Google logo

Staff Security Engineer, Product Security Engineering, Cloud CISO

Google

WAJob$207–300K/yrPosted 1mo agoStill listed today

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$207–300K/yr
Location
WA
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

The Staff Security Engineer will help ensure Google Cloud products and underlying infrastructure meet high security standards. The role performs technical security assessments, code reviews, and vulnerability testing across varied software designs and technology stacks, while helping teams improve security. It also focuses on scalable security strategy and strengthening product teams’ ability to build secure products by design and default.

Skills & qualifications

RequiredNice to have

Skills

Security EngineeringThreat ModelingNetwork SecurityPeople ManagementVulnerability ScanningReverse EngineeringFuzz TestingSecurity AssessmentsSecurity Design ReviewsComputer SecuritySecurity ProtocolsCodingTeam LeadershipTechnical Risk AnalysisAI/ML SecurityCross-Functional InfluenceExecutive Stakeholder EngagementCommunicationInitiativeRelationship Building

Qualifications

Bachelor's Degree or Equivalent Practical Experience8 Years Security Assessments or Design Reviews or Threat Modeling8 Years Security Engineering, Computer and Network Security, and Protocols5 Years Coding Experience3 Years Technical Team Leadership or Enterprise Risk AnalysisEnglish Proficiency

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
401(k) Match
Paid Time Off
Parental Leave

Full job description

Staff Security Engineer, Product Security Engineering, Cloud CISO

  • linkCopy link
  • emailEmail a friend

corporate_fareGoogleplaceNew York, NY, USA; Kirkland, WA, USA Advanced Experience owning outcomes and decision making, solving ambiguous problems and influencing stakeholders; deep expertise in domain.

Apply

  • linkCopy link
  • emailEmail a friend

info_outline XIn accordance with Washington state law, we are highlighting our comprehensive benefits package, which is available to all eligible US based employees. Benefits for this role include:

  • Health, dental, vision, life, disability insurance
  • Retirement Benefits: 401(k) with company match
  • Paid Time Off: 20 days of vacation per year, accruing at a rate of 6.15 hours per pay period for the first five years of employment
  • Sick Time: 40 hours/year (increased to 69 hours/year for Seattle) including 5 discretionary sick days per instance
  • Maternity Leave (Short-Term Disability + Baby Bonding): 28-30 weeks
  • Baby Bonding Leave: 18 weeks
  • Holidays: 13 paid days per year

Note: By applying to this position you will have an opportunity to share your preferred working location from the following: New York, NY, USA; Kirkland, WA, USA.

Minimum qualifications:

  • Bachelor's degree or equivalent practical experience.

  • 8 years of experience with security assessments or security design reviews or threat modeling.

  • 8 years of experience with security engineering, computer and network security and security protocols.

  • 5 years of coding experience in one or more general purpose languages.

  • 3 years of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.

Preferred qualifications:

  • Experience applying AI/ML to solve complex security problems.
  • Ability to influence and engage with cross-functional teams and executive stakeholders, driving alignment and achieving results.
  • Exceptional communication and people management skills with proven ability to take initiative and build strong, productive relationships externally and internally.

About the job There's no such thing as a "safe system" - only safer systems. Our Security team works to create and maintain the safest operating environment for Google's users and developers. As a Security Engineer, you help protect network boundaries, keep computer systems and network devices hardened against attacks and provide security services to protect highly sensitive data like passwords and customer information. Security Engineers work directly with network equipment and actively monitor our systems for attacks and intrusions. You also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

You use your industry experience to own and drive the resolution of complex security incidents, policy questions and technical security issues. The Cloud CISO Security Engineering team within the Cloud CISO organization is responsible for helping ensure every product that Cloud ships is as secure as it can be and increasing the assurance levels of security in the infrastructure underlying all our products. This team also focuses on increasing the capabilities of each product team to develop more secure products by design and by default, from patterns, tools and frameworks to increasing the skill level of embedded security leads. In this role, you will help to ensure that our software and systems are designed and implemented to the highest security standards. You will perform technical security assessments, code reviews, and vulnerability testing to highlight risk, helping Google teams and partners to improve security, and work on a wide variety of software designs and technology stacks. Google Cloud accelerates every organization’s ability to digitally transform its business and industry. We deliver enterprise-grade solutions that leverage Google’s cutting-edge technology, and tools that help developers build more sustainably. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

US: $207000 - $300000 (USD) + 20% bonus target + equity + benefits

Learn more about benefits at Google. Responsibilities

  • Perform security reviews, research and reproduce vulnerabilities, design secure protocols and systems, and write tests and fuzzers.
  • Review and develop secure operational practices, and provide security guidance for engineers and support staff.
  • Review designs and look for vulnerabilities, both with one-time reviews and longer term engagements. Look for vulnerabilities with techniques including reverse engineering, fuzzing, and static analysis.
  • Respond to vulnerabilities with repos, mitigations, and hardening. Surface vulnerability patterns and design them out.
  • Focus on the security strategy for Google Cloud and scalable solutions, and the ability to influence cross-organizationally.

Information collected and processed as part of your Google Careers profile, and any job applications you choose to submit is subject to Google's Applicant and Candidate Privacy Policy. Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See also Google's EEO Policy, Know your rights: workplace discrimination is illegal, Belonging at Google, and How we hire. If you have a need that requires accommodation, please let us know by completing our Accommodations for Applicants form. Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting. To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes. Equity is granted exclusively and discretionarily by Alphabet Inc. on the basis of an agreement concluded between you and Alphabet Inc. Alphabet Inc. is your sole contractual partner with respect to equity grants. GSU grants are not guaranteed, are discretionary, are subject to approval by the Alphabet Inc. board of directors or its delegate, the terms of the relevant Alphabet Inc. stock plan, and your grant agreement. They have no impact on statutory payments. Current or past grants do not confer an acquired right.

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.