Google

Senior Security Engineer, Insider and Technology Risk

Google Sunnyvale, California, United States · $174K–$252K/yr

Software Development · 10,001+ employees

14 h ago
security Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The role involves serving as a trusted advisor for insider risk management and evaluating the security of complex products and systems. You will also design and implement technical controls to mitigate security flaws and drive remediation efforts across the organization.

What they look for

Security Engineering Threat Modeling Risk Assessment Compliance Testing Cloud Security Network Security Security Protocols Coding Technical Leadership Vulnerability Management Access Management System Resilience Critical Thinking Problem Solving Governance Data Protection

Requirements

Candidates must have a bachelor's degree and at least 5 years of experience in security engineering, threat modeling, and coding. Strong analytical skills and experience leading technical risk analysis in an enterprise environment are also required.

Benefits

Bonus Equity Health Insurance Retirement Benefits

Full description

Minimum qualifications:

  • Bachelor's degree or equivalent practical experience.
  • 5 years of experience with security assessments or security design reviews or threat modeling.
  • 5 years of experience with security engineering, computer and network security and security protocols.
  • 5 years of coding experience in one or more general purpose languages.
  • 1 year of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.

Preferred qualifications:

  • 8 years of experience in engineering, cybersecurity, technology risk, or security-related roles.
  • Experience with control frameworks, including risk assessment, compliance testing, monitoring, and governance.
  • Proficiency in security engineering, cybersecurity principles, problem solving, and analytical/quantitative methods.
  • Strong analytic capacity and technical understanding of cloud software development methodologies, architectures, and hardware, and networking concepts.
  • Ability to have active community contributions designed to improve organizational culture and operations.
  • Exceptional critical thinking and problem-solving skills, with the ability to connect technical or security details to broader risk implications.

About the job:

Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

The Risk and Compliance Programs team is part of the Cloud CISO organization, driving high priority risk management efforts through formalized programs, including insider and technology risk. We are responsible for managing and creating consistent analysis, assessments, controls, and strategies to reduce insider and technology risk across Cloud. Our team is collaborative, innovative, and passionate about security.Google Cloud accelerates every organization’s ability to digitally transform its business and industry. We deliver enterprise-grade solutions that leverage Google’s cutting-edge technology, and tools that help developers build more sustainably. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

US: $174000 - $252000 (USD) + 15% bonus target + equity + benefits

Learn more about benefits at Google. Responsibilities:

  • Serve as a trusted advisor to Cloud leadership for guidance on insider risk-related questions, such as threat analysis and patterns, access controls, intellectual property protection, and detection and response.
  • Evaluate the security and risk of complex, interconnected products, systems, and services, and drive mitigation and remediation efforts for systemic problems.
  • Own parts of the security outlook and roadmap for your technical problem space. Apply engineering and technical best practices to design and implement controls, tools, or processes required to solve difficult security problems.
  • Apply principles from information security and risk management domains (e.g., access management, detection and response, system resilience, vulnerability management) to protect systems and data. 
  • Work with engineering organizations to identify, develop, document, and test controls for design and operating effectiveness, in coordination with the Cloud CISO controls team.

Similar roles