Google
Posted 3w ago

Senior Security Engineer, Product Security Engineering, Cloud CISO

Google
Sunnyvale or Kirkland or New York City or Seattle
$174k-$253k/yrOnsiteFull Time
Responsibilities
  • surfacing vulnerabilities
  • implementing mitigations
  • reviewing practices
Requirements
  • 5+ years security engineering and coding experience
  • Security assessments or threat modeling
  • Vulnerability management
  • Bachelor\u0002s or equivalent
  • Strong communication and collaboration skills
Technical tools mentioned
Google CloudAI/ML

Job description

In accordance with Washington state law, we are highlighting our comprehensive benefits package, which is available to all eligible US based employees. Benefits for this role include:
  • Health, dental, vision, life, disability insurance
  • Retirement Benefits: 401(k) with company match
  • Paid Time Off: 20 days of vacation per year, accruing at a rate of 6.15 hours per pay period for the first five years of employment
  • Sick Time: 40 hours/year (increased to 69 hours/year for Seattle) including 5 discretionary sick days per instance
  • Maternity Leave (Short-Term Disability + Baby Bonding): 28-30 weeks
  • Baby Bonding Leave: 18 weeks
  • Holidays: 13 paid days per year

Note: By applying to this position you will have an opportunity to share your preferred working location from the following: Sunnyvale, CA, USA; Kirkland, WA, USA; New York, NY, USA; Seattle, WA, USA.

Minimum qualifications:

  • Bachelor's degree or equivalent practical experience.
  • 5 years of experience with security engineering, computer and network security and security protocols.
  • 5 years of coding experience in one or more general purpose languages.
  • 5 years of experience with security assessments or security design reviews or threat modeling.
  • Experience with vulnerability management including identification, classification and remediation.

Preferred qualifications:

  • Experience applying AI/ML to solve complex security problems (e.g., vulnerability validation, remediation).
  • Experience with securing Cloud infrastructure and products running in Cloud environments.
  • Understanding of vulnerability assessment and exploitation methods.
  • Track record of successfully designing, implementing, and managing security projects and excellent teamwork and communication skills.
  • Track record of influencing others without authority, and building strong relationships with stakeholders.

About the job

Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

Product Security Engineering is the team within the Cloud CISO organization responsible for helping ensure every product Cloud ships is as secure as it can be and increasing the assurance levels of security in the infrastructure underlying all our products. This team will also focus on increasing the capabilities of each product team to develop more secure products by design and by default, from patterns, tools and frameworks to increasing the skill level of embedded security leads.

As a Security Engineer, you will help to ensure that our software and systems are designed and implemented to the highest security standards. You will oversee technical security assessments, code reviews and vulnerability testing to highlight risk, helping Google teams and partners to improve security, and work to secure a wide variety of software designs and technology stacks.
Google Cloud accelerates every organization’s ability to digitally transform its business and industry. We deliver enterprise-grade solutions that leverage Google’s technology, and tools that help developers build more sustainably. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

US: $174000 - $253000 (USD) + 15% bonus target + equity + benefits

Learn more about benefits at Google.

Responsibilities

  • Surface vulnerability patterns, and implement mitigations and hardening strategies to eliminate them.
  • Drive vulnerability discovery coverage across Google Cloud products and shared infrastructure.
  • Enable real-time visibility into Cloud product security risks, enabling prioritization based on a number of dimensions, such as business impact, and exploitability.
  • Review and develop secure operational practices, and provide security guidance for engineers and support staff.
  • Design and drive implementation of scalable solutions. 
    Facilitate alignment and clarity across teams on goals, outcomes, and timelines.
Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Google's EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our Accommodations for Applicants form.

About Google

Provides online search, advertising, cloud computing, and consumer electronics.

