Google

Senior Security Engineer, Exploits, Google Threat Intelligence Group

Google · Zurich, Zurich, Switzerland

Software Development · 10,001+ employees

4 h ago
Senior (5-10 yrs) Full-time Switzerland
Log in to apply, save this posting, or score it against your profile with AI.

About the role

Lead complex technical analyses of threat activity and develop detection signatures to protect users from targeted exploitation. Collaborate with cross-functional teams to design exploit mitigations and produce actionable intelligence documentation.

What they look for

Threat Intelligence Intrusion Analysis Vulnerability Research Malware Analysis Reverse Engineering Python GoogleSQL Android Security Chrome Security TTPs SIEM VirusTotal Exploit Mitigation Project Leadership Technical Documentation

Requirements

Requires a bachelor's degree in Computer Science or a related field and at least 5 years of experience in threat intelligence or vulnerability research. Candidates should possess deep knowledge of attacker TTPs and proficiency in scripting or querying languages.

Full description

Minimum qualifications:

  • Bachelor's degree in Computer Science, Cybersecurity, a related field, or equivalent practical experience.
  • 5 years of experience in threat intelligence, intrusion analysis, vulnerability researcher, or a similar security role.
  • Experience with threat intelligence platforms and tools (e.g., VirusTotal, SIEMs).

Preferred qualifications:

  • Knowledge of Android and Chrome security and internals.
  • Deep understanding of attacker Tactics, Techniques, and Procedures (TTPs).
  • Proven ability to lead complex threat research projects independently.
  • Strong analytical, problem-solving, and communication skills.
  • Skills in malware analysis, reverse engineering, or vulnerability analysis.
  • Proficiency in scripting or querying languages (e.g., Python, GoogleSQL).

About the job:

Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

Join the Google Threat Intelligence Group's (GTIG) Exploits Mission. The Exploits Mission focuses on protecting users from targeted exploitation, primarily from government-backed attackers and Commercial Surveillance Vendors (CSVs), through the detection, analysis, and ultimate prevention of vulnerabilities and exploits, with a special focus on 0-day attacks.

We provide timely, actionable intelligence and coordinate with internal and external partners to fix critical vulnerabilities and secure user devices.

As a Security Engineer on our team, you will conduct in-depth research on threat groups, their Tactics, Techniques, and Procedures (TTPs), and the malware they employ. You'll utilize Google's powerful internal intelligence platforms, Nirvana and mGraph, to model threat activity and generate actionable insights. This role involves close collaboration with various teams across GTIG and Google to develop and implement effective countermeasures, contributing directly to threat disruption and enhancing our collective security posture. We are looking for engineers passionate about threat research who can lead projects and mentor others.

Responsibilities:

  • Lead complex technical analyses, modeling threat activity, TTPs, and Indicators of Compromise (IOCs) across internal platforms (mGraph, Nirvana).
  • Create and deploy detection signatures (autoqueries, Watchtower rules) to maintain visibility over threat actors and assist in closing security gaps.
  • Produce polished, high-quality technical intelligence documentation and actor profiles to deliver actionable insights to internal and external stakeholders.
  • Influence technical direction within your scope, mentor junior engineers, and collaborate with cross-functional Google teams to support threat disruption efforts. Collaborate with security engineers and product teams in designing innovative exploit mitigations.
  • Identify and execute opportunities for continuous improvement: analytic collection, process  optimization, and automation.