Google is seeking a Senior Security Engineer to enhance the safety of its operating environment for users and developers. The role involves working with network equipment to monitor systems for attacks, collaborating with software engineers to identify and rectify security vulnerabilities, and leading security operations for various platforms.
Responsibilities:
- Identify security issues and implement and design security controls, tools, and services to improve security systems and processes
- Create custom AI-driven detections and workflows. Lead the design of automated, AI-native offensive tools and simulation frameworks to identify vulnerabilities at scale
- Implement monitoring strategies, response plans, and awareness programs. Optimize SIEM, IDS/IPS, and core security tools
- Conduct ongoing threat hunts using intelligence. Perform forensic analysis and provide actionable post-incident guidance
- Embed best practices into the Software Development Life Cycle (SDLC), building automated evaluation pipelines and guardrails for secure code deployment
Requirements:
- Bachelor's degree or equivalent practical experience
- 5 years of experience with security assessments or security design reviews or threat modeling
- 5 years of experience with security engineering, computer and network security and security protocols
- 5 years of coding experience in one or more general purpose languages
- Must possess an active Top Secret/SCI security clearance with current polygraph
- Master's degree or PhD in Computer Science, Artificial Intelligence, Cybersecurity, or a related technical field
- Experience building, deploying, or evaluating AI-native solutions and generative AI technologies, including integrating LLMs or agentic workflows into complex operational environments
- Demonstrated experience in offensive security, red teaming, or advanced pen testing, with a strong ability to apply an attacker's mindset to infrastructure defense and defensive engineering
- Strong background in DevSecOps practices, including designing high-performance evaluation pipelines, building security automation, and integrating security controls directly into CI/CD workflows