No official application deadline is posted. Google closes listings when positions are filled. Apply early.
What Mandiant Is Hiring For
Mandiant, part of Google Cloud since a $5.4B acquisition in 2022, runs incident response for some of the most consequential breaches in the world. This Senior Consultant role sits inside that unit.
Day-to-day, you will lead investigation workstreams, run host and network forensics, produce client-facing reports, and brief both technical teams and executive leadership on findings.
Travel requirements are real. Mandiant notes up to 30% travel is expected for on-site engagements at client locations when incidents demand it. The role is hybrid-eligible within Nigeria, with Lagos as the listed in-office location.
SEE ALSO: Moniepoint Is Hiring a Motion Designer - Remote, Nigeria
What You Need to Qualify
These are the minimum qualifications. Google lists:
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, a related technical field, or equivalent hands-on experience
- 5 years of end-to-end incident response investigations, analysis, and containment
- 5 years of investigative experience in at least one of: network forensics, malware triage, cloud forensics, or disk and memory forensics
- 5 years working in Linux or Unix environments
- Experience coding in Python
- Ability to travel up to 30%
What Puts You Ahead
- Cloud platform certifications (AWS, GCP, or Azure; Mandiant does not specify which)
- Participation in CTFs, Hack The Box, TryHackMe, OverTheWire, or similar platforms
- Proven ability to communicate investigation findings to legal counsel, executives, and non-technical clients
- Mentorship experience with junior consultants
Core Responsibilities
- Lead small incident response investigations and workstreams within larger engagements
- Perform host, network, and log-based forensic analysis
- Develop client reports drawing from forensic data, threat intelligence, and network telemetry
- Present technical findings clearly to both technical and non-technical audiences
- Stay current on TTPs of nation-state, financially motivated, and opportunistic threat actors
Compensation and Benefits
Google has not disclosed a salary figure for this role. Market rates for senior incident response consultants at major security firms in Nigeria vary considerably depending on employment structure.
It is not confirmed whether this position is salaried or structured as a consulting contract. Google’s equity and performance bonuses, if applicable to Nigeria-based hires at this level, have not been confirmed.
Health cover, travel expense policy, and additional benefits are not disclosed in the listing.
What Nigerian Applicants Should Know
This role is explicitly located in Lagos, Nigeria, in-office with remote eligibility within Nigeria. No third-country work authorization is required.
The 30% travel requirement means international engagements are likely. Confirm whether Google covers visa support and expedited processing for incident-driven travel.
Application Process
Google runs multi-stage hiring. For technical security roles at this seniority level, expect a recruiter screen, one or more technical interviews covering forensics and IR methodology, and a scenario-based assessment. The exact process for this role has not been published.
No closing deadline is listed. Apply early.
GizPulse Verdict
This posting is built for a mid-career security professional in Nigeria who already works in incident response, not someone transitioning into it. The five-year floor across IR, forensics, and Linux is not a flexible language. Mandiant means it.
The upside is genuine. Mandiant's caseload includes nation-state actors. If you want to work on the hardest incidents in the world and build a credible international reputation, few employers in this region match that access.
Standout tip: In your cover materials and interviews, speak in threat actor terms. Reference specific adversary groups, TTPs from MITRE ATT&CK, or attribution methodology. Mandiant evaluators respond to candidates who treat the adversary as the subject, not the malware.
