Senior Security Engineer, Exploits, Google Threat Intelligence Group
Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
Join the Google Threat Intelligence Group's (GTIG) Exploits Mission. The Exploits Mission focuses on protecting users from targeted exploitation, primarily from government-backed attackers and Commercial Surveillance Vendors (CSVs), through the detection, analysis, and ultimate prevention of vulnerabilities and exploits, with a special focus on 0-day attacks.
We provide timely, actionable intelligence and coordinate with internal and external partners to fix critical vulnerabilities and secure user devices.
As a Security Engineer on our team, you will conduct in-depth research on threat groups, their Tactics, Techniques, and Procedures (TTPs), and the malware they employ. You'll utilize Google's powerful internal intelligence platforms, Nirvana and mGraph, to model threat activity and generate actionable insights. This role involves close collaboration with various teams across GTIG and Google to develop and implement effective countermeasures, contributing directly to threat disruption and enhancing our collective security posture. We are looking for engineers passionate about threat research who can lead projects and mentor others.
Responsibilities
- Lead complex technical analyses, modeling threat activity, TTPs, and Indicators of Compromise (IOCs) across internal platforms (mGraph, Nirvana).
- Create and deploy detection signatures (autoqueries, Watchtower rules) to maintain visibility over threat actors and assist in closing security gaps.
- Produce polished, high-quality technical intelligence documentation and actor profiles to deliver actionable insights to internal and external stakeholders.
- Influence technical direction within your scope, mentor junior engineers, and collaborate with cross-functional Google teams to support threat disruption efforts. Collaborate with security engineers and product teams in designing innovative exploit mitigations.
- Identify and execute opportunities for continuous improvement: analytic collection, process optimization, and automation.
Minimum qualifications:
- Bachelor's degree in Computer Science, Cybersecurity, a related field, or equivalent practical experience.
- 5 years of experience in threat intelligence, intrusion analysis, vulnerability researcher, or a similar security role.
- Experience with threat intelligence platforms and tools (e.g., VirusTotal, SIEMs).
Preferred qualifications:
- Knowledge of Android and Chrome security and internals.
- Deep understanding of attacker Tactics, Techniques, and Procedures (TTPs).
- Proven ability to lead complex threat research projects independently.
- Strong analytical, problem-solving, and communication skills.
- Skills in malware analysis, reverse engineering, or vulnerability analysis.
- Proficiency in scripting or querying languages (e.g., Python, GoogleSQL).