Security Engineer, Platforms and Devices
Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
Counter Abuse, Detection, and Response Workgroup.
This is a focused role for security engineers who care about protecting the user and are familiar with Blue Team activities. This role requires periodic on-call rotation work as part of the larger Detection, Signal, Analysis, and Protection incident management program.
We aim to help Platforms and Devices (P&D) deliver trustworthy products and services by analyzing abuse or exploitation vectors that haven’t been discovered yet and either remediating the problem or devising new detections that trigger on an attacker’s behavior. This requires analyzing large datasets, both manually and with tooling, to deliver the most impact for the product area.
Additionally, the role conducts regular design and architecture reviews to confirm that we launch with the most secure services possible for the customer. Identifying and addressing security issues in this type of stack requires not only strong technical expertise as a security engineer, but also the ability to partner with cross-functional engineering and product teams to reduce overall security risk.
In this role, you will grow into a counter abuse security subject matter expert and directly improve the security of fundamental building blocks, software services, and tools across Platforms and Devices.
US: $123000 - $174000 (USD) + 15% bonus target + equity + benefits
Learn more about benefits at Google.
Responsibilities
- Conduct reviews of infrastructure and service designs through the lens of information security, which will vary between 25-65% of working time week-to-week.
- Recommend changes to designs to account for future security concerns regarding access, abuse, and logging.
- Participate in incident investigation of logs to measure impact or find/hunt for indicators of compromise.
- Develop, test, and deploy new strategies for detecting abuse of P&D services like Fitbit, Nest, Android Enterprise, Fi, and more.
Minimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 1 year of experience with security assessments or security design reviews or threat modeling.
- 1 year of coding experience in one or more general purpose languages.
- Experience with security engineering, computer and network security and security protocols.
Preferred qualifications:
- 2 years of experience querying and analyzing Terabyte-scale data sets in SQL.
- 2 years of experience working with highly-available, cloud-based infrastructure.
- Proficient in Linux shell scripting.