Year founded
1998
Employees
190000
Organization type
Public
Headquarters
US

Similar jobs

Security Engineer roles near Sunnyvale, California
1d
Save
Mark Applied
Hide
Security Engineer
Guadalajara or San Francisco
OnsiteFull Time
Bright Machines
Bright Machines: Provides software-defined robotic automation for electronics manufacturing.
5+ YOERequires 5+ years in security engineering or related work, ISO 27001 ISMS experience, application security tooling, scripting, infrastructure-as-code, cloud security, GRC, and strong English communication.
ISO 27001:2022, SIG, CAIQ, SAST, DAST, SCA, Snyk, Semgrep, Checkmarx, Burp Suite, Python, Terraform, Ansible, AWS, Azure, GCP, IAM, EDR, SOC, IDS/IPS, MFA, SSO, SOC 2 Type II
1d
Save
Mark Applied
Hide
Staff Security Engineer, Cloud
Palo Alto, California, United States
$205k-$240k/yr OnsiteFull Time
ALSO
ALSO: Developing vertically integrated small electric vehicles for urban mobility.
10+ YOE10+ years in backend and infrastructure engineering, hands-on production security ownership, expert AWS and Kubernetes, fluent Go, distributed systems security, identity protocols, cryptography, threat modeling, incident response, and 0-to-1 security program ownership.
Go, AWS, Kubernetes, IAM, VPC, KMS, Secrets Manager, GuardDuty, Security Hub, CloudTrail, Config, SCPs, EKS, ECS, ECR, Lambda, DynamoDB, S3, RBAC, OAuth2, OIDC, JWT, SAML, PKI, CI/CD, SBOM, FSA, HSA, 401(k)
2d
Save
Mark Applied
Hide
Security Engineer
San Francisco, California, United States
OnsiteFull Time
Raindrop
Raindrop: AI agent monitoring and observability platform.
Security engineering experience at a fast-growing startup; familiarity with SOC 2 and HIPAA compliance; security community contributions; AI product interest; strong communication and problem-solving skills.
2d
Save
Mark Applied
Hide
Senior/Staff Security Engineer - Product Security
South San Francisco, California, United States
HybridFull Time
Zipline
Zipline: Operates an autonomous drone delivery system for medical supplies.
8+ YOERequires 8+ years securing large-scale production systems, hands-on Python or Go engineering, cloud-native and microservices expertise, vulnerability management, incident response, threat modeling, and quantitative security metrics.
Python, Go, Kubernetes, IAM, CI/CD, KMS, OWASP LLM
3d
Save
Mark Applied
Hide
Senior Security Engineer, AI Incident Response
Menlo Park or Bellevue
$176k-$253k/yr HybridFull Time
Snowflake
SnowflakeNYSE: SNOW: Cloud-based platform for data storage, processing, and analytics.
5+ YOE5+ years in information security, incident response, security or product/application engineering; AI/ML security experience; cloud knowledge; SQL and Python; bachelor's degree or equivalent experience.
Cortex AI, Cortex Agents, Snowflake Intelligence, Snowpark ML, Cortex Search, AWS, Azure, GCP, SQL, Python, CI/CD, RAG
4d
Save
Mark Applied
Hide
Senior Security Engineer, RTOS and Virtualization
Santa Clara or Austin or Hillsboro or United States or Redmond
$184k-$357k/yr RemoteFull Time
NVIDIA
NVIDIANASDAQ: NVDA: Designs GPU-accelerated computing and artificial intelligence hardware.
8+ YOE8+ years in systems, embedded, platform, product, or automotive security; BSEE/BSCS or equivalent; RTOS or privileged software security; strong C/C++; threat modeling, fuzzing, vulnerability analysis, and automotive security standards.
C, C++, RTOS, Hypervisor, Rust, Ada, SPARK, MMU, SMMU, IOMMU, DMA, ISO/SAE 21434, UN R155, ISO 26262, Automotive SPICE
4d
Save
Mark Applied
Hide
Senior Security Engineer, RTOS and Virtualization
Santa Clara or Austin or Hillsboro or United States or Redmond
$184k-$357k/yr RemoteFull Time
NVIDIA
NVIDIANASDAQ: NVDA: Designs graphics processing units and artificial intelligence hardware.
8+ YOE8+ years in systems, embedded, platform, product, or automotive security; bachelor's in electrical engineering or computer science; C/C++; RTOS, hypervisor, kernel, firmware, or privileged software security experience.
C, C++, RTOS, Hypervisor, CPU, SoC, MMU, SMMU, IOMMU, DMA, Rust, Ada/SPARK, ISO/SAE 21434, UN R155, ISO 26262, Automotive SPICE
5d
Save
Mark Applied
Hide
Lead Security Engineer
Austin or Sunnyvale
$170k-$210k/yr OnsiteFull Time
Neurophos
Neurophos: Develops high-performance photonic processors for AI inference acceleration.
8+ YOERequires 8+ years in infrastructure security, security engineering, or cybersecurity management, including 3+ years leading security programs; expertise in cloud security, networks, IAM, endpoints, incident response, and compliance.
Azure, Identity & Access Management, Role-Based Access Control, Multi-Factor Authentication, SIEM, EDR, Vanta, Drata, Infrastructure as Code, Linux, NIST CSF, ISO 27001