Threat Analyst, Google Threat Intelligence Group
About the position Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities. Google's Threat Intelligence Group (GTIG) is looking for a threat intelligence analyst covering our Middle East APT mission. In this role, you will focus on serious threats to Google, our products, and our users which are consumed by hundreds of security and abuse teams across the company, all levels of leadership, and externally to the security research industry. Responsibilities • Identify, analyze, and document network signals, malware behaviors, and threat reports related to trends and developments in adversary tactics, techniques, and procedures (TTPs). • Provide clear, actionable, and structured intelligence to product and security teams, assist in ensuring corporate and production systems are safeguarded. • Own the analysis efforts of multiple threat actors, and serve as a subject matter expert on how those actors might impact Google and our users. Requirements • Bachelor's degree or equivalent practical experience. • 5 years of experience with security engineering, computer and network security and security protocols. • 5 years of coding experience in one or more general purpose languages. • 5 years of experience in a threat intelligence or a related analyst role. • 2 years of experience in detection engineering with YARA, Snort/Suricata, EDR rule creation. • Experience with networks, techniques for lateral machine movement, malware persistence mechanisms, covert channels, application security and user authentication, command and control techniques. Nice-to-haves • Experience in an incident response or security operations center. • Experience in Reverse Engineering. • Understanding of dynamic and static malware analysis. Apply tot his job