Administer, maintain, and optimize the Google Chronicle SIEM platform
Onboard and manage log sources from cloud, on‑prem, network, and application environments
Develop and fine‑tune Detection Rules (YARA‑L / UDM rules)
Conduct threat hunting activities and analyze large datasets using Google Chronicle search capabilities
Build custom parsers, dashboards, and investigative workbooks
Monitor SIEM platform performance, ingest pipelines, and data quality
Collaborate with SOC teams on incident detection, triage, and escalation
Integrate Chronicle with other GCP security services (SecOps, SCC, Event Threat Detection)
Implement automated workflows and playbooks (SOAR integrations if applicable)
Troubleshoot ingestion failures, parsing gaps, and connector issues
Prepare documentation for SIEM architecture, rule logic, and operational processes
Ensure alignment with security policies, regulatory compliance, and audit expectations