Google Cloud Professional Security Engineer
A free, self-paced 13 module training curriculum for Google Cloud Professional Security Engineer, built for security engineers hardening Google Cloud environments. Completing every module issues a printable 13.0 contact hour certificate from TECHLEAD 187 LLC.
- 13 modules
- 13.0 contact hours
- 6 domains
- Self-paced
- Free to use
Domains covered
- Platform Operations: 2 modules
- Data Management: 2 modules
- Threat Hunting: 2 modules
- Detection Engineering: 2 modules
- Incident Response: 3 modules
- Observability: 2 modules
Module syllabus
- 1.1 Enhancing Detection & Response
Prioritizing telemetry sources including SCC, Google Security Operations (SecOps), Google Threat Intelligence (GTI), and Cloud IDS. Integrating and justifying tool choices to refine security architectures. - 1.2 Configuring Access
Configuring user and service account authentication and authorization for security tools. Managing IAM roles, audit logs, and setting up Workforce Identity Federation. - 2.1 Ingesting Logs for Security Tooling
Designing log ingestion pipelines. Configuring parsers and extensions, performing data normalization via UDM, and optimizing log storage and ingestion costs. - 2.2 Baseline and Entity Context
Establishing baselines of user, asset, and entity contexts. Integrating threat intelligence and matching event logs with entity context (aliasing). - 3.1 Hunting Across Environments
Formulating threat-hunting hypotheses. Querying big datasets utilizing Log Analytics, BigQuery, YARA-L, and identifying anomalous actor behaviors. - 3.2 Leveraging Threat Intelligence
Searching for Indicators of Compromise (IOCs). Analyzing threat scores and conducting retrohunts using rule engines and Global Threat Intelligence (GTI) feeds. - 4.1 Developing Detection Mechanisms
Writing and syntax validation of YARA-L detection rules. Implementing custom SCC detectors, risk score mappings, and relational entity context graphs. - 4.2 Tuning and Score Optimisation
Tuning detection rules to minimize noise. Designing risk scoring logic, applying logic rules to reduce false positives, and analyzing detector efficiency. - 5.1 Containment and Investigation
Executing incident containment steps, performing forensic investigation, isolating cloud services, and determining root cause vectors using SecOps SIEM. - 5.2 Building Automated Playbooks
Designing, implementing, and testing Google SecOps SOAR playbooks. Automating alert enrichment and configuring active responder action steps. - 5.3 Case Management Lifecycle
Managing case lifecycle stages, task queues, and user assignment. Implementing escalation flows and SOC service handoffs. - 6.1 Dashboards and Insights
Designing Looker Studio dashboard reports to visualize threat trends, SLA compliance, and operational analyst operational KPIs. - 6.2 Health Monitoring & Alerts
Setting up Cloud Monitoring ingestion status alerts. Implementing silent logging detection rules and parser pipeline error notifications.
What each module includes
An executive lesson briefing with five key concepts and official vendor documentation references, a scenario based knowledge check scored for mastery, an applied scenario evaluation, and supplemental verified videos plus official free hands on labs where available.
Start this curriculumOther curricula
Published by TECHLEAD 187 LLC. Training certificates evidence completed instruction and contact hours; they are not vendor certifications and do not by themselves satisfy technical compliance requirements. Not affiliated with or endorsed by Google, Amazon Web Services, Microsoft, ISC2, Anthropic, or any U.S. government agency.