Senior Strategic Security Consultant, Mandiant, Google Cloud

Google LLC
Atlanta, GA, United States
26 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$138,000.0 - $201,000.0
Working hours
Regular working hours
Job source

Tech stack

Agile Methodology Artificial Intelligence Cloud Computing Cloud Computing Security Cyber Security Information Systems Open Web Application Security Software Engineering Systems Integration Virtual Machines Software Vulnerability Management Google Cloud
+10 more
Software Security Multi-Cloud Cyber Threat Analysis Information Technology Checkmarx Cyber Warfare Qualys Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

As a Mandiant Strategic Security Consultant, you will lead and support projects on behalf of clients that assess, test, or build their security programs. Project teams may range from 2 to 5 colleagues. Clients will range from start-up companies looking to supplement their security team to Fortune 100 companies that need fresh ideas to enhance their perspective on the security program. You will provide guidance and advice to our client on best practices and managing the risks for their security program.

In this role, you will lead strategic consulting engagements focused on Applied Security (AppSec) and Vulnerability Management. You will design secure SDLC roadmaps, establish industry-standard policies (Developer Security Operations, Threat Modeling), and collaborate with clients to implement continuous security testing across cloud and on-prem platforms.

Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant’s cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry’s best security validation ensures that Mandiant knows more about today’s advanced threats than anyone.

Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

US: $138000 - $201000 (USD) + 15% bonus target + equity + benefits, * Lead strategic security consulting engagements, maturity assessments, and gap analyses against industry frameworks (OWASP SAMM, BSIMM, NIST SSDF) to deliver risk-reduction roadmaps for cloud and on-premises environments.

  • Architect and secure Developer Security Operations pipelines by designing technical blueprints and integrating automated security gates (SAST, DAST, SCA) seamlessly into developer workflows.
  • Establish robust governance structures and facilitated risk-tiering workshops to define remediation service-level agreements, exception handling, and prioritization metrics (CVSS, EPSS) across multi-cloud and legacy infrastructure.
  • Support application threat modeling (STRIDE) and architect security reviews early in the Software Development Life Cycle (SDLC) to identify design flaws and provide engineering teams with strategies.
  • Pioneer application landscape discovery and Software Bill of Materials (SBOM) mapping to manage supply chain risks, while advising on the deployment of enterprise AppSec and Virtual Machine technologies (e.g., Qualys, Tenable, Snyk, Checkmarx).

Requirements

Experience driving progress, solving problems, and mentoring more junior team members; deeper expertise and applied knowledge within relevant area., * Bachelor’s degree in Computer Science, Information Systems, Cyber-security, related technical field, or equivalent practical experience.

  • 5 years of experience assessing and developing cyber-security solutions and programs across security domains.
  • 5 years of experience in delivering cyber outcomes, identifying mission risks, and devising solutions.
  • Ability to travel up to 30% of the time as needed., * Certifications related to specific cloud platforms.
  • Experience implementing industry-leading practices around cyber risks and cloud security for clients’ cloud security frameworks using industry standards.
  • Experience with cloud governance, with the ability to convey governance principles to cloud computing in terms of policies.
  • Experience deploying and maintaining security testing infrastructures (SAST, DAST, SCA, network/container vulnerability scanners) across hybrid ecosystems and multi-cloud environments.
  • Proficiency in the Open Web Application Security Project (OWASP) Top 10, Common Weakness Enumeration (CWE), Threat Modeling Methodologies, and integrating security controls into Agile and Developer Security Operation environments.

About the company

Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See alsoGoogle’s EEO Policy (https://www.google.com/about/careers/applications/eeo/) ,Know your rights: workplace discrimination is illegal (https://careers.google.com/jobs/dist/legal/EEOC_KnowYourRights_10_20.pdf) ,Belonging at Google (https://about.google/belonging/) , andHow we hire (https://careers.google.com/how-we-hire/) .

If you have a need that requires accommodation, please let us know by completing ourAccommodations for Applicants form (https://goo.gl/forms/aBt6Pu71i1kzpLHe2) .

Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.

To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Overcoming developer challenges in multi-cloud environments

Sandeep Pal Sandeep Pal · Coffee With Developers

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

1:20 min

Introduction to multi-cloud development infrastructure

Sandeep Pal Sandeep Pal · Coffee With Developers

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:00 min

Connecting multi-cloud services for automated data preparation

Linda Mohamed · LIVE

Videos

See all

Related articles

See all