Lead SecOps Engineer - Cloud Sec Spec 3

Softthink Solutions Inc

Lead SecOps Engineer - Cloud Sec Spec 3

Washington, DC
Full Time
Paid
  • Responsibilities

    Lead SecOps Engineer (Cloud Sec Spec 3) Location: Washington, DC Work Authorization: US Citizen

    Role Summary

    The Lead SecOps Engineer serves as the senior technical lead responsible for designing, building, and operationalizing the SBA Google SecOps Enterprise Plus environment. This role oversees SIEM/SOAR architecture, data ingestion pipelines, threat‑intelligence integration, and ensures the platform meets FedRAMP High security and operational requirements.

    Roles & Responsibilities

    · Lead the design and implementation of the Google SecOps Enterprise Plus tenant.

    · Architect ingestion pipelines from Microsoft Sentinel, Entra ID, AWS GovCloud, and on‑premises log sources.

    · Validate parser coverage across 700+ supported log types.

    · Oversee deployment of curated detections, UEBA, and Gemini-assisted investigation workflows.

    · Direct integration of Zero Trust and IAM telemetry (Okta, Entra).

    · Ensure platform alignment with SBA insider‑threat and privileged‑access monitoring requirements.

    · Provide senior-level guidance across all phases: Initiate & Design, Build & Integrate, Detect & Tune, Operationalize & Transition.

    · Support runbook development, training, and transition to steady-state operations.

    Professional Experience Required

    · 10+ years of experience in cloud security engineering, SIEM/SOAR architecture, or enterprise security operations.

    · Extensive experience with Google SecOps, BigQuery UDM, and cloud-native security platforms.

    · Experience integrating multi-cloud telemetry (Azure, AWS, on-prem).

    · Experience leading enterprise-scale security modernization projects.

    Educational Qualification

    · Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or related field (Master’s preferred).

    Certifications

    · Industry certifications such as Google Cybersecurity Professional, CISSP, CCSP, GIAC, or equivalent.