On the Threat Analyst Team, you execute established threat hunts, write and tune detection logic, assist with clients utilizing Google Threat Intelligence, support active incidents, and serve as an ...
Quick apply
On the Threat Analyst Team, you execute established threat hunts, write and tune detection logic, assist with clients utilizing Google Threat Intelligence, support active incidents, and serve as an ...
Quick apply
On the Threat Analyst Team, you execute established threat hunts, write and tune detection logic, assist with clients utilizing Google Threat Intelligence, support active incidents, and serve as an ...
Southern Md Facility, MD · On-site
... analysis in an enterprise environment. * Experience applying Cyber Threat Intelligence (CTI ... About the job In your capacity as a Security Analyst within the Google Threat Intelligence Group ...
Southern Md Facility, MD · On-site
... analysis in an enterprise environment. * Experience applying Cyber Threat Intelligence (CTI ... About the job In your capacity as a Security Analyst within the Google Threat Intelligence Group ...
Washington, DC · On-site
Hands-on experience with cloud threat analysis (AWS, Azure, Google Cloud Platform) and container security. * Ability to lead advanced threat hunting campaigns and mentor junior analysts.
Washington, DC · On-site
Hands-on experience with cloud threat analysis (AWS, Azure, Google Cloud Platform) and container security. * Ability to lead advanced threat hunting campaigns and mentor junior analysts.
Annapolis, MD · On-site
$132K - $200K/yr
Working within a collaborative threat analysis team, analysts leverage intelligence reporting ... group medical plan, company paid dental, vision, life insurance, and STD/LTD plans. Salary is ...
Annapolis, MD · On-site
$132K - $200K/yr
Working within a collaborative threat analysis team, analysts leverage intelligence reporting ... group medical plan, company paid dental, vision, life insurance, and STD/LTD plans. Salary is ...
Working within a collaborative threat analysis team, analysts leverage intelligence reporting ... group medical plan, company paid dental, vision, life insurance, and STD/LTD plans. Salary is ...
Working within a collaborative threat analysis team, analysts leverage intelligence reporting ... group medical plan, company paid dental, vision, life insurance, and STD/LTD plans. Salary is ...
Experience may also include multi-source or technical threat analysis (e.g., SIGINT, ELINT, FISINT ... Group Term Life, Short-Term and Long-Term Disability is provided by Sentar to all qualifying ...
Experience may also include multi-source or technical threat analysis (e.g., SIGINT, ELINT, FISINT ... Group Term Life, Short-Term and Long-Term Disability is provided by Sentar to all qualifying ...
Experience may also include multi-source or technical threat analysis (e.g., SIGINT, ELINT, FISINT ... Group Term Life, Short-Term and Long-Term Disability is provided by Sentar to all qualifying ...
Experience may also include multi-source or technical threat analysis (e.g., SIGINT, ELINT, FISINT ... Group Term Life, Short-Term and Long-Term Disability is provided by Sentar to all qualifying ...
Experience in the analysis of CTI, supporting monitoring, detection, and response capabilities ... Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence ...
Experience in the analysis of CTI, supporting monitoring, detection, and response capabilities ... Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence ...
Miami, FL · On-site
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Miami, FL · On-site
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Nashville, TN · On-site
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Nashville, TN · On-site
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Tampa, FL · On-site
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Tampa, FL · On-site
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Las Vegas, NV · On-site
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Las Vegas, NV · On-site
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Chicago, IL · On-site
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Chicago, IL · On-site
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
$102K - $132K/yr
Experience with Microsoft Threat Intelligence and Google Threat Intelligence (Previously Mandiant ... Conduct in-depth analysis of security logs, network traffic, and endpoint data to identify ...
$102K - $132K/yr
Experience with Microsoft Threat Intelligence and Google Threat Intelligence (Previously Mandiant ... Conduct in-depth analysis of security logs, network traffic, and endpoint data to identify ...
Atlanta, GA · On-site
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Atlanta, GA · On-site
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
San Diego, CA · On-site
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
San Diego, CA · On-site
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Hartford, CT · On-site
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Hartford, CT · On-site
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Denver, CO · On-site
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Denver, CO · On-site
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Richmond, VA · On-site
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Richmond, VA · On-site
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
$34K - $46.9K
4% of jobs
$46.9K - $59.8K
0% of jobs
$59.8K - $72.7K
4% of jobs
$72.7K - $85.6K
7% of jobs
$96.2K is the 25th percentile. Wages below this are outliers.
$85.6K - $98.5K
11% of jobs
$98.5K - $111.5K
5% of jobs
The median wage is $116.7K / yr.
$111.5K - $124.4K
44% of jobs
$124.4K - $137.3K
10% of jobs
$137.3K - $150.2K
11% of jobs
$150.2K - $163.1K
2% of jobs
$163.1K - $176K
0% of jobs
$34K
$112.9K
$176K
A Google Threat Analysis Group (TAG) job involves identifying, tracking, and countering cyber threats that target Google, its users, and the broader internet. TAG analysts research advanced persistent threats (APTs), disinformation campaigns, and other malicious activities from state-sponsored actors and cybercriminals. They collaborate with internal security teams and external organizations to enhance digital security. The role requires expertise in cybersecurity, threat intelligence, and incident response.
A typical workday for a member of the Google Threat Analysis Group involves monitoring for new and emerging security threats, analyzing malware and cyber-attack campaigns, and producing threat intelligence reports. Team members frequently collaborate with engineers, product managers, and other security specialists to respond to potential threats and strengthen defenses. Daily tasks often include conducting in-depth investigations, communicating findings internally, and sharing relevant intelligence with external partners as appropriate. The work is dynamic and high-impact, demanding agility and a proactive approach to rapidly changing threat landscapes.
To thrive in the Google Threat Analysis Group, you need expertise in cybersecurity, malware analysis, digital forensics, and possess a strong analytical mindset, often backed by a degree in computer science or related field. Familiarity with security information and event management (SIEM) tools, threat intelligence platforms, scripting languages, and relevant certifications such as CISSP or GIAC is highly valuable. Strong communication, collaboration, and problem-solving skills help you effectively share findings and work with cross-functional teams. These abilities are crucial for identifying, investigating, and mitigating evolving security threats that target Google's products and users.
Cities with the most Google Threat Analysis Group job openings:
The most popular types of Google Threat Analysis Group jobs are:
States with the most job openings for Google Threat Analysis Group jobs include:
The top searched job categories for Google Threat Analysis Group jobs are:

The Threat Analyst is an experienced security analyst moving into a specialist threat hunting role. This is not a junior position — candidates already have solid SOC fundamentals and can independently work complex alerts. On the Threat Analyst Team, you execute established threat hunts, write and tune detection logic, assist with clients utilizing Google Threat Intelligence, support active incidents, and serve as an escalation point above the standard analyst line.
What you'll do:
Execute threat hunts: Execute established threat hunts across client environments, applying IOCs and TTPs supplied by senior staff and derived from threat intelligence.
Write & tune detection logic: Write and tune log-source-specific threat hunting and detection queries in YARA-L 2.0, extending and modifying existing queries to improve coverage.
Act as an escalation point: Serve as an escalation point for SOC analysts, taking on complex, anomalous, or ambiguous alerts that exceed standard triage.
Support incident response: Provide threat hunting support during active incidents and contribute findings directly to incident response and incident command.
Drive detection enrichment: Enrich detections and investigations using Google Threat Intelligence and threat reports, while identifying process gaps and recommending improvements to reduce workload and improve response times.
Support specialized engagements: Assist senior analysts with insider threat investigations and support the implementation and operation of dark web monitoring capabilities for enterprise clients using Google Threat Intelligence.
Document & report findings: Document hunt results, detections, and lessons learned for client and internal operational use.
Who you are:
Experience: Experience equivalent to a Tier 2 SOC analyst, backed by solid incident response fundamentals and strong log analysis across endpoint, network, identity, and cloud telemetry.
Knowledge of Security Frameworks: Working knowledge of MITRE ATT&CK, Cyber Kill Chain, and the Diamond Model frameworks.
Detection & Query Capabilities: Working knowledge of TTPs and the ability to write queries to identify them based on threat intelligence reports, with the aptitude to become proficient in YARA-L 2.0 quickly.
Strong Communication: Strong written documentation and communication skills for detailing complex hunt findings and client deliverables.
Certifications: Relevant industry certifications (e.g., Security+, CySA+, PenTest+, SecurityX, GIAC, PJPT, PNPT, OSCP, or equivalent).
Nice to have:
Hands-on experience with Google SecOps (Chronicle) and Google Threat Intelligence.
Proficiency with at least 2 of the following EDR/XDR consoles:
SentinelOne
CrowdStrike
Microsoft Defender
Palo Alto Cortex
Cisco Secure Endpoint / AMP
Scripting ability (e.g., Python) for lightweight automation and data enrichment.
Why Join Foresite?
We are a mission-driven partner helping organizations navigate an increasingly complex threat landscape. Founded by security practitioners, we’ve grown into a global leader in SecOps and MDR by staying true to our core value: radical transparency. When you join Foresite, you are part of a "humans-first" culture where your expertise is valued, and your well-being is a priority. We leverage our Google Cloud Premier SecOps Partnership to stay at the cutting edge, but we know that our greatest asset is our people.
What we offer:
Comprehensive Health & Wellness: Robust medical insurance options to keep you and your family healthy.
Employer-Covered Insurance: We fully provide employer-paid Dental coverage, as well as Short-Term (STD) and Long-Term Disability (LTD).
Recharge & Refuel: We believe in a true work-life balance. You’ll start with 3 weeks of paid vacation, plus additional sick leave and paid company holidays to ensure you have time to recharge.
Growth & Mentorship: Access to world-class training and mentorship. We support your career trajectory, whether you’re looking to deepen your technical skills or move into leadership.
Impactful Work: Help protect global clients using the latest AI-enhanced security tools and GCP native technologies.