Principal Threat Intelligence Analyst - Google Australia (Sydney / Melbourne / Remote)

IT

Principal Threat Intelligence Analyst - Google Australia (GTIG)

Google is hiring a highly experienced Principal Threat Intelligence Analyst to join the Cyber Threat Coordination Center (CTCC) within the Google Threat Intelligence Group (GTIG) in Australia. This role offers hybrid and remote-eligible options across major Australian locations including Sydney, Melbourne, NSW, VIC, QLD, and SA.

📋 Quick Job Overview

  • Employer: Google (Mandiant / Google Cloud)
  • Location: Sydney NSW / Melbourne VIC / Remote Eligible (Australia)
  • Role: Principal Threat Intelligence Analyst
  • Work Type: Full-Time (Hybrid / Remote)
  • Category: IT & Cybersecurity / Threat Intelligence
  • Experience Level: Senior (7+ Years Required)

✨ Role Highlights & About the Team

Part of Google Cloud, Mandiant is a global leader in cyber defense, threat intelligence, and incident response. In this leadership role, you will operate as an incident commander orchestrating immediate, organized responses to critical cybersecurity events and nation-state level threat campaigns.

🎯 Key Responsibilities

  • Lead ad-hoc technical teams to coordinate the overall response to major threat actor operations.
  • Rapidly analyze emerging threat activity to assess scope, severity, and potential business impact.
  • Manage the publication of rapid-release threat intelligence, including customer reports and public-facing technical blogs.
  • Serve as a trusted advisor to executive leadership by translating complex technical risks into strategic briefings.
  • Provide mentorship and technical guidance to threat analysts within GTIG and the broader organization.

📋 Requirements & Qualifications

  • Education: Bachelor's degree or equivalent practical experience.
  • Experience: Minimum 7 years of experience in cyber threat intelligence or incident response (DFIR).
  • Technical Expertise: Proven background in Digital Forensics, malware research, and vulnerability exploitation analysis.
  • Preferred Skills: Experience with SIEM, SecOps, detection engineering, LLM-based automation workflows, and public intelligence reporting.