This posting is for a new vacancy.
Google utilizes AI tools to assist in assessing candidates in our hiring processes.
Note: By applying to this position you will have an opportunity to share your preferred working location from the following:
Toronto, ON, Canada; Ottawa, ON, Canada; Montreal, QC, Canada.
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, related technical field, or equivalent practical experience.
- 5 years of experience in detection engineering, SIEM/SOAR administration, or Security Operations Centre (SOC) operations.
- Experience developing detections, automated response playbooks, and custom scripts (e.g., Python, Bash).
- Experience with AI-augmented SOC workflows, agentic security, or using LLMs to automate security operations.
- Experience integrating distributed systems via Cloud APIs or REST.
- Ability to travel up to 30% of the time. as needed.
- Experience engineering and deploying detection and response content within modern SIEM solutions (e.g., SecOps, Elastic, Sentinel, Splunk, Cortex XSIAM).
- Experience building MCP servers and seamlessly integrating complex distributed systems via Cloud APIs.
- Experience with Python engineering and designing multi-agent systems, RAG pipelines, and LLM tool-calling.
- Experience in client-facing consulting and communication.
- Familiarity with AI evaluation frameworks, production guardrails, and Google Cloud’s AI ecosystem.
- Background in cybersecurity operations (SOC, Incident Response, or Detection Engineering) utilizing SIEM and SOAR platforms.
As a Security Consultant, you will be responsible for helping clients effectively prepare for, proactively mitigate, and detect and respond to cyber security threats. Security Consultants have an understanding of computer science, operating system functionality and networking, cloud services, corporate network environments and how to apply this knowledge to cyber security threats.
As a Security Consultant, you could work on engagements including assisting clients in navigating technically complex and high-profile incidents, performing forensic analysis, threat hunting, and malware triage. You may also test client networks, applications and devices by emulating the latest techniques to help them defend against threats, and will be the technical advocate for information security requirements and provide an in-depth understanding of the information security domain. You will also articulate and present complex concepts to business stakeholders, executive leadership, and technical contributors and successfully lead complex engagements alongside cross functional teams.
As a Senior Consultant, you will design and develop agentic capabilities within clients Security Operations Centers (SOCs). Collaborating with client developers and analysts, you will translate security operations workflows into reliable AI-augmented systems, implementing agentic capabilities into client environments.This role is designed for technical professionals focused on emerging technologies and protecting clients from cybersecurity risks.
Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.
Canada: $166000 - $170000 (CAD) + 15% bonus target + equity + benefits
Learn more about benefits at Google.
- Analyze customer Security Operations performance and workflows to identify operational issues and areas that could be measurably improved through the implementation of technology.
- Propose innovative AI and automation strategies that optimize overall defense capabilities. Develop robust internal AI solutions, prompt pipelines, and MCP connectors to seamlessly integrate intelligent agents with core enterprise security platforms including SIEM and SOAR solutions.
- Design, build, and maintain an internal library of agentic solutions and reusable skills that transform manual security operations into efficient, automated and semi-automated workflows.
- Design and integrate AI-augmented detection use case life-cycles, agentic response playbooks, and machine-speed threat hunting procedures.
- Operationalize advanced Security Orchestration, Automation, and Response (SOAR) capabilities, including the integration of connectors for automated case management.
Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Google's EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our Accommodations for Applicants form.