Jobs · Georgia

Senior Strategic Security Consultant, Mandiant, Google Cloud

Google · Georgia, United States · 6 days ago
HybridFull-time

About the role

Note: Google's hybrid workplace includes remote and in-office roles. By applying to this position you will have an opportunity to share your preferred working location from the following: In-office locations: Atlanta, GA, USA. Remote location(s): Georgia, USA.

Responsibilities

  • Lead strategic security consulting engagements, maturity assessments, and gap analyses against industry frameworks (OWASP SAMM, BSIMM, NIST SSDF) to deliver risk-reduction roadmaps for cloud and on-premises environments.
  • Architect and secure Developer Security Operations pipelines by designing technical blueprints and integrating automated security gates (SAST, DAST, SCA) seamlessly into developer workflows.
  • Establish robust governance structures and facilitated risk-tiering workshops to define remediation service-level agreements, exception handling, and prioritization metrics (CVSS, EPSS) across multi-cloud and legacy infrastructure.
  • Support application threat modeling (STRIDE) and architect security reviews early in the Software Development Life Cycle (SDLC) to identify design flaws and provide engineering teams with strategies.
  • Pioneer application landscape discovery and Software Bill of Materials (SBOM) mapping to manage supply chain risks, while advising on the deployment of enterprise AppSec and Virtual Machine technologies (e.g., Qualys, Tenable, Snyk, Checkmarx).

Requirements

  • Bachelor's degree in Computer Science, Information Systems, Cyber-security, related technical field, or equivalent practical experience.
  • 5 years of experience assessing and developing cyber-security solutions and programs across security domains.
  • 5 years of experience in delivering cyber outcomes, identifying mission risks, and devising solutions.
  • Ability to travel up to 30% of the time as needed.

Preferred qualifications

  • Certifications related to specific cloud platforms.
  • Experience implementing industry-leading practices around cyber risks and cloud security for clients’ cloud security frameworks using industry standards.
  • Experience with cloud governance, with the ability to convey governance principles to cloud computing in terms of policies.
  • Experience deploying and maintaining security testing infrastructures (SAST, DAST, SCA, network/container vulnerability scanners) across hybrid ecosystems and multi-cloud environments.
  • Proficiency in the Open Web Application Security Project (OWASP) Top 10, Common Weakness Enumeration (CWE), Threat Modeling Methodologies, and integrating security controls into Agile and Developer Security Operation environments.

Benefits

Individual pay is determined by factors including job-related skills, experience, and relevant education or training. US: $138000 - $201000 (USD) + 15% bonus target + equity + benefits

Similar jobs