> Markdown version of [/jobs/ext/514943-application-security-consultant-mandiant-google](https://www.wearedevelopers.com/jobs/ext/514943-application-security-consultant-mandiant-google). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Consultant, Mandiant, Google... - **Company:** Google LLC - **Location:** Kentucky, AR, United States (Remote available) - **Experience:** Experienced - **Salary:** $112,000.0 - $162,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Bioinformatics, Cloud Computing, Code Review, Cyber Security, Information Systems, Web Development, Network Security, Wireless Security, Network Administration, Network Protocols, Web Applications, Scripting, Google Cloud, Software Security, Software Application Programming, Cyber Threat Analysis, Information Technology, Purple Team (Cyber Security), Cyber Warfare - **Published:** June 12, 2026 - **Apply:** https://www.juju.com/job/00000000g7gh4m ## About the Role Experience driving progress, solving problems, and mentoring more junior team members; deeper expertise and applied knowledge within relevant area., + Bachelor's degree in Computer Science, Information Systems, Cybersecurity, related technical field, or equivalent practical experience. + 3 years of experience with pen testing and red teaming functions, including network, web application, mobile, cloud, social engineering, scripting, or tool development. + Experience with tools used for wireless, web application, and network security testing or software/web development. + Ability to travel up to 30% of the time. Preferred qualifications: + Offensive security certifications including OSWE, BSCP, CWEE, OSCP or relevant SANS courses. + Experience in four or more of the following: application security, offensive security testing, developing applications, source code review, exploit development, network protocols, system and network administration. + Experience in security consulting. + Experience with bug bounty programs. + Experience with AI pen testing. ## Description As a Mandiant red team consulting team member, you will be responsible for assessing and advising clients on both technical and process-based controls for all manner of environments. You will perform red and purple team assessments, including adversarial emulation of cyber attacks against customer organizations, and other technical cyber assessments including external pen testing, web application, mobile, and wireless security testing. You will expand the team's capabilities through tool creation, research on offensive techniques, incorporation of threat actor intelligence, internal presentations, and knowledge sharing. Web application pen testing will be a majority of your work as you conduct offensive security assessments against our customers. As you conduct these assessments, you will be expected to exploit these vulnerabilities and show the full impact of the exploited vulnerabilities, you will be expected to report on these findings in great detail, collaborate on a team, and help others grow in their roles as well. Finally, you will assist Mandiant's global consulting arm by contributing to one or more areas of pen testing that will help everyone else become better. Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.Individual pay is determined by factors including job-related skills, experience, and relevant education or training. US: $112000 - $162000 (USD) + 15% bonus target + bonus + equity + benefits Learn more aboutbenefits at Google (https://www.google.com/about/careers/applications/benefits/) . Responsibilities + Perform a variety of assessments, including end-to-end adversarial emulation of cyber attacks against customer organizations, and other technical cyber assessments including external engagement, web application, mobile, and wireless security testing. + Expand the team's capabilities through tool creation, research on offensive techniques, incorporation of threat actor intelligence, internal engagement, and knowledge share. + Develop comprehensive and accurate reports and presentations for both technical and executive audiences, and act as a trusted advisor to chief executive-level, security leaders, and other customer stakeholders. + Assist with scoping prospective engagements, leading teams for engagements from kickoff through remediation phase, as well as mentoring other staff. + Demonstrate familiarity with offensive security, threat actors, and security best practices in general. Information collected and processed as part of your Google Careers profile, and any job applications you choose to submit is subject to Google'sApplicant and Candidate Privacy Policy (./privacy-policy) . Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See alsoGoogle's EEO Policy (https://www.google.com/about/careers/applications/eeo/) ,Know your rights: workplace discrimination is illegal (https://careers.google.com/jobs/dist/legal/EEOC\_KnowYourRights\_10\_20.pdf) ,Belonging at Google (https://about.google/belonging/) , andHow we hire (https://careers.google.com/how-we-hire/) . If you have a need that requires accommodation, please let us know by completing ourAccommodations for Applicants form (https://goo.gl/forms/aBt6Pu71i1kzpLHe2) . Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting. To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes. Equity is granted exclusively and discretionarily by Alphabet Inc. on the basis of an agreement concluded between you and Alphabet Inc. Alphabet Inc. is your sole contractual partner with respect to equity grants. GSU grants are not guaranteed, are discretionary, are subject to approval by the Alphabet Inc. board of directors or its delegate, the terms of the relevant Alphabet Inc. stock plan, and your grant agreement. They have no impact on statutory payments. Current or past grants do not confer an acquired right. ## Related Videos - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges)