Senior Strategic Security Consultant, Mandiant, Google Cloud
About the Job
As a Mandiant Strategic Security Consultant, you will lead and support projects on behalf of clients that assess, test, or build their security programs. Project teams may range from 2 to 5 colleagues. Clients will range from start-up companies looking to supplement their security team to Fortune 100 companies that need fresh ideas to enhance their perspective on the security program. You will provide guidance and advice to our client on best practices and managing the risks for their security program.
US: $138000 - $201000 (USD) + 15% bonus target + equity + benefits
Learn more about benefits at Google.
Responsibilities
- Lead strategic security consulting engagements, maturity assessments, and gap analyses against industry frameworks (OWASP SAMM, BSIMM, NIST SSDF) to deliver risk-reduction roadmaps for cloud and on-premises environments.
- Architect and secure Developer Security Operations pipelines by designing technical blueprints and integrating automated security gates (SAST, DAST, SCA) seamlessly into developer workflows.
- Establish robust governance structures and facilitated risk-tiering workshops to define remediation service-level agreements, exception handling, and prioritization metrics (CVSS, EPSS) across multi-cloud and legacy infrastructure.
- Support application threat modeling (STRIDE) and architect security reviews early in the Software Development Life Cycle (SDLC) to identify design flaws and provide engineering teams with strategies.
- Pioneer application landscape discovery and Software Bill of Materials (SBOM) mapping to manage supply chain risks, while advising on the deployment of enterprise AppSec and Virtual Machine technologies (e.g., Qualys, Tenable, Snyk, Checkmarx).
Qualifications
Minimum qualifications:
- Bachelor's degree in Computer Science, Information Systems, Cyber-security, related technical field, or equivalent practical experience.
- 5 years of experience assessing and developing cyber-security solutions and programs across security domains.
- 5 years of experience in delivering cyber outcomes, identifying mission risks, and devising solutions.
- Ability to travel up to 30% of the time as needed.
Preferred qualifications:
- Certifications related to specific cloud platforms.
- Experience implementing industry-leading practices around cyber risks and cloud security for clients’ cloud security frameworks using industry standards.
- Experience with cloud governance, with the ability to convey governance principles to cloud computing in terms of policies.
- Experience deploying and maintaining security testing infrastructures (SAST, DAST, SCA, network/container vulnerability scanners) across hybrid ecosystems and multi-cloud environments.
- Proficiency in the Open Web Application Security Project (OWASP) Top 10, Common Weakness Enumeration (CWE), Threat Modeling Methodologies, and integrating security controls into Agile and Developer Security Operation environments.
Summary
Lead security consulting projects, assess risks, design secure architectures, and advise clients.
Job title
Senior Strategic Security Consultant
Experience level
5+ years
Minimum experience
5+ years exp
Industry
cybersecurity
Location requirements
On-site in Atlanta, GA, USA;Remote work allowed.
Salary
$138k–$201k
Management role
No
Required skills
Preferred skills
Specializations
Structured locations inferred from the posting.
Atlanta, GA, USA
Georgia, VT, USA