Senior Strategic Security Consultant, Mandiant, Google Cloud
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+10 more
Job description
As a Mandiant Strategic Security Consultant, you will lead and support projects on behalf of clients that assess, test, or build their security programs. Project teams may range from 2 to 5 colleagues. Clients will range from start-up companies looking to supplement their security team to Fortune 100 companies that need fresh ideas to enhance their perspective on the security program. You will provide guidance and advice to our client on best practices and managing the risks for their security program.
In this role, you will lead strategic consulting engagements focused on Applied Security (AppSec) and Vulnerability Management. You will design secure SDLC roadmaps, establish industry-standard policies (Developer Security Operations, Threat Modeling), and collaborate with clients to implement continuous security testing across cloud and on-prem platforms.
Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant’s cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry’s best security validation ensures that Mandiant knows more about today’s advanced threats than anyone.
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.
US: $138000 - $201000 (USD) + 15% bonus target + equity + benefits, * Lead strategic security consulting engagements, maturity assessments, and gap analyses against industry frameworks (OWASP SAMM, BSIMM, NIST SSDF) to deliver risk-reduction roadmaps for cloud and on-premises environments.
- Architect and secure Developer Security Operations pipelines by designing technical blueprints and integrating automated security gates (SAST, DAST, SCA) seamlessly into developer workflows.
- Establish robust governance structures and facilitated risk-tiering workshops to define remediation service-level agreements, exception handling, and prioritization metrics (CVSS, EPSS) across multi-cloud and legacy infrastructure.
- Support application threat modeling (STRIDE) and architect security reviews early in the Software Development Life Cycle (SDLC) to identify design flaws and provide engineering teams with strategies.
- Pioneer application landscape discovery and Software Bill of Materials (SBOM) mapping to manage supply chain risks, while advising on the deployment of enterprise AppSec and Virtual Machine technologies (e.g., Qualys, Tenable, Snyk, Checkmarx).
Requirements
Experience driving progress, solving problems, and mentoring more junior team members; deeper expertise and applied knowledge within relevant area., * Bachelor’s degree in Computer Science, Information Systems, Cyber-security, related technical field, or equivalent practical experience.
- 5 years of experience assessing and developing cyber-security solutions and programs across security domains.
- 5 years of experience in delivering cyber outcomes, identifying mission risks, and devising solutions.
- Ability to travel up to 30% of the time as needed., * Certifications related to specific cloud platforms.
- Experience implementing industry-leading practices around cyber risks and cloud security for clients’ cloud security frameworks using industry standards.
- Experience with cloud governance, with the ability to convey governance principles to cloud computing in terms of policies.
- Experience deploying and maintaining security testing infrastructures (SAST, DAST, SCA, network/container vulnerability scanners) across hybrid ecosystems and multi-cloud environments.
- Proficiency in the Open Web Application Security Project (OWASP) Top 10, Common Weakness Enumeration (CWE), Threat Modeling Methodologies, and integrating security controls into Agile and Developer Security Operation environments.
About the company
Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See alsoGoogle’s EEO Policy (https://www.google.com/about/careers/applications/eeo/) ,Know your rights: workplace discrimination is illegal (https://careers.google.com/jobs/dist/legal/EEOC_KnowYourRights_10_20.pdf) ,Belonging at Google (https://about.google/belonging/) , andHow we hire (https://careers.google.com/how-we-hire/) .
If you have a need that requires accommodation, please let us know by completing ourAccommodations for Applicants form (https://goo.gl/forms/aBt6Pu71i1kzpLHe2) .
Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.
To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on dejobs.orgGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
Understanding and Mitigating Common Web Vulnerabilities
Walking Into The Era of Supply Chain Risks
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.