Technical Program Manager, Technology Cyber Security
A problem isn’t truly solved until it’s solved for all. That’s why Googlers build products that help create opportunities for everyone, whether down the street or across the globe. As a Technical Program Manager at Google, you’ll use your technical expertise to lead complex, multi-disciplinary projects from start to finish. You’ll work with stakeholders to plan requirements, identify risks, manage project schedules, and communicate clearly with cross-functional partners across the company. You're equally comfortable explaining your team's analyses and recommendations to executives as you are discussing the technical tradeoffs in product development with engineers.
The Compliance, Security, and Risk Management (CSRM) team is dedicated to delivering the safest and most resilient technical infrastructure in the world. As a Technical Program Manager for operational technology (OT) cyber security, you will lead the charge in protecting the assets that support Google's data centers. You will be responsible for the risk and compliance aspects of OT, including building management systems (BMS) and power monitoring systems (PMS). By collaborating with 24x7 operations, data center technical services (DCTS), and data center operations, you will identify enterprise risks and develop industry-leading programs that integrate safety and security into the creative process, ensuring our program elements align with the business risk appetite.
Behind everything our users see online is the architecture built by the Technical Infrastructure team to keep it running. From developing and maintaining our data centers to building the next generation of Google platforms, we make Google's product portfolio possible. We're proud to be our engineers' engineers and love voiding warranties by taking things apart so we can rebuild them. We keep our networks up and running, ensuring our users have the best and fastest experience possible.
The US base salary range for this full-time position is $156,000-$229,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.
Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.
Responsibilities
- Oversee the risk and compliance aspects of data center operational technology (OT) cyber security, specifically covering building management systems (BMS), power monitoring systems (PMS), and the associated networking equipment they communicate with.
- Lead a comprehensive program to quantify and reduce cyber risks to data center systems, ensuring alignment with business risk appetite and facilitating decision-making for business leaders.
- Liaison effectively across 24x7 operations, DCTS, and DC operations to drive sustainable program effectiveness and ensure security strategies are integrated into daily operations.
- Analyze security data to identify trends, manage vulnerability assessments and threat modeling, and utilize threat detection solutions to maintain a robust security posture.
Minimum qualifications:
- Bachelor's degree in a technical field or equivalent practical experience.
- 5 years of experience utilizing cyber security risk frameworks (e.g., NIST CSF) and conducting risk assessments.
- 5 years of experience in technical program management, cyber security, risk management, with data center operational technology (OT), specifically regarding building management systems (BMS) and power monitoring systems (PMS).
- 5 years of experience with networking systems and the security issues of OT environments, including ICS, SCADA, and real-time controls.
Preferred qualifications:
- 10 years of experience with security systems, critical infrastructure protection, or a related field.
- Experience creating business and product requirements documents (BRD & PRD) and defining success metrics for technical programs.
- Knowledge of emerging cyber security system technologies, trends, and vulnerability management processes (including threat modeling and remediation).
- Understanding of Tier-1 OT security vendor platforms, network visibility tools, and threat detection solutions.
- Excellent program management skills with an ability to influence cross-functional teams without direct authority.