Senior Information Security Engineer, Cloud CISO, Vulnerability Rewards Program
- Location
- Sunnyvale, CA, USA
- Work model
- On-Site
- Level
- Senior
- Salary
- $174k – $252k/yr
- H-1B history
- 2,460 approvals (FY2023)
- Posted
- 2h ago
Skills
About this role
There's no such thing as a "safe system" - only safer systems. Our Security team works to create and maintain the safest operating environment for Google's users and developers. As a Security Engineer, you help protect network boundaries, keep computer systems and network devices hardened against attacks and provide security services to protect highly sensitive data like passwords and customer information. Security Engineers work directly with network equipment and actively monitor our systems for attacks and intrusions. You also work with software engineers to proactively identify and fix security flaws and vulnerabilities. You use your industry experience to own and drive the resolution of complex security incidents, policy questions and technical security issues. Google Cloud Security Engineering within the Cloud CISO organization is responsible for ensuring every product Cloud ships securely and for increasing the assurance levels of security in the infrastructure underlying all our products. As an Information Security Engineer, you will help design and implement software and systems to the highest security standards. You will work with external security researchers from the Google Cloud Vulnerability Rewards Program (Cloud VRP) and perform technical security assessments, code reviews and vulnerability testing to highlight risk, helping Google teams and partners to improve security, and work on a wide variety of Cloud products, software designs, and technology stacks. Google Cloud accelerates every organization’s ability to digitally transform its business and industry. We deliver enterprise-grade solutions that leverage Google’s cutting-edge technology, and tools that help developers build more sustainably. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems. Individual pay is determined by factors including job-related skills, experience, and relevant education or training. US: $174000 - $252000 (USD) + 15% bonus target + equity + benefits Learn more about benefits at Google .
Conduct security assessments of Cloud security and vulnerability reports to assess risk and impact and ensure prompt and proper mitigations with key stakeholders. Manage multiple cross-functional efforts and escalations simultaneously with engaged priorities. Solve complex technical problems that involve independent but interconnected components. Serve as the go-to person for broad security domains and understand the interplay of threats between systems and services. Build and maintain strong relationships with stakeholders across Google, including legal, engineering, and communications teams. Investigate impact to Google Cloud and its customers to determine if new detection or compromise notifications are necessary. Demonstrate consistent ability to drive positive change in alignment with business objectives, and collaborate with teams to uplift overarching security capabilities. Demonstrate exceptional judgment in balancing security and business needs in owned areas, considering both risk and impact.
Minimum qualifications: Bachelor's degree or equivalent practical experience. 5 years of experience with security engineering, computer and network security and security protocols. 5 years of experience with security assessments, security design reviews, or threat modeling. 5 years of coding experience in one or more general purpose languages. 1 year of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment. Preferred qualifications: 8 years of experience with vulnerability identification, assessment, and management. Technical background with experience in security operations, systems administration, digital forensics, security engineering, vulnerability assessments, etc. Ability to demonstrate composure and level-headedness during security