Senior Security Engineer, Trust and Safety Cloud, Workspace

Google LLC
Kirkland, WA, United States
12 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
1 year minimum
Compensation
$174,000.0 - $252,000.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Cloud Computing Computer Programming Software Debugging Identity and Access Management Networking Hardware Intrusion Detection and Prevention OAuth OpenID Security Assertion Markup Language (SAML) Google Cloud Large Language Models
+8 more
Multi-Agent Systems Software Security Cyber Threat Analysis Build Management Gsuite Virtual Agents Security Orchestration, Automation & Response Vulnerability Analysis

Job description

Our Security team works to create and maintain the safest operating environment for Google’s users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

As a Senior Security Engineer within the Workspace Account Security and Integrity team, you will drive the technical strategy to defend Workspace accounts and protect the Google Workspace and Cloud customers against advanced and evolving threats. Operating at the frontier of account security, adversarial analysis, and agentic AI, you will lead in-depth searchs into account vulnerabilities and pioneer the next generation of automated defense tools.

In this role, you will not only identify and patch critical vulnerabilities but also architect novel, customer-facing agentic systems that empower Google Workspace and Cloud customers to defend their own environments. You will provide strong technical leadership, collaborate closely with product engineering and threat intelligence teams, and mentor junior engineers to scale the defensive capabilities.

Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

US: $174000 - $252000 (USD) + 15% bonus target + equity + benefits, * Drive Technical Strategy and Threat Modeling: Drive the technical strategy and threat modeling for Workspace account security, identifying systemic weaknesses in authentication, recovery, and API integration paths.

  • Lead Vulnerability Research: Lead vulnerability research and adversarial simulation to expose novel account takeover (ATO) and Made for Abuse (MFA) techniques.
  • Build Agentic Defense Systems: Design and build advanced agentic systems, debugging tools, and simulators to autonomously detect, analyze, and mitigate complex account security threats.
  • Co-Develop Customer-Facing Security Tools: Architect and deploy customer-facing agentic tools that empower Workspace and Google Cloud customers to proactively monitor and secure their own environments.
  • Lead Incident Mitigation: Lead the investigation of high-severity account security incidents, developing robust, long-term mitigations and patches in collaboration with product engineering teams.

Requirements

  • Bachelor’s degree or equivalent practical experience.
  • 5 years of experience with security assessments or security design reviews or threat modeling.
  • 5 years of experience with security engineering, computer and network security and security protocols.
  • 5 years of coding experience in one or more general purpose languages.
  • 1 year of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment., * Core Security Experience: 5 years of experience in security engineering, threat modeling, and application security.
  • Identity and Auth Expertise: Deep expertise in account security mechanisms, identity and access management (IAM), and modern authentication standards (e.g., OAuth 2.0, OIDC, FIDO/Passkeys, SAML).
  • Agentic AI and LLMs: Demonstrated experience building or deploying AI agents, LLMs, or agentic workflows for security automation, threat detection, or user-facing product features.
  • Vulnerability Discovery: Proven track record of identifying novel security vulnerabilities (e.g., threat research, bug bounties, security advisories) and implementing systemic engineering fixes.

Benefits & conditions

Experience driving progress, solving problems, and mentoring more junior team members; deeper expertise and applied knowledge within relevant area.

info_outline

XIn accordance with Washington state law, we are highlighting our comprehensive benefits package, which is available to all eligible US based employees.

Benefits for this role include:

  • Health, dental, vision, life, disability insurance
  • Retirement Benefits: 401(k) with company match
  • Paid Time Off: 20 days of vacation per year, accruing at a rate of 6.15 hours per pay period for the first five years of employment
  • Sick Time: 40 hours/year (increased to 69 hours/year for Seattle) including 5 discretionary sick days per instance
  • Maternity Leave (Short-Term Disability + Baby Bonding): 28-30 weeks
  • Baby Bonding Leave: 18 weeks
  • Holidays: 13 paid days per year

About the company

Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See alsoGoogle’s EEO Policy (https://www.google.com/about/careers/applications/eeo/) ,Know your rights: workplace discrimination is illegal (https://careers.google.com/jobs/dist/legal/EEOC_KnowYourRights_10_20.pdf) ,Belonging at Google (https://about.google/belonging/) , andHow we hire (https://careers.google.com/how-we-hire/) .

If you have a need that requires accommodation, please let us know by completing ourAccommodations for Applicants form (https://goo.gl/forms/aBt6Pu71i1kzpLHe2) .

Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.

To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

3:10 min

Building hands-on experience with Google Cloud skill badges

Asrar Asrar · WWC 2024

Videos

See all

Related articles

See all