Senior Information Security Engineer, Cloud CISO, Vulnerability Rewards Program

Google LLC
Sunnyvale, CA, United States
13 days ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
1 year minimum
Compensation
$174,000.0 - $252,000.0
Working hours
Regular working hours
Job source

Tech stack

Cloud Computing Cloud Computing Security Code Review Cyber Security Computer Programming Digital Forensics Networking Hardware Cloud Services Software Engineering Google Cloud Information Technology Data Analytics
+2 more
Service Stack Vulnerability Analysis

Job description

There’s no such thing as a “safe system” - only safer systems. Our Security team works to create and maintain the safest operating environment for Google’s users and developers. As a Security Engineer, you help protect network boundaries, keep computer systems and network devices hardened against attacks and provide security services to protect highly sensitive data like passwords and customer information. Security Engineers work directly with network equipment and actively monitor our systems for attacks and intrusions. You also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

You use your industry experience to own and drive the resolution of complex security incidents, policy questions and technical security issues.

Google Cloud Security Engineering within the Cloud CISO organization is responsible for ensuring every product Cloud ships securely and for increasing the assurance levels of security in the infrastructure underlying all our products. As an Information Security Engineer, you will help design and implement software and systems to the highest security standards. You will work with external security researchers from the Google Cloud Vulnerability Rewards Program (Cloud VRP) and perform technical security assessments, code reviews and vulnerability testing to highlight risk, helping Google teams and partners to improve security, and work on a wide variety of Cloud products, software designs, and technology stacks.

Google Cloud accelerates every organization’s ability to digitally transform its business and industry. We deliver enterprise-grade solutions that leverage Google’s cutting-edge technology, and tools that help developers build more sustainably. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.

Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

US: $174000 - $252000 (USD) + 15% bonus target + equity + benefits

Learn more aboutbenefits at Google (https://www.google.com/about/careers/applications/benefits/) .

Responsibilities

  • Conduct security assessments of Cloud security and vulnerability reports to assess risk and impact and ensure prompt and proper mitigations with key stakeholders.
  • Manage multiple cross-functional efforts and escalations simultaneously with engaged priorities. Solve complex technical problems that involve independent but interconnected components.
  • Serve as the go-to person for broad security domains and understand the interplay of threats between systems and services. Build and maintain strong relationships with stakeholders across Google, including legal, engineering, and communications teams.
  • Investigate impact to Google Cloud and its customers to determine if new detection or compromise notifications are necessary.
  • Demonstrate consistent ability to drive positive change in alignment with business objectives, and collaborate with teams to uplift overarching security capabilities. Demonstrate exceptional judgment in balancing security and business needs in owned areas, considering both risk and impact.

Requirements

Experience driving progress, solving problems, and mentoring more junior team members; deeper expertise and applied knowledge within relevant area., * Bachelor’s degree or equivalent practical experience.

  • 5 years of experience with security engineering, computer and network security and security protocols.
  • 5 years of experience with security assessments, security design reviews, or threat modeling.
  • 5 years of coding experience in one or more general purpose languages.
  • 1 year of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.

Preferred qualifications:

  • 8 years of experience with vulnerability identification, assessment, and management.
  • Technical background with experience in security operations, systems administration, digital forensics, security engineering, vulnerability assessments, etc.
  • Ability to demonstrate composure and level-headedness during security escalations and lead teams towards timely resolution.
  • Leadership of various teams through ambiguous situations with influence without authority.
  • Demonstration of strong writing skills, and an ability to present to various types of audiences both external and internal.
  • Exceptional communication skills with a proven ability to articulate complex risks to stakeholders at all levels using a data-driven.

About the company

Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See alsoGoogle’s EEO Policy (https://www.google.com/about/careers/applications/eeo/) ,Know your rights: workplace discrimination is illegal (https://careers.google.com/jobs/dist/legal/EEOC_KnowYourRights_10_20.pdf) ,Belonging at Google (https://about.google/belonging/) , andHow we hire (https://careers.google.com/how-we-hire/) .

If you have a need that requires accommodation, please let us know by completing ourAccommodations for Applicants form (https://goo.gl/forms/aBt6Pu71i1kzpLHe2) .

Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.

To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:39 min

Addressing code review surrender and process exploitation

Laura Tacho Laura Tacho ¡ World Congress 2026 Europe

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar ¡ World Congress 2024

3:47 min

Solving the knowledge deficit in large language models

Alejandro Saucedo Alejandro Saucedo +3 ¡ World Congress 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira ¡ Coffee With Developers

56 sec

The hidden costs of delayed peer code reviews

Tim Gilboy Tim Gilboy

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all