Security Platform Engineer
Job Summary
Job Description Security Platform Engineer (Google SecOps & BindPlane)
Role Overview
The Security Platform Engineer is responsible for operating maintaining and enhancing the organisations security telemetry and analytics platforms with a strong focus on Google SecOps (SIEM/SOAR) and BindPlane. This role ensures reliable telemetry ingestion platform stability and seamless data delivery to support detection engineering incident response threat hunting and broader security operations.
The ideal candidate brings deep technical hands-on experience with security platforms data ingestion pipelines cloud infrastructure and automation tooling. They will collaborate closely with the SOC incident response cloud and security engineering teams to ensure high-quality scalable and resilient security data pipelines and platforms.
Key Responsibilities
Google SecOps SIEM & SOAR Operations
- Configure administer and maintain Google SecOps SIEM and SOAR environments including tenancy setup access controls roles and permissions.
- Operate and ensure ongoing health performance availability and capacity of SIEM and SOAR platforms.
- Implement platform configuration changes upgrades and feature enhancements.
- Troubleshoot and resolve issues related to platform stability integrations and data ingestion.
- Support detection enablement platform access requests and incident-related data queries.
Telemetry Ingestion & BindPlane Engineering
- Configure manage and maintain BindPlane collectors agents and data ingestion pipelines.
- Oversee log and telemetry ingestion from cloud services infrastructure applications and security tools.
- Design and maintain parsing normalisation enrichment routing and delivery pipelines.
- Route telemetry to Google SecOps SIEM BigQuery and other downstream platforms.
- Monitor BindPlane throughput latency error rates data loss and pipeline health.
- Troubleshoot ingestion failures parsing errors schema mismatches and performance bottlenecks.
Data Architecture Quality & Reliability
- Design and implement scalable resilient and cost-optimised telemetry ingestion architectures.
- Validate data quality schema consistency field mapping and delivery guarantees to support detection and analytics use cases.
- Maintain architecture diagrams pipeline documentation operational runbooks and knowledge base content.
Automation & CI/CD
- Deploy platform and pipeline updates via CI/CD pipelines.
- Read and modify Python and Terraform code used within CI/CD workflows for minor fixes or enhancements.
- Integrate platform management tasks into automated deployment and validation processes.
Incident & Operational Support
- Provide platform-level support during security incidents and investigations ensuring data availability integrity and timely access.
- Assist SOC and incident response teams with telemetry validation platform troubleshooting and detection enablement.
- Collaborate with cloud engineering infrastructure DevOps and security teams to improve reliability and operational maturity.
Required Skills & Experience
- Hands-on experience with Google SecOps SIEM/SOAR platforms.
- Expertise in BindPlane or similar telemetry ingestion technologies.
- Strong understanding of log formats schemas parsing enrichment and data routing.
- Familiarity with cloud environments (e.g. Google Cloud Platform AWS Azure).
- Experience troubleshooting data ingestion pipelines and performance issues.
- Ability to read and modify basic Python and Terraform code.
- Experience with CI/CD pipelines and automated deployments.
- Strong incident support and cross-team collaboration skills.
Preferred Qualifications
- Experience with BigQuery or other cloud-based analytics platforms.
- Understanding of detection engineering concepts and operational security telemetry requirements.
- Background in SOC operations cloud engineering or security engineering.
- Certifications such as Google Professional Cloud Security Engineer Google SecOps or equivalent (nice to have).