Google Chronicle Developer - Remote
Google Chronicle Developer - Remote

Google Chronicle Developer - Remote

Full-Time 48000 - 72000 £ / year (est.) No home office possible
F

At a Glance

  • Tasks: Develop and optimise Google Chronicle for security monitoring and threat detection.
  • Company: FDM is a leading global consultancy, empowering the innovators of tomorrow.
  • Benefits: Enjoy remote work, career coaching, annual leave, and a workplace pension.
  • Why this job: Join a dynamic team, make an impact in security, and grow your skills.
  • Qualifications: 4+ years in Google Chronicle development; expertise in YARA-L and EQL required.
  • Other info: Mentorship opportunities and potential for international assignments.

The predicted salary is between 48000 - 72000 £ per year.

FDM is a global business and technology consultancy seeking a Senior Google Chronicle Developer to work for our client within the health sector. This is initially a 6-month contract with the potential to extend and will be a fully remote role.

Our client is seeking a Senior Google Chronicle Developer, who will be instrumental in building, managing, and optimising their Chronicle-based security monitoring and threat detection ecosystem. You will work closely with Security Operations (SecOps), DevOps, and Data Engineering teams to ensure they have reliable data ingestion, robust detection logic, and automated response playbooks that surface actionable insights and drive rapid incident response.

Responsibilities

  • Design, develop, and maintain Chronicle detections and playbooks across IT, application, and security domains, using YARA-L, EQL, and Chronicle Policy Engine.
  • Onboard new data sources into Chronicle via forwarders (e.g., Chronicle Data Forwarder, Fluentd/Fluent Bit), APIs, and custom parsers.
  • Build and optimise UDM pipelines (parsers & normalization)—create custom parsing rules, JSON or regex-based Normalized Event configurations, and ensure new log sources conform to the common schema.
  • Develop scheduled hunts and automated workflows in Chronicle for threat hunting (e.g., abnormal DNS tunneling, lateral movement). Leverage EQL for complex queries and scheduled scans.
  • Collaborate with SecOps and DevOps to integrate Chronicle alerts with SOAR platforms (e.g., Phantom, Demisto), enabling automated enrichment (TI, asset data) and response actions. Author playbooks that, for example, isolate compromised endpoints, block IPs, or escalate to ticketing systems.
  • Drive improvements in log standardization and detection rule hygiene—audit existing YARA-L rules, tune conditions to reduce false positives/negatives, and retire stale detections.
  • Act as Chronicle SME for architecture reviews, capacity planning, licensing, and best practices and advise on Chronicle’s ingestion pipeline scaling (back-pressure, sharding), health monitoring, and performance metrics (ingest latency, query response times).
  • Participate in incident investigations and postmortems, providing insights via Chronicle query analysis and retrospectives. Identify detection gaps and propose new rule or playbook enhancements.
  • Mentor junior Chronicle engineers and analysts—lead brown-bag sessions on writing EQL hunts, building YARA-L rules, or configuring UDM transformations.

Requirements

  • Minimum of 4+ years’ hands-on experience with Google Chronicle (or equivalent SIEM/SecOps) development and administration.
  • Expertise in Chronicle detection languages: YARA-L (rule authoring, tuning), EQL-style queries, and Chronicle Policy Engine.
  • Solid experience onboarding data via Chronicle Data Forwarder, Fluentd/Fluent Bit, syslog, and RESTful APIs. Comfortable building custom parsing pipelines and mapping to UDM.
  • Deep understanding of Chronicle’s UDM schema—ability to create or extend Normalized Events, parse nested JSON, extract fields via JSONPath/regex.
  • Proficiency integrating Chronicle with SOAR platforms (e.g., Phantom, Demisto) via webhooks or Cloud Pub/Sub. Able to automate threat-intel enrichment, host quarantines, and ticket creation.
  • Hands-on with GCP services (Pub/Sub, Cloud Functions, BigQuery) and cloud-native logging (Stackdriver/Cloud Logging, AWS CloudWatch). Comfortable with containerized deployments (Kubernetes, Docker).
  • Strong foundation in security operations—familiarity with threat intelligence feeds, MITRE ATT&CK, and intrusion detection concepts. Able to translate raw logs into actionable detections.
  • Experience using Git, CI/CD pipelines (e.g., Cloud Build, Jenkins) to manage Chronicle rule repositories, automated testing of YARA-L against staging data, and staged rollouts.

Why join us

  • Career coaching, mentoring and access to upskilling throughout your entire FDM career.
  • Assignments with global companies and opportunities to work abroad.
  • Opportunity to re-skill and up-skill into new areas, develop non-linear career paths and build a skillset within your field.
  • Annual leave, work-place pension and BAYE share scheme.

About FDM

We are a business and technology consultancy and one of the UK's leading employers, recruiting the brightest talent to become the innovators of tomorrow. We have centres across Europe, North America and Asia-Pacific, and a global workforce of over 3,500 Consultants. FDM has shown exponential growth throughout the years, firmly establishing itself as an award-winning employer and is listed on the FTSE4Good Index.

Diversity and Inclusion

FDM Group is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, national origin, age, disability, veteran status or any other status protected by federal, provincial or local laws.

Google Chronicle Developer - Remote employer: FDM Group

FDM is an exceptional employer that prioritises employee growth and development, offering comprehensive career coaching and mentoring to help you thrive in your role as a Senior Google Chronicle Developer. With a fully remote work environment, you will have the flexibility to collaborate with global teams while enjoying competitive benefits such as annual leave, a workplace pension, and opportunities for upskilling in a dynamic and inclusive culture.
F

Contact Detail:

FDM Group Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Google Chronicle Developer - Remote

✨Tip Number 1

Familiarise yourself with Google Chronicle's detection languages, especially YARA-L and EQL. Being able to demonstrate your expertise in these areas during discussions can set you apart from other candidates.

✨Tip Number 2

Engage with the community around Google Chronicle and related technologies. Join forums, attend webinars, or participate in relevant online groups to network and learn from others in the field.

✨Tip Number 3

Prepare to discuss your experience with integrating Chronicle with SOAR platforms. Be ready to share specific examples of how you've automated threat intelligence enrichment or incident response actions in past roles.

✨Tip Number 4

Showcase your understanding of security operations concepts, such as MITRE ATT&CK and intrusion detection. Being able to relate these concepts to your work with Chronicle will demonstrate your depth of knowledge and relevance to the role.

We think you need these skills to ace Google Chronicle Developer - Remote

Google Chronicle Development
YARA-L Rule Authoring
EQL Query Proficiency
Chronicle Policy Engine Expertise
Data Onboarding via Chronicle Data Forwarder
Fluentd/Fluent Bit Integration
Custom Parsing Pipelines Creation
Understanding of UDM Schema
JSONPath and Regex Field Extraction
SOAR Platform Integration (e.g., Phantom, Demisto)
Automation of Threat-Intel Enrichment
GCP Services (Pub/Sub, Cloud Functions, BigQuery)
Cloud-Native Logging Experience
Containerized Deployments (Kubernetes, Docker)
Security Operations Knowledge
Threat Intelligence Feeds Familiarity
MITRE ATT&CK Framework Understanding
Git Version Control
CI/CD Pipeline Management
Automated Testing of YARA-L Rules

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights your experience with Google Chronicle and relevant technologies. Focus on specific projects where you've designed detections, onboarded data sources, or collaborated with SecOps and DevOps teams.

Craft a Compelling Cover Letter: In your cover letter, express your passion for security monitoring and threat detection. Mention how your skills align with the responsibilities listed in the job description, such as your expertise in YARA-L and EQL.

Showcase Relevant Projects: Include examples of past projects that demonstrate your ability to build and optimise detection logic and automated workflows. Highlight any experience you have with SOAR platforms and cloud services like GCP.

Highlight Continuous Learning: Mention any recent training or certifications related to Google Chronicle or security operations. This shows your commitment to staying updated in the field and can set you apart from other candidates.

How to prepare for a job interview at FDM Group

✨Showcase Your Technical Skills

Be prepared to discuss your hands-on experience with Google Chronicle and related technologies. Highlight specific projects where you've designed detections or developed playbooks, and be ready to explain the technical details behind your work.

✨Understand the Ecosystem

Familiarise yourself with the broader security operations landscape, including how Chronicle integrates with SOAR platforms. Be ready to discuss how you would approach onboarding new data sources and optimising detection logic.

✨Prepare for Scenario-Based Questions

Expect questions that assess your problem-solving skills in real-world scenarios. Think about past incidents you've handled and how you used Chronicle to drive incident response or improve detection capabilities.

✨Demonstrate Collaboration Skills

Since the role involves working closely with SecOps and DevOps teams, be prepared to discuss your experience collaborating with cross-functional teams. Share examples of how you've mentored others or led knowledge-sharing sessions.

Google Chronicle Developer - Remote
FDM Group
F
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>