Google
Posted 9h ago

Staff Security Engineer, Google Distributed Cloud, Federated Security

Google
New York or Kirkland or Seattle or Sunnyvale
$207k-$300k/yrOnsiteFull Time
Responsibilities
  • leading security
  • developing partnerships
  • reviewing designs
Requirements
  • Bachelor's degree or equivalent
  • 8 years in security assessments
  • Design reviews
  • Threat modeling
  • Security engineering, and coding
  • Plus 3 years of cloud security experience
Technical tools mentioned
CI/CDSoftware Development Life Cycle (SDLC)Infrastructure as CodeGPUsTPUs

Job description

In accordance with Washington state law, we are highlighting our comprehensive benefits package, which is available to all eligible US based employees. Benefits for this role include:
  • Health, dental, vision, life, disability insurance
  • Retirement Benefits: 401(k) with company match
  • Paid Time Off: 20 days of vacation per year, accruing at a rate of 6.15 hours per pay period for the first five years of employment
  • Sick Time: 40 hours/year (increased to 69 hours/year for Seattle) including 5 discretionary sick days per instance
  • Maternity Leave (Short-Term Disability + Baby Bonding): 28-30 weeks
  • Baby Bonding Leave: 18 weeks
  • Holidays: 13 paid days per year

Note: By applying to this position you will have an opportunity to share your preferred working location from the following: New York, NY, USA; Kirkland, WA, USA; Seattle, WA, USA; Sunnyvale, CA, USA.

Minimum qualifications:

  • Bachelor's degree or equivalent practical experience.
  • 8 years of experience with security assessments, security design reviews, or threat modeling.
  • 8 years of experience with security engineering, computer and network security and security protocols.
  • 8 years of coding experience in one or more general purpose languages.
  • 3 years of experience with Cloud Security.

Preferred qualifications:

  • Experience building, scaling, or deploying machine learning models on enterprise AI platforms.
  • Experience scaling security impact using AI native solutions.
  • Experience utilizing static code analysis tools to maintain code quality, security, and performance.
  • Understanding of hardware architecture, particularly how software interacts with compute accelerators like GPUs or TPUs.
  • Ability to implement code automation practices, including CI/CD pipelines and infrastructure as code.

About the job

Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

GDC Federated Security is the team within the Google Distributed Cloud organization responsible for ensuring every product GDC ships is as secure as it can be and increasing the assurance levels of security in the infrastructure underlying all our products. This team focuses on increasing the capabilities of our product teams to develop more secure products by design and by default, from patterns, tools, and frameworks.

In this role, you have the opportunity to help set the direction for product security across Google Distributed Cloud (GDC) and partner with amazing teams across Google. These include existing security teams, privacy teams and engineering teams. You will be a part of the team that defines the focus, direction, and impact with regards to product security in this organization. There is an exciting mix of work to be accomplished across multiple security domains. A few examples are: product security reviews, AI security, building security tooling, vulnerability research, security data analysis, all with the goal of highlighting and driving down risk.

Google Cloud accelerates every organization’s ability to digitally transform its business and industry. We deliver enterprise-grade solutions that leverage Google’s cutting-edge technology, and tools that help developers build more sustainably. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.

Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

US: $207000 - $300000 (USD) + 20% bonus target + equity + benefits

Learn more about benefits at Google.

Responsibilities

  • Lead product security as a horizontal domain or product vertical SME.
  • Develop a trusted partnership with product team partners to ensure security is built into the Software Development Life Cycle (SDLC).
  • Focus on the holistic security strategy for GDC products.
  • Leverage AI tooling to Perform SDLC reviews, research and reproduce vulnerabilities, design secure systems.
  • Review and develop secure operational practices, and provide security guidance for engineers. Review designs and look for vulnerabilities, both with one-time reviews and longer term engagements.
Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Google's EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our Accommodations for Applicants form.

About Google

Provides online search, advertising, cloud computing, and consumer electronics.

Year founded
1998
Employees
190000
Organization type
Public
Headquarters
US

Similar jobs

Security Engineer roles near New York, New York
3h
Save
Mark Applied
Hide
Software Engineer — Security
New York City or San Francisco
$220k-$300k/yr HybridFull Time
Snorkel AI
Snorkel AI: Software platform for programmatic AI data development and labeling.
Requires Python, Go, or similar programming; cloud-native and containerized systems experience; Terraform and AWS architecture; IAM and network security expertise. Experience with security automation, incident response, threat modeling, and compliance frameworks is valued.
Python, Go, Infrastructure as Code (IaC), Cloud Security Posture Management (CSPM), AWS, Kubernetes, Identity and Access Management (IAM), Network Access Control Lists (NACLs), Virtual Private Cloud (VPC), AWS Key Management Service (KMS), Terraform, CI/CD, Amazon Machine Images (AMIs), Secrets Manager, HashiCorp Vault, NIST CSF, ISO 27001, SOC 2, CIS benchmarks, Secure Development Lifecycle (SDLC), Static Application Security Testing (SAST), Software Composition Analysis (SCA), Software Bill of Materials (SBOM), Security Information and Event Management (SIEM), Security Orchestration, Automation and Response (SOAR), GCP, Azure, Zero-trust, Data Loss Prevention (DLP)
10h
Save
Mark Applied
Hide
Staff Security Engineer, Threat Detection & Response
New York City or Miami or United States
$168k-$240k/yr HybridFull Time
Gemini
GeminiNasdaq: GEMI: Regulated platform for trading and storing digital assets.
8+ YOEBachelor's degree or equivalent experience; 8–10+ years in security engineering; expertise in security technologies, cloud, network and application security, identity management, and frameworks including NIST and ISO 27001.
1d
Save
Mark Applied
Hide
Security Engineer
San Francisco or New York City
$250k-$300k/yr OnsiteFull Time
Town
Town: AI-powered productivity assistant that automates workplace workflows.
Extensive security engineering experience, production coding ability, multi-tenant SaaS security expertise, cloud security knowledge, and experience with authentication, authorization, secrets, encryption, and threat modeling.
AWS, GCP, Google, Slack, CRM
2d
Save
Mark Applied
Hide
Security Engineer, Application Security
United States or New York City
$120k-$140k/yr RemoteFull Time
GameChanger
GameChangerNYSE: DKS: Youth sports app for scorekeeping, streaming, and team management.
3+ YOERequires 3+ years in application security engineering, security tooling and CI/CD experience, threat modeling, AWS, containers, Kubernetes, IaC, policy-as-code, and secure TypeScript, Swift, or Kotlin development.
GitHub Actions, Terraform, Kubernetes, Web Application Firewall (WAF), CDN, GHAS, NowSecure, Wiz, BugCrowd, AWS, OWASP Top 10, TypeScript, Swift, Kotlin, iOS, Android, AI/ML
3d
Save
Mark Applied
Hide
Security Engineer
New York City, New York, United States
$80k-$100k/yr HybridFull Time
Manatt, Phelps & Phillips
Manatt, Phelps & Phillips: Integrated professional services firm providing legal, advocacy, and consulting.
5+ YOERequires 5+ years of IT security experience, 2+ years of network security experience, CrowdStrike Falcon expertise, and enterprise security operations knowledge. Bachelor's degree and certifications preferred.
Microsoft Windows, CrowdStrike Falcon, Endpoint Detection and Response (EDR), Managed Detection and Response (MDR), Microsoft Office, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview
3d
Save
Mark Applied
Hide
Security Engineer III - AMZ9971078
New York City, New York, United States
$176k-$237k/yr OnsiteFull Time
Amazon
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
5+ YOEBachelor's degree in Computer Science or related field plus 5 years' experience, or equivalent experience. Requires cloud security, threat modeling, governance controls, infrastructure-as-code, and policy automation expertise.
Service Control Policies, AWS Config Rules, CloudFormation Guard, CloudFormation, Terraform, NIST, SOC 2, PCI-DSS, ISO 27001, GDPR
4d
Save
Mark Applied
Hide
Security Engineer
Florham Park, New Jersey, United States
$135k-$150k/yr RemoteFull Time
Tech Mahindra
Tech MahindraNational Stock Exchange of India: TECHM: Global provider of information technology and business process services.
7+ YOEBachelor’s or higher degree and 7–10 years of experience required; expertise in Azure security, identity management, access governance, DLP, compliance monitoring, vulnerability assessment, and incident investigation.
Microsoft Azure, Microsoft Fabric, Microsoft Power BI, Microsoft Power Platform, Microsoft Copilot Studio
1w
Save
Mark Applied
Hide
Security Engineer
New York City or Los Angeles
$80k-$100k/yr HybridFull Time
Manatt
Manatt: Provides legal, public advocacy, and business strategy consulting services.
5+ YOERequires 5+ years of IT security experience, 2+ years of network security experience, CrowdStrike Falcon and EDR/MDR experience. Strong communication and organizational skills; bachelor's degree and certifications preferred.
Microsoft Windows, CrowdStrike Falcon, Endpoint Detection and Response (EDR), Managed Detection and Response (MDR), Microsoft Office, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, E-Verify, Form I-9