Associate Security Analyst, Agentic Security Operations

Google Google · Big Tech · TX +1

This role involves leveraging generative AI and AI-infused tools to enhance security defense workflows, moving beyond traditional alert verification to perform deep-dive investigations. The analyst will use AI assistants to translate threat hypotheses into detection queries, conduct forensic analysis with AI analytics, and utilize AI-driven tools for file analysis and automated response.

What you'd actually do

  1. Analyze real-time security events across endpoint, network, and cloud environments, integrate AI-infused alert summarization platforms to rapidly categorize and prioritize high-severity alerts.
  2. Leverage generative AI security assistants (such as Google Security Operations Gemini) to translate natural language threat hypotheses into advanced detection queries (YARA-L), accelerating threat hunting and triage.
  3. Conduct host and network forensic analysis to support incident response efforts, applying AI analytics to correlate disparate signals, understand attacker activity, and assess customer impact.
  4. Execute basic static and dynamic analysis of suspicious files, utilize AI-driven code explainers and de-obfuscation models to identify malicious capabilities rapidly (e.g., identifying GOOTLOADER JavaScript or CORNFLAKE.V3 backdoors).
  5. Isolate compromised hosts and stop lateral movement or ransomware propagation using both manual controls and AI-driven automated response playbooks.

Skills

Required

  • Bachelor's degree in Computer Science, a related technical field (e.g. Cyber Security, Information Technology) or equivalent practical experience.
  • Experience utilizing generative AI security assistants, security copilots, or AI-infused query builders to search Security Information and Event Management (SIEM) telemetry, summarize incidents, or accelerate analysis workflows.
  • Experience with Endpoint Detection and Response (EDR) tools (such as Crowdstrike Falcon or SentinelOne Singularity, specifically utilizing AI or heuristic modules), Network Detection and Response (NDR) and Next-Generation Firewall (NGFW) tools (such as Corelight, Palo Alto, Vectra, or Trellix NX), or SIEM platforms (such as Google Security Operations, Splunk, or QRadar).

Nice to have

  • 4 years of experience in a SOC environment, a specialized Information Security role.
  • Experience leading investigations/participating in response operations for high-severity events.
  • Proficiency with AI prompting techniques (prompt engineering) tailored for cyber security use cases, such as extracting indicators of compromise (IOCs) from unstructured threat reports or automating the generation of YARA-L/Sigma rules.
  • Proficiency in scripting with experience connecting to AI model APIs to parse data, automate repetitive tasks, or build tools.
  • Understanding of the risks associated with using Generative AI in security contexts, including data privacy/leakage concerns, model hallucination management, and prompt injection concepts.

What the JD emphasized

  • Experience utilizing generative AI security assistants, security copilots, or AI-infused query builders to search Security Information and Event Management (SIEM) telemetry, summarize incidents, or accelerate analysis workflows.
  • Proficiency with AI prompting techniques (prompt engineering) tailored for cyber security use cases, such as extracting indicators of compromise (IOCs) from unstructured threat reports or automating the generation of YARA-L/Sigma rules.
  • Understanding of the risks associated with using Generative AI in security contexts, including data privacy/leakage concerns, model hallucination management, and prompt injection concepts.

Other signals

  • Leverage generative AI security assistants
  • AI-infused alert summarization platforms
  • AI analytics to correlate disparate signals
  • AI-driven automated response playbooks