Senior Information Security Engineer, Product Security Engineering
Product, IT
Kirkland, WA, USA
USD 174k-253k / year + Equity
Senior Information Security Engineer, Product Security Engineering
- linkCopy link
- emailEmail a friend
- Health, dental, vision, life, disability insurance
- Retirement Benefits: 401(k) with company match
- Paid Time Off: 20 days of vacation per year, accruing at a rate of 6.15 hours per pay period for the first five years of employment
- Sick Time: 40 hours/year (increased to 69 hours/year for Seattle) including 5 discretionary sick days per instance
- Maternity Leave (Short-Term Disability + Baby Bonding): 28-30 weeks
- Baby Bonding Leave: 18 weeks
- Holidays: 13 paid days per year
Minimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 5 years of experience with security engineering, computer and network security and security protocols.
- 5 years of experience with security assessments or security design reviews or threat modeling.
- 5 years of coding experience in one or more general purpose languages.
- 1 year of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.
- Coding experience in one or more general purpose languages.
Preferred qualifications:
- Experience identifying and mitigating network security risks using threat modeling and other risk identification techniques.
- Experience in applications security, cryptography, network security or systems security.
- Experience with C++ dynamic analysis and static code analysis.
- Expertise in in security assessments, vulnerability management and security research.
About the job
There's no such thing as a "safe system" - only safer systems. Our Security team works to create and maintain the safest operating environment for Google's users and developers. As a Security Engineer, you help protect network boundaries, keep computer systems and network devices hardened against attacks and provide security services to protect highly sensitive data like passwords and customer information. Security Engineers work directly with network equipment and actively monitor our systems for attacks and intrusions. You also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
You use your industry experience to own and drive the resolution of complex security incidents, policy questions and technical security issues.
In this role, you will help set the focus, direction and impact of this organization with regards to product security. There is an exciting mix of work to be accomplished across multiple security domains. A few examples are: security reviews, security education, web application scanning and testing, vulnerability research and security data analysis all with the goal of highlighting and driving down risk.
Google Cloud accelerates every organization’s ability to digitally transform its business and industry. We deliver enterprise-grade solutions that leverage Google’s cutting-edge technology, and tools that help developers build more sustainably. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.US: $174000 - $253000 (USD) + 15% bonus target + bonus + equity + benefits
Learn more about benefits at Google.
Responsibilities
- Identify security issues and implement and design security controls, tools, and services to improve security systems and processes.
- Perform security reviews, research and reproduce vulnerabilities, design secure protocols and systems, and write tests and fuzzers. Look for vulnerabilities with techniques including reverse engineering, fuzzing, and static analysis
- Review and develop secure operational practices, and provide security guidance for engineers and support staff. Review designs and drive towards defense in depth and security by default, both with one-time reviews and longer term engagements
- Respond to vulnerabilities with repros, variant analysis, mitigations, and hardening. Focus on the security strategy for Google Cloud.
Information collected and processed as part of your Google Careers profile, and any job applications you choose to submit is subject to Google's Applicant and Candidate Privacy Policy.
Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See also Google's EEO Policy, Know your rights: workplace discrimination is illegal, Belonging at Google, and How we hire.
If you have a need that requires accommodation, please let us know by completing our Accommodations for Applicants form.
Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.
To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes.