Minimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 5 years of coding experience in one or more general purpose languages.
- 5 years of experience with security assessments, security design reviews, or threat modeling.
- 5 years of experience with security engineering, computer and network security, and security protocols.
- 1 year of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.
Preferred qualifications:
- 4 years of experience in data analysis, hazard assessment, risk and fraud investigation, security vulnerabilities, or ethical hacking.
- Ability to comprehend and review code in one or more general purpose languages.
- Excellent communication skills, with the ability to influence others.
Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
As a Senior Information Security Engineer, you will help to ensure that our software and systems are designed and implemented to the highest security standards. You will perform technical security assessments, code reviews and vulnerability testing to highlight risk, helping Google teams and partners to improve security, and work on a wide variety of software designs and technology stacks.
Google Cloud accelerates every organization’s ability to digitally transform its business and industry. We deliver enterprise-grade solutions that leverage Google’s cutting-edge technology, and tools that help developers build more sustainably. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.
- Identify security issues and implement and design security controls, tools, and services to improve security systems and processes.
- Perform security reviews, research and reproduce vulnerabilities, design secure protocols and systems, and write tests and fuzzers.
- Review and develop secure operational practices, and provide security guidance for engineers and support staff.
- Review designs and look for vulnerabilities, both with one-time reviews and longer term engagements, surface vulnerability patterns, and design them out.
- Look for vulnerabilities with techniques including reverse engineering, fuzzing, and static analysis. Respond to vulnerabilities with repos, mitigations, and hardening.