Senior Security Engineer, Trust and Safety, Cloud, Workspace
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+8 more
Job description
Our Security team works to create and maintain the safest operating environment for Google’s users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
As a Senior Security Engineer within the Workspace Account Security and Integrity team, you will drive the technical strategy to defend Workspace accounts and protect the Google Workspace and Cloud customers against advanced and evolving threats. Operating at the frontier of account security, adversarial analysis, and agentic AI, you will lead in-depth searchs into account vulnerabilities and pioneer the next generation of automated defense tools.
In this role, you will not only identify and patch critical vulnerabilities but also architect novel, customer-facing agentic systems that empower Google Workspace and Cloud customers to defend their own environments. You will provide strong technical leadership, collaborate closely with product engineering and threat intelligence teams, and mentor junior engineers to scale the defensive capabilities.
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.
US: $174000 - $252000 (USD) + 15% bonus target + equity + benefits, * Drive the technical strategy and threat modeling for Workspace account security, identifying systemic weaknesses in authentication, recovery, and API integration paths.
- Lead vulnerability research and adversarial simulation to expose novel account takeover (ATO) and Made for Abuse (MFA) techniques.
- Design and build advanced agentic systems, debugging tools, and simulators to autonomously detect, analyze, and mitigate complex account security threats.
- Architect and deploy customer-facing agentic tools that empower Workspace and Google Cloud customers to proactively monitor and secure their own environments.
- Lead the investigation of high-severity account security incidents, developing long-term mitigations and patches in collaboration with product engineering teams.
Requirements
Experience driving progress, solving problems, and mentoring more junior team members; deeper expertise and applied knowledge within relevant area., * Bachelor’s degree or equivalent practical experience.
- 5 years of experience with security assessments or security design reviews or threat modeling.
- 5 years of experience with security engineering, computer and network security and security protocols.
- 5 years of coding experience in one or more general purpose languages.
- 1 year of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment., * 5 years of experience in security engineering, threat modeling, and application security.
- Deep expertise in account security mechanisms, identity and access management (IAM), and modern authentication standards (e.g., OAuth 2.0, OIDC, FIDO/Passkeys, SAML).
- Demonstrated experience building or deploying AI agents, LLMs, or agentic workflows for security automation, threat detection, or user-facing product features.
- Proven track record of identifying novel security vulnerabilities (e.g., threat research, bug bounties, security advisories) and implementing systemic engineering fixes.
Benefits & conditions
XIn accordance with Washington state law, we are highlighting our comprehensive benefits package, which is available to all eligible US based employees. Benefits for this role include:
- Health, dental, vision, life, disability insurance
- Retirement Benefits: 401(k) with company match
- Paid Time Off: 20 days of vacation per year, accruing at a rate of 6.15 hours per pay period for the first five years of employment
- Sick Time: 40 hours/year (increased to 69 hours/year for Seattle) including 5 discretionary sick days per instance
- Maternity Leave (Short-Term Disability + Baby Bonding): 28-30 weeks
- Baby Bonding Leave: 18 weeks
- Holidays: 13 paid days per year
About the company
Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See alsoGoogle’s EEO Policy (https://www.google.com/about/careers/applications/eeo/) ,Know your rights: workplace discrimination is illegal (https://careers.google.com/jobs/dist/legal/EEOC_KnowYourRights_10_20.pdf) ,Belonging at Google (https://about.google/belonging/) , andHow we hire (https://careers.google.com/how-we-hire/) .
If you have a need that requires accommodation, please let us know by completing ourAccommodations for Applicants form (https://goo.gl/forms/aBt6Pu71i1kzpLHe2) .
Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.
To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 138 - Are you secure about this?
Highest Paying Tech Companies for Developers
Understanding and Mitigating Common Web Vulnerabilities
Trustworthy AI Starts at Deployment: 5 Checks Before You Ship