1

Soc Analyst Google Jobs in Delaware (NOW HIRING)

We are looking for a Threat Detection Engineer to analyze large-scale SaaS security data ... A background of at least 5 years in cybersecurity, preferably in SOC, SIEM, Threat Intelligence, or ...

Soc Analyst Google information

What does a SOC Analyst at Google do?

A SOC (Security Operations Center) Analyst at Google is responsible for monitoring, detecting, and responding to security threats across Google's systems and networks. They analyze security alerts, investigate incidents, and help protect the organization's sensitive data from cyber threats. In addition, SOC Analysts collaborate with other security teams to improve detection capabilities and mitigate vulnerabilities. Their work is critical to maintaining the security and integrity of Google's vast digital infrastructure.

What are the key skills and qualifications needed to thrive as a SOC Analyst at Google?

To thrive as a SOC Analyst at Google, you generally need a strong background in cybersecurity, knowledge of threat detection, and experience with incident response, often supported by a degree in computer science or a related field. Familiarity with SIEM tools (like Splunk or Chronicle), IDS/IPS systems, and relevant certifications such as CISSP or GIAC are typically required. Strong analytical thinking, attention to detail, and effective communication skills help SOC Analysts excel in dynamic security environments. These skills and qualifications are crucial for identifying, investigating, and mitigating security threats to protect Google’s complex infrastructure.

What are some common challenges that SOC Analysts at Google face in their daily work?

SOC Analysts at Google often encounter the challenge of sifting through large volumes of security alerts to identify genuine threats while minimizing false positives. The fast-paced environment requires them to stay updated on the latest threat intelligence and adapt quickly to new attack techniques. Collaboration with cross-functional teams, such as incident response and engineering, is essential for timely mitigation and continuous improvement of security processes. Managing stress and maintaining focus during high-priority incidents are also key aspects of the role.

What is the difference between Soc Analyst Google vs Security Operations Center (SOC) Analyst?

AspectSoc Analyst GoogleSecurity Operations Center (SOC) Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentIn-house at Google or remote, tech-focusedTypically in a security operations center, various industries
Employer & IndustryGoogle, tech and internet servicesVarious organizations, including finance, healthcare, tech
Job FocusMonitoring Google’s infrastructure and cloud securityMonitoring and responding to security incidents across organizations

Both roles involve monitoring security threats and require similar certifications. However, Soc Analyst Google focuses on Google’s infrastructure and cloud security, often in a tech environment, while a SOC Analyst generally works across multiple industries in a dedicated security operations center, handling broader security incident response.

Is Soc Analyst Google still in demand?

Soc Analysts at Google are in high demand due to the increasing need for cybersecurity and threat detection. These roles often require knowledge of security tools, incident response, and certifications like CISSP or CompTIA Security+ to stay competitive in the job market.

What are popular job titles related to Soc Analyst Google jobs in Delaware?

For Soc Analyst Google jobs in Delaware, the most frequently searched job titles are:

What cities in Delaware are hiring for Soc Analyst Google jobs?

Cities in Delaware with the most Soc Analyst Google job openings:

Security Researcher

Reco

Wilmington, DE • On-site, Remote

Full-time

Re-posted 17 days ago


Job description

Description
Reco is a fast-growing SaaS security company that helps organizations secure their SaaS and AI environments by detecting identity-based threats and risky configurations.
We are looking for a Threat Detection Engineer to analyze large-scale SaaS security data, investigate incidents, and develop advanced threat detection strategies.
You will work closely with security researchers and customers to identify emerging threats and improve detection capabilities across SaaS environments.
Responsibilities
  • Threat Analysis and Research: Dive deep into terabytes of SaaS Application data to identify new attack vectors, emerging threats, and vulnerabilities across various attack surfaces.
  • Stay up-to-date with the latest cybersecurity trends and contribute to the development of cutting-edge threat detection methodologies.
  • Incident Investigation: Utilize your technical prowess to investigate complex SaaS & AI security incidents, analyzing data from diverse SaaS applications to uncover the root causes and methods of attack.
  • False Positive Reduction: Leverage your expertise in data analysis and correlation to fine-tune detection rules and algorithms, minimizing false positives and enhancing the accuracy of our platform's threat alerts.
  • Thought Leadership and Community Engagement: Drive thought leadership initiatives by creating technical blog posts, delivering webinars, and speaking at conferences to share insights, educate the community, and enhance the company's reputation in the cybersecurity landscape.
  • Be at the forefront of the Reco mission and work closely with Reco customers regarding cyber security investigations and incidents detected in their environments
  • Collaborate with security researchers and data scientists to define new threat detection strategies based on SaaS attack vectors and industry trends.
  • Continuously monitor and analyze SaaS attack techniques, adapting security posture to evolving threats.
  • Work with APIs and integrations to ingest security logs from various SaaS platforms, correlating signals to detect real threats.

Requirements
  • A background of at least 5 years in cybersecurity, preferably in SOC, SIEM, Threat Intelligence, or Cloud Security
  • Experience with SaaS security challenges, such as shadow IT, OAuth risks, IDP misconfigurations, and excessive permissions.
  • Hands-on experience with security data analysis, including large-scale log processing, anomaly detection, and behavioral analytics.
  • Proficiency in SQL (e.g., ClickHouse) for querying security events and correlating threat indicators.
  • Strong understanding of identity-based attacks, insider threats, and SOC detection methodologies.
  • Familiarity with SIEM and XDR solutions (e.g., Splunk, Sentinel, Chronicle) and their role in modern detection engineering.
  • Strong problem-solving and analytical skills to triage security incidents and optimize detection rules.

Advantages:
  • Familiarity with SaaS security best practices, including least-privilege access, OAuth governance, and SSPM.
  • Knowledge of SaaS security frameworks (e.g., SSPM, CASB).
  • Experience with IDP security (Okta, Azure AD, Google IAM) and detecting identity-related SaaS threats.
  • Hands-on experience with Threat Hunting and / or Detection engineering in SaaS environments.
  • Understanding of SaaS API security and experience analyzing integrations with third-party applications.