Google Cloud Professional Security Engineer

A free, self-paced 13 module training curriculum for Google Cloud Professional Security Engineer, built for security engineers hardening Google Cloud environments. Completing every module issues a printable 13.0 contact hour certificate from TECHLEAD 187 LLC.

Domains covered

Module syllabus

  1. 1.1 Enhancing Detection & Response
    Prioritizing telemetry sources including SCC, Google Security Operations (SecOps), Google Threat Intelligence (GTI), and Cloud IDS. Integrating and justifying tool choices to refine security architectures.
  2. 1.2 Configuring Access
    Configuring user and service account authentication and authorization for security tools. Managing IAM roles, audit logs, and setting up Workforce Identity Federation.
  3. 2.1 Ingesting Logs for Security Tooling
    Designing log ingestion pipelines. Configuring parsers and extensions, performing data normalization via UDM, and optimizing log storage and ingestion costs.
  4. 2.2 Baseline and Entity Context
    Establishing baselines of user, asset, and entity contexts. Integrating threat intelligence and matching event logs with entity context (aliasing).
  5. 3.1 Hunting Across Environments
    Formulating threat-hunting hypotheses. Querying big datasets utilizing Log Analytics, BigQuery, YARA-L, and identifying anomalous actor behaviors.
  6. 3.2 Leveraging Threat Intelligence
    Searching for Indicators of Compromise (IOCs). Analyzing threat scores and conducting retrohunts using rule engines and Global Threat Intelligence (GTI) feeds.
  7. 4.1 Developing Detection Mechanisms
    Writing and syntax validation of YARA-L detection rules. Implementing custom SCC detectors, risk score mappings, and relational entity context graphs.
  8. 4.2 Tuning and Score Optimisation
    Tuning detection rules to minimize noise. Designing risk scoring logic, applying logic rules to reduce false positives, and analyzing detector efficiency.
  9. 5.1 Containment and Investigation
    Executing incident containment steps, performing forensic investigation, isolating cloud services, and determining root cause vectors using SecOps SIEM.
  10. 5.2 Building Automated Playbooks
    Designing, implementing, and testing Google SecOps SOAR playbooks. Automating alert enrichment and configuring active responder action steps.
  11. 5.3 Case Management Lifecycle
    Managing case lifecycle stages, task queues, and user assignment. Implementing escalation flows and SOC service handoffs.
  12. 6.1 Dashboards and Insights
    Designing Looker Studio dashboard reports to visualize threat trends, SLA compliance, and operational analyst operational KPIs.
  13. 6.2 Health Monitoring & Alerts
    Setting up Cloud Monitoring ingestion status alerts. Implementing silent logging detection rules and parser pipeline error notifications.

What each module includes

An executive lesson briefing with five key concepts and official vendor documentation references, a scenario based knowledge check scored for mastery, an applied scenario evaluation, and supplemental verified videos plus official free hands on labs where available.

Start this curriculum

Other curricula

Published by TECHLEAD 187 LLC. Training certificates evidence completed instruction and contact hours; they are not vendor certifications and do not by themselves satisfy technical compliance requirements. Not affiliated with or endorsed by Google, Amazon Web Services, Microsoft, ISC2, Anthropic, or any U.S. government agency.