Minimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 8 years of experience with security assessments or security design reviews or threat modeling.
- 8 years of coding experience in one or more general purpose languages.
- 8 years of experience with security engineering, computer and network security, and security protocols.
- