Security Engineer, Information Security Engineering
About the job
The Information Security Engineering (ISE) team is dedicated to safeguarding Google's products and the data of billions of users.
A key component of this effort is the Product Security Review team, which collaborates with engineering teams throughout Google to perform comprehensive security assessments at every stage of the product lifecycle. These assessments prioritize finding and exploiting security vulnerabilities, from subtle design flaws to implementation bugs. Through these engagements, ISE advocates security best practices and advocates for products that are secure by design.
In this role you will not only apply your security expertise but will also actively develop and enhance a suite of custom tools to scale security assessments. Your role will extend beyond just finding vulnerabilities; it will include providing guidance on secure design principles and best practices, empowering teams to build more resilient systems from the ground up.
Responsibilities
- Analyze systems to uncover high-impact vulnerabilities and pinpoint opportunities for hardening, reporting findings to stakeholders for mitigation.
- Develop specialized tools for security engineers to expand vulnerability identification and enhance the security posture of Google products, including AI agents.
- Promote quality security practices across the organization, influencing software engineers, immediate colleagues, and beyond Google.
- Perform rapid threat modeling of systems to quickly determine areas that warrant further investigation and security review.
Minimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 2 years of experience in security assessment.
- Experience in software engineering.
- Experience within a security field (e.g. AI, Web, Mobile).
Preferred qualifications:
- Experience building or deploying automated tools (e.g., Large Language Models (LLMs)-based agents) for security workflows such vulnerability discovery or threat modeling.
- Experience driving security improvements and collaborating with product teams to remediate widespread technical issues.