Senior Security Engineer, Exploits, Google Threat Intelligence Group
Job Description
Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
As a Security Engineer on our team, you will conduct in-depth research on risk groups, their tactics, techniques, and procedures (TTPs), and the malware they employ. You will utilize internal intelligence platforms to model risk activity and generate insights. This role involves close collaboration with various security teams across Google to develop and implement effective countermeasures, contributing directly to risk disruption and enhancing our collective security posture. You will lead projects, mentor others, and apply your passion for security research. Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.
US: $174000 - $252000 (USD) + 15% bonus target + equity + benefits
Learn more about benefits at Google. Responsibilities
- Own, prioritize, and drive the tracking of complex, threat actors and associated research projects.
- Lead complex technical analyses, modeling threat activity, tactics, techniques, and procedures (TTPs), and indicators of compromise (IOCs) across internal platforms (mGraph).
- Create and deploy detection signatures (autoqueries, Watchtower rules) to maintain visibility over threat actors and assist in closing security gaps.
- Produce polished, high-quality technical intelligence documentation and actor profiles to deliver actionable insights to internal and external stakeholders.
- Influence technical direction within your scope, mentor junior engineers, and collaborate with cross-functional Google teams to support threat disruption efforts. Collaborate with security engineers and product teams in designing innovative exploit mitigations.
Qualifications Minimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 5 years of experience with security assessments or security design reviews or threat modeling.
- 5 years of experience with security engineering, computer and network security and security protocols.
- 5 years of coding experience in one or more general purpose languages.
- 1 year of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.
Preferred qualifications:
- Experience with threat intelligence platforms and tools (e.g., VirusTotal, SIEMs).
- Proficiency in analyzing and correlating data from sources to track threat activity.
- Knowledge of Android and Chrome security and internals.
- Proven ability to lead complex threat research projects independently.
- Skills in malware analysis, reverse engineering, or vulnerability analysis.