Senior Information Security Engineer, Product Security Engineering, Cloud
Company: Google
Google’s mission is to organize the world's information and make it universally accessible and useful.
Minimum Qualifications:
* Bachelor's degree or equivalent practical experience.
* 5 years of coding experience in one or more general purpose languages.
* 5 years of experience with security assessments, security design reviews, or threat modeling.
* 5 years of experience with security engineering, computer and network security, and security protocols.
* 1 year of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.
Preferred Qualifications:
* 4 years of experience in data analysis, hazard assessment, risk and fraud investigation, security vulnerabilities, or ethical hacking.
* Ability to comprehend and review code in one or more general purpose languages.
* Excellent communication skills, with the ability to influence others.
About the Job
Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
Product Security Engineering is the team within the Cloud CISO organization responsible for helping ensure every product Cloud ships is as secure as it can be and increasing the assurance levels of security in the infrastructure underlying all our products. This team will also focus on increasing the capabilities of each product team to develop more secure products by design and by default, from patterns, tools and frameworks to increasing the skill level of embedded security leads. As a Senior Information Security Engineer, you will help to ensure that our software and systems are designed and implemented to the highest security standards. You will perform technical security assessments, code reviews and vulnerability testing to highlight risk, helping Google teams and partners to improve security, and work on a wide variety of software designs and technology stacks.
Responsibilities
* Identify security issues and implement and design security controls, tools, and services to improve security systems and processes.
* Perform security reviews, research and reproduce vulnerabilities, design secure protocols and systems, and write tests and fuzzers.
* Review and develop secure operational practices, and provide security guidance for engineers and support staff.
* Review designs and look for vulnerabilities, both with one-time reviews and longer term engagements, surface vulnerability patterns, and design them out.
* Look for vulnerabilities with techniques including reverse engineering, fuzzing, and static analysis. Respond to vulnerabilities with repos, mitigations, and hardening.
#J-18808-Ljbffr