Staff Security Engineer, Product Security Engineering, Cloud CISO
Google · New York, New York, United States · $207K–$300K/yr
Software Development · 10,001+ employees
About the role
The role involves performing technical security assessments, code reviews, and vulnerability testing to ensure Google Cloud products are secure by design. You will also drive the resolution of complex security incidents and develop scalable security strategies across the organization.
What they look for
Requirements
Candidates must have at least 8 years of experience in security engineering and threat modeling, along with 5 years of coding experience. A bachelor's degree or equivalent practical experience is required for this position.
Benefits
Full description
Minimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 8 years of experience with security assessments or security design reviews or threat modeling.
- 8 years of experience with security engineering, computer and network security and security protocols.
- 5 years of coding experience in one or more general purpose languages.
- 3 years of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.
Preferred qualifications:
- Experience applying AI/ML to solve complex security problems.
- Ability to influence and engage with cross-functional teams and executive stakeholders, driving alignment and achieving results.
- Exceptional communication and people management skills with proven ability to take initiative and build strong, productive relationships externally and internally.
About the job:
There's no such thing as a "safe system" - only safer systems. Our Security team works to create and maintain the safest operating environment for Google's users and developers. As a Security Engineer, you help protect network boundaries, keep computer systems and network devices hardened against attacks and provide security services to protect highly sensitive data like passwords and customer information. Security Engineers work directly with network equipment and actively monitor our systems for attacks and intrusions. You also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
You use your industry experience to own and drive the resolution of complex security incidents, policy questions and technical security issues.
The Cloud CISO Security Engineering team within the Cloud CISO organization is responsible for helping ensure every product that Cloud ships is as secure as it can be and increasing the assurance levels of security in the infrastructure underlying all our products. This team also focuses on increasing the capabilities of each product team to develop more secure products by design and by default, from patterns, tools and frameworks to increasing the skill level of embedded security leads. In this role, you will help to ensure that our software and systems are designed and implemented to the highest security standards. You will perform technical security assessments, code reviews, and vulnerability testing to highlight risk, helping Google teams and partners to improve security, and work on a wide variety of software designs and technology stacks.
Google Cloud accelerates every organization’s ability to digitally transform its business and industry. We deliver enterprise-grade solutions that leverage Google’s cutting-edge technology, and tools that help developers build more sustainably. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.Individual pay is determined by factors including job-related skills, experience, and relevant education or training.
US: $207000 - $300000 (USD) + 20% bonus target + equity + benefits
Learn more about benefits at Google. Responsibilities:
- Perform security reviews, research and reproduce vulnerabilities, design secure protocols and systems, and write tests and fuzzers.
- Review and develop secure operational practices, and provide security guidance for engineers and support staff.
- Review designs and look for vulnerabilities, both with one-time reviews and longer term engagements. Look for vulnerabilities with techniques including reverse engineering, fuzzing, and static analysis.
- Respond to vulnerabilities with repos, mitigations, and hardening. Surface vulnerability patterns and design them out.
- Focus on the security strategy for Google Cloud and scalable solutions, and the ability to influence cross-organizationally.