yoinka

Senior Strategic AppSec Consultant, Mandiant, Google Cloud

Google

New York, NY, USA; Atlanta, GA, USA; Cambridge, MA, USA; Reston, VA, USASenior$138k – $200k/yrH-1B sponsor company
Sign in to applyVerified 1h ago
Location
New York, NY, USA; Atlanta, GA, USA; Cambridge, MA, USA; Reston, VA, USA
Work model
On-Site
Level
Senior
Salary
$138k – $200k/yr
H-1B history
2,460 approvals (FY2023)
Posted
1h ago

Skills

AgileCybersecurityGCPGenAIMLOps

About this role

As a Senior Strategic AppSec Consultant, you will lead consulting engagements and deliver results that align with the client's needs and risk profiles, with a specific focus on Application Security (AppSec) and Vulnerability Management. You will develop roadmaps, recommendations, and business strategies to drive enhancements in secure software development lifecycles (SDLC) and comprehensive vulnerability management programs. Your role involves developing policies, procedures, and standards in line with industry best practices, as well as implementing continuous security testing strategies across cloud and on-premises environments. You will identify and articulate AppSec best practices—such as Threat Modeling, DevSecOps integration, and Secure Coding—while identifying performance enhancement opportunities for Vulnerability Management programs. Furthermore, you will work closely with clients to implement, maintain, and optimize solutions across various platforms and collaborate with cross-functional teams to develop effective cybersecurity controls and measures with a specific focus on Application Security (AppSec), Vulnerability Management, and the secure adoption of Artificial Intelligence (AI) platforms. Your role involves developing policies, procedures, and standards in line with industry best practices (such as the NIST AI RMF), as well as implementing continuous security testing strategies. Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone. Individual pay is determined by factors including job-related skills, experience, and relevant education or training. US: $138000 - $200000 (USD) + 15% bonus target + equity + benefits Learn more about benefits at Google .

Lead security engagements and establish Vulnerability Management governance, remediation SLAs, and continuous scanning strategies. Architect secure DevSecOps pipelines by seamlessly integrating SAST, DAST, and SCA tooling, and map application landscapes to address supply chain risks. Facilitate advanced AI/ML threat modeling (e.g., OWASP Top 10 for LLMs) to secure generative AI deployments, MLOps pipelines, and autonomous agents. Conduct comprehensive architecture security reviews and gap analyses to mitigate risks during digital transformations and define metrics for risk reduction. Collaborate with engineering teams to advise on enterprise vulnerability scanners, implement actionable mitigation strategies, and evaluate AI-driven security tooling.

Minimum qualifications: Bachelor's degree in Computer Science, Information Systems, Cybersecurity, a related technical field, or equivalent practical experience. 5 years of experience assessing and developing application security (AppSec) programs and vulnerability management architectures. 5 years of experience in the delivery of cyber outcomes, identification of mission risks, and development of solutions. Ability to travel up to 30% of the time. Preferred qualifications: Experience in communicating strategic roadmaps to stakeholders. Experience in vulnerability management, architect governance structures, remediation SLAs, and risk prioritization workflows. Familiarity of DevSecOps and infrastructure, and deploying and maintaining security testing (SAST/DAST/SCA) across hybrid and multi-cloud ecosystems. Familiarity in AI/ML security of GenAI workloads, MLSecOps, and autonomous agents utilizing emerging AI frameworks and testing tools. Knowledge in threat modeling, and applying OWASP Top 10 and CWE

Listing verified 1h ago. Applications go through the company's official careers site.

← Back to Yoinka

Senior Strategic AppSec Consultant, Mandiant, Google Cloud at Google, New York, NY, USA; Atlanta, GA, USA; Cambridge, MA, USA; Reston, VA, USA | Yoinka