Google

Senior Security Engineer, Exploits, Google Threat Intelligence Group

Google · Reston, Virginia, United States · $174K–$252K/yr

Software Development · 10,001+ employees

7 h ago
Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The role involves tracking complex threat actors, modeling their tactics, techniques, and procedures, and developing detection signatures to close security gaps. You will also collaborate with cross-functional teams to design exploit mitigations and mentor junior engineers.

What they look for

Security Engineering Threat Intelligence Malware Analysis Reverse Engineering Vulnerability Analysis Threat Modeling Security Assessments Network Security Android Security Chrome Security SIEM VirusTotal Risk Analysis Technical Leadership Exploit Mitigations

Requirements

Candidates must have a bachelor's degree and at least 5 years of experience in security engineering, threat modeling, and coding. Additionally, 1 year of technical leadership experience is required to manage complex research projects.

Benefits

Bonus Equity Health Insurance

Full description

Minimum qualifications:

  • Bachelor's degree or equivalent practical experience.
  • 5 years of experience with security assessments or security design reviews or threat modeling.
  • 5 years of experience with security engineering, computer and network security and security protocols.
  • 5 years of coding experience in one or more general purpose languages.
  • 1 year of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.

Preferred qualifications:

  • Experience with threat intelligence platforms and tools (e.g., VirusTotal, SIEMs).
  • Proficiency in analyzing and correlating data from sources to track threat activity.
  • Knowledge of Android and Chrome security and internals.
  • Proven ability to lead complex threat research projects independently.
  • Skills in malware analysis, reverse engineering, or vulnerability analysis.

About the job:

Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

As a Security Engineer on our team, you will conduct in-depth research on risk groups, their tactics, techniques, and procedures (TTPs), and the malware they employ. You will utilize internal intelligence platforms to model risk activity and generate insights. This role involves close collaboration with various security teams across Google to develop and implement effective countermeasures, contributing directly to risk disruption and enhancing our collective security posture. You will lead projects, mentor others, and apply your passion for security research.

Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.

Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

US: $174000 - $252000 (USD) + 15% bonus target + equity + benefits

Learn more about benefits at Google. Responsibilities:

  • Own, prioritize, and drive the tracking of complex, threat actors and associated research projects.
  • Lead complex technical analyses, modeling threat activity, tactics, techniques, and procedures (TTPs), and indicators of compromise (IOCs) across internal platforms (mGraph).
  • Create and deploy detection signatures (autoqueries, Watchtower rules) to maintain visibility over threat actors and assist in closing security gaps.
  • Produce polished, high-quality technical intelligence documentation and actor profiles to deliver actionable insights to internal and external stakeholders.
  • Influence technical direction within your scope, mentor junior engineers, and collaborate with cross-functional Google teams to support threat disruption efforts. Collaborate with security engineers and product teams in designing innovative exploit mitigations.