Important Disclaimer
This is an independent editorial guide about the incident-response and threat-intelligence career track associated with Mandiant. It is not affiliated with Mandiant or Google Cloud. Verify any current openings directly through Google Cloud's official careers site.
Who Mandiant Is
Mandiant is a cybersecurity company specializing in incident response, threat intelligence, and tracking advanced adversary groups. Google acquired Mandiant in 2022, and it now operates as part of Google Cloud Security. Mandiant remains one of the most recognized names in the industry for investigating major breaches and publishing widely cited research on threat-actor activity.
Ads
Roles Mandiant Hires For
Hiring spans a mix of frontline response, research, and advisory positions.
- Incident Response Consultant
- Threat Intelligence Analyst
- Red Team / Offensive Security Consultant
- Managed Defense Analyst — an ongoing, MDR-style monitoring role
- Security Consultant — advisory and assessment-focused work
Reported Salary by Role
Exact figures aren't publicly confirmed by the company; the ranges below are market estimates for comparable roles at major incident-response and security-consulting firms in Canada.
| Role | Estimated Salary (CAD) |
|---|---|
| Incident Response Consultant (entry-mid) | C$85,000 - C$120,000 |
| Threat Intelligence Analyst | C$90,000 - C$130,000 |
| Managed Defense Analyst | C$80,000 - C$115,000 |
| Senior Incident Response Consultant | C$130,000 - C$170,000 |
| Principal Consultant | C$160,000 - C$210,000+ |
Ads
What the Work Is Actually Like
Consulting-track roles here don't look like a typical in-house security job.
- Incident response consultants can be dispatched to active breaches at client organizations on short notice
- The work is project-based and can involve intense, high-pressure sprints during an active incident
- Threat intelligence analysts track and profile adversary groups and publish research findings
- Travel is a real, recurring part of consulting-track roles, more so than in a typical in-house security position
Skills and Background That Get You Hired
The bar reflects the seriousness of the work.
- Strong fundamentals in digital forensics and incident response (DFIR)
- Scripting and automation skills, with Python being the most common language requested
- Familiarity with major attacker frameworks, especially MITRE ATT&CK
- Prior SOC or security-consulting experience is a common path into these roles
- Clear written communication, since consultants deliver formal incident reports directly to clients
Certifications That Carry Weight Here
A few credentials show up consistently in DFIR and incident-response hiring.
- GIAC certifications, particularly GCIH, GCFA, and GNFA, are widely respected in DFIR-focused hiring
- CISSP for broader security credibility
- OSCP for candidates targeting offensive-track roles
How Google Cloud's Acquisition Changed Things
Since joining Google Cloud in 2022, Mandiant's threat intelligence and detection technology have been integrated into Google's broader security product line, including tools built around Google Security Operations. That means some current roles blend Mandiant's investigative expertise with Google Cloud's platform and scale — it's worth reading a job posting carefully to understand which specific team and product area an opening actually sits within.
How to Apply
Apply through the official channel and prepare for a technical process.
- Apply only through Google Cloud's official careers site
- Search specifically for Mandiant-branded teams within the broader listings
- Tailor your resume to DFIR and threat-intelligence keywords rather than generic security terms
- Prepare for technical, scenario-based interview questions grounded in real investigative situations
Avoiding Fake Mandiant Job Offers
No legitimate opening asks for payment at any stage. Verify any recruiter contact against an official google.com or mandiant.com domain before sharing personal information or documents.
Final Thoughts
Incident response and threat intelligence work in the Mandiant tradition is demanding, travel-heavy, and genuinely high-stakes, which is exactly why it commands strong pay and carries real prestige within the security field. A solid DFIR foundation, a GIAC certification or two, and demonstrated scripting ability give you a realistic shot at breaking into this track.