Senior Security Engineer, Trust and Safety Workspace
Google Singapore
Software Development · 10,001+ employees
About the role
You will drive the technical strategy for Workspace account security and lead vulnerability research to mitigate advanced threats. Additionally, you will design and build agentic systems to autonomously detect and analyze security incidents while mentoring junior engineers.
What they look for
Requirements
Candidates must have at least 5 years of experience in security engineering, threat modeling, and coding in general-purpose languages. A bachelor's degree or equivalent practical experience is required, with preference given to those holding a master's or PhD in a technical field.
Full description
Minimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 5 years of experience with security assessments or security design reviews or threat modeling.
- 5 years of experience with security engineering, computer and network security and security protocols.
- 5 years of coding experience in one or more general purpose languages.
- 1 year of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.
Preferred qualifications:
- Master’s degree or PhD in Computer Science, Cybersecurity, or a related technical field, or equivalent practical experience.
- Experience in account security mechanisms, identity and access management (IAM), and modern authentication standards (e.g., OAuth 2.0, OIDC, FIDO/Passkeys, SAML).
- Experience building or deploying AI agents, LLMs, or agentic workflows for security automation, threat detection, or user-facing product features.
- Understanding of anti-abuse systems, bot detection, and mitigations against malicious automation (credential stuffing, bulk creation).
- Ability to identify novel security vulnerabilities (e.g., threat research, bug bounties, security advisories) and implementing systemic engineering fixes.
About the job:
The Trust and Safety Workspace Account Security and Integrity (AIS) team is dedicated to protecting Google Workspace and Cloud customers from account-based threats. The mission is to safeguard the integrity of Workspace accounts by delivering a unified, scalable defense against account hijacking, takeover (ATO), and malicious automation. We operate at the critical intersection of product security and abuse prevention, balancing robust security controls with a frictionless experience for both individual users and enterprise organizations. By studying adversarial behavior and building state-of-the-art telemetry and agentic defense systems, we ensure a secure, trusted, and resilient ecosystem that protects our customers' businesses, data, and users.
As a Senior Security Engineer, you will drive the technical strategy to defend Workspace accounts and protect the Google Workspace and Cloud customers against advanced and evolving threats. Operating at the frontier of account security, adversarial analysis, and agentic AI, you will lead research into account vulnerabilities and pioneer the next generation of automated defense tools. In this role, you will not only identify and patch critical vulnerabilities but also architect novel, customer-facing agentic systems that empower Google Workspace and Cloud customers to defend their own environments. You will provide strong technical leadership, collaborate closely with product engineering and threat intelligence teams, and mentor junior engineers to scale our defensive capabilities.
Responsibilities:
- Drive the technical strategy and threat modeling for Workspace account security, identifying systemic weaknesses in authentication, recovery, and API integration paths.
- Lead vulnerability research and adversarial simulation to expose novel account takeover (ATO) and "Made for Abuse" (MFA) techniques.
- Design and build advanced agentic systems, debugging tools, and simulators to autonomously detect, analyze, and mitigate complex account security threats.
- Architect and deploy customer-facing agentic tools that empower Workspace and Google Cloud customers to proactively monitor and secure their own environments.
- Lead the investigation of high-severity account security incidents, developing robust, long-term mitigations and patches in collaboration with Product Engineering teams.
Similar roles
-
Cybersecurity Compliance & Client Delivery
Cyberleaf Fort Myers, Florida, United States · $85K/yr
-
Senior Counsel, Privacy, Cybersecurity, and AI Governance
Scout Motors Charlotte, North Carolina, United States · $200K–$245K/yr
-
Cybersecurity Analyst – Data Security
Jostens Santiago, Santiago, Dominican Republic
-
Cybersecurity Engineer (System Engineering)
General Dynamics Missions System International Ottawa, Ontario, Canada · CA$92K–CA$115K/yr
-
Elmbridge Electrical Services - Apprentice Fire and Security Engineer
Apprenticeships at Skills for Security Cranleigh, England, United Kingdom · £17K/yr
-
Cybersecurity Requirements Analyst
9th Way Insignia United States · $63K–$70K/yr