Senior Security Engineer, Insider and Technology Risk
About the Job
Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
The Risk and Compliance Programs team is part of the Cloud CISO organization, driving high priority risk management efforts through formalized programs, including insider and technology risk. We are responsible for managing and creating consistent analysis, assessments, controls, and strategies to reduce insider and technology risk across Cloud. Our team is collaborative, innovative, and passionate about security.
Google Cloud accelerates every organization’s ability to digitally transform its business and industry. We deliver enterprise-grade solutions that leverage Google’s cutting-edge technology, and tools that help developers build more sustainably. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.US: $174000 - $253000 (USD) + 15% bonus target + equity + benefits
Learn more about benefits at Google.
Responsibilities
- Serve as a trusted advisor to Cloud leadership for guidance on insider risk-related questions, such as threat analysis and patterns, access controls, intellectual property protection, and detection and response.
- Evaluate the security and risk of complex, interconnected products, systems, and services, and drive mitigation and remediation efforts for systemic problems.
- Own parts of the security outlook and roadmap for your technical problem space. Apply engineering and technical best practices to design and implement controls, tools, or processes required to solve difficult security problems.
- Apply principles from information security and risk management domains (e.g., access management, detection and response, system resilience, vulnerability management) to protect systems and data.
- Work with engineering organizations to identify, develop, document, and test controls for design and operating effectiveness, in coordination with the Cloud CISO controls team.
Qualifications
Minimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 5 years of experience with security assessments or security design reviews or threat modeling.
- 5 years of experience with security engineering, computer and network security and security protocols.
- 5 years of coding experience in one or more general purpose languages.
- 1 year of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.
Preferred qualifications:
- 8 years of experience in engineering, cybersecurity, technology risk, or security-related roles.
- Experience with control frameworks, including risk assessment, compliance testing, monitoring, and governance.
- Proficiency in security engineering, cybersecurity principles, problem solving, and analytical/quantitative methods.
- Strong analytic capacity and technical understanding of cloud software development methodologies, architectures, and hardware, and networking concepts.
- Ability to have active community contributions designed to improve organizational culture and operations.
- Exceptional critical thinking and problem-solving skills, with the ability to connect technical or security details to broader risk implications.
Additional Information
In accordance with Washington state law, we are highlighting our comprehensive benefits package, which is available to all eligible US based employees. Benefits for this role include:- Health, dental, vision, life, disability insurance
- Retirement Benefits: 401(k) with company match
- Paid Time Off: 20 days of vacation per year, accruing at a rate of 6.15 hours per pay period for the first five years of employment
- Sick Time: 40 hours/year (increased to 69 hours/year for Seattle) including 5 discretionary sick days per instance
- Maternity Leave (Short-Term Disability + Baby Bonding): 28-30 weeks
- Baby Bonding Leave: 18 weeks
- Holidays: 13 paid days per year
Summary
Design and implement security controls, assess risks, and advise on insider threats.
Job title
Senior Security Engineer, Insider and Technology Risk
Experience level
5+ years
Minimum experience
5+ years exp
Industry
software
Location requirements
Remote work possible in US, mainly East and West coasts.
Salary
$174k–$253k
Management role
Yes
Required skills
Preferred skills
Specializations
Structured locations inferred from the posting.
United States
New York, NY, USA
Kirkland, WA, USA
Reston, VA, USA
Sunnyvale, CA, USA