Jobs · Engineering · California

Senior Information Security Engineer, Product Security Engineering

Google · Sunnyvale, CA · 2 mo ago
On-siteEngineeringFull-time

About the role

There's no such thing as a "safe system" - only safer systems. Our Security team works to create and maintain the safest operating environment for Google's users and developers. As a Security Engineer, you help protect network boundaries, keep computer systems and network devices hardened against attacks and provide security services to protect highly sensitive data like passwords and customer information. Security Engineers work directly with network equipment and actively monitor our systems for attacks and intrusions. You also work with software engineers to proactively identify and fix security flaws and vulnerabilities. You use your industry experience to own and drive the resolution of complex security incidents, policy questions and technical security issues. In this role, you will help set the focus, direction and impact of this organization with regards to product security.

Responsibilities

  • Identify security issues and implement and design security controls, tools, and services to improve security systems and processes.
  • Perform security reviews, research and reproduce vulnerabilities, design secure protocols and systems, and write tests and fuzzers.
  • Look for vulnerabilities with techniques including reverse engineering, fuzzing, and static analysis.
  • Review and develop secure operational practices, and provide security guidance for engineers and support staff.
  • Review designs and drive towards defense in depth and security by default, both with one-time reviews and longer term engagements.
  • Respond to vulnerabilities with repros, variant analysis, mitigations, and hardening.
  • Focus on the security strategy for Google Cloud.

Requirements

  • Bachelor's degree or equivalent practical experience.
  • 5 years of experience with security engineering, computer and network security and security protocols.
  • 5 years of experience with security assessments or security design reviews or threat modeling.
  • 5 years of coding experience in one or more general purpose languages.
  • 1 year of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.
  • Coding experience in one or more general purpose languages.

Qualifications

  • Experience identifying and mitigating network security risks using threat modeling and other risk identification techniques.
  • Experience in applications security, cryptography, network security or systems security.
  • Experience with C++ dynamic analysis and static code analysis.
  • Expertise in in security assessments, vulnerability management and security research.

Skills

  • Strong understanding of security principles and practices.
  • Ability to analyze and debug complex security issues.
  • Excellent communication and collaboration skills.
  • Proficiency in one or more programming languages.

Benefits

  • Health, dental, vision, life, disability insurance.
  • Retirement Benefits: 401(k) with company match.
  • Paid Time Off: 20 days of vacation per year, accruing at a rate of 6.15 hours per pay period for the first five years of employment.
  • Sick Time: 40 hours/year (increased to 69 hours/year for Seattle) including 5 discretionary sick days per instance.
  • Maternity Leave (Short-Term Disability + Baby Bonding): 28-30 weeks.
  • Baby Bonding Leave: 18 weeks.
  • Holidays: 13 paid days per year.

Pay

US: $174,000 - $253,000 (USD) + 15% bonus target + equity + benefits

Schedule

Full-time

Similar jobs