where relevant to SecOps telemetry and response.
Educational qualifications
•Bachelor’s degree in Computer Science / Cyber Security / IT or related field
•Relevant certifications (preferred): Google Professional Cloud Security Engineer; Google Security Operations/Chronicle training
Work experience
•5-7 years of experience in:
•Incident Response / SOC / Threat Hunting / SIEM Engineering / Cloud Architecture
•Experience in global client engagements (US/UK/Europe) preferred.
Mandatory technical & functional skills
•Strong understanding of:
•Enterprise security architecture and its alignment to business and IT strategies.
•Incident Response lifecycle and SOC workflows
•MITRE ATT&CK mapping for detections, hunts, and reporting.
•Hands-on experience in:
•SIEM tools (Google SecOps)
•EDR tools (Microsoft Defender, SentinelOne, CrowdStrike - exposure)
•Knowledge of:
•SIEM Engineering/YARA-L concepts, SOC/SOAR
•SCC concepts and integration patterns into SecOps workflows.
•Strong:
•Analytical and problem-solving skills
•Technical report writing and documentation skills
•Communication and stakeholder engagement skills
Preferred technical & functional skills
•Exposure to:
•Threat intelligence integration/enrichment (STIX/TAXII, MISP, VirusTotal, commercial feeds) and IOC lifecycle management.
•EDR/identity/network telemetry
•Cloud Security Controls
•Familiarity with:
•Content-as-code, CI/CD for detections/parsers/playbooks; API-driven configuration management.
•Experience in:
•Threat hunting and hypothesis-driven analysis using Chronicle UDM Search and entity pivots.