Skip to content
mimi

Staff Security Engineer, Product Security Engineering

Google

Raleigh · On-site Full-time $207k – $300k/yr Today

About the role

In accordance with Washington state law, we are highlighting our comprehensive benefits package, which is available to all eligible US based employees. Benefits for this role include:

• Health, dental, vision, life, disability insurance

• Retirement Benefits: 401(k) with company match

• Paid Time Off: 20 days of vacation per year, accruing at a rate of 6.15 hours per pay period for the first five years of employment

• Sick Time: 40 hours/year (statutory, where applicable); 5 days/event (discretionary)

• Maternity Leave (Short-Term Disability + Baby Bonding): 28-30 weeks

• Baby Bonding Leave: 18 weeks

• Holidays: 13 paid days per year.

Note: By applying to this position you will have an opportunity to share your preferred working location from the following: New York, NY, USA; Kirkland, WA, USA; Raleigh, NC, USA; Durham, NC, USA. Minimum qualifications:

• Bachelor's degree or equivalent practical experience.

• 8 years of experience with security assessments or security design reviews or threat modeling.

• 8 years of experience with security engineering, computer and network security and security protocols.

• 8 years of coding experience in one or more general purpose languages.

• 3 years of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.

Preferred qualifications:

• 5 years of experience in Network Security (i.e., network protocols, software-defined networking (SDN), Internet Engineering Task Force (IETF), firewalls, or DNS security).

• 5 years of experience in security testing and pen-testing.

• Ability to consult and influence stakeholders.

About the job

There's no such thing as a "safe system" - only safer systems. Our Security team works to create and maintain the safest operating environment for Google's users and developers. As a Security Engineer, you help protect network boundaries, keep computer systems and network devices hardened against attacks and provide security services to protect highly sensitive data like passwords and customer information. Security Engineers work directly with network equipment and actively monitor our systems for attacks and intrusions. You also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

You use your industry experience to own and drive the resolution of complex security incidents, policy questions and technical security issues.

The Cloud CISO Security Engineering team within the Cloud CISO organization is responsible for helping ensure every product that Cloud ships is as secure as it can be and increasing the assurance levels of security in the infrastructure underlying all our products. This team also focuses on increasing the capabilities of each product team to develop more secure products by design and by default, from patterns, tools and frameworks to increasing the skill level of embedded security leads. As an information security engineer you will help to ensure that our software and systems are designed and implemented to the highest security standards. You will perform technical security assessments, code reviews, and vulnerability testing to highlight risk, helping Google teams and partners to improve security, and work on a wide variety of software designs and technology stacks. Google Cloud accelerates every organization’s ability to digitally transform its business and industry. We deliver enterprise-grade solutions that leverage Google’s cutting-edge technology, and tools that help developers build more sustainably. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.

The US base salary range for this full-time position is $207,000-$300,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.

Responsibilities

• Architect secure operational protocols and distributed systems from inception, embedding threat modeling and defensive design principles into the core engineering lifecycle.

• Lead comprehensive security design reviews for business-critical infrastructure, balancing deep-dive tactical assessments with long-term strategic engineering engagements.

• Review designs for vulnerabilities, both with one-time reviews and longer term engagements, using techniques including reverse engineering, fuzzing, and static analysis.

• Scale solutions and influence cross-organizationally.

• Respond to vulnerabilities with repos, mitigations, and hardening. Surface vulnerability patterns and design them out.

Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Google's EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our Accommodations for Applicants form.

Don't send a generic resume

Paste this job description into Mimi and get a resume tailored to exactly what the hiring team is looking for.

Get started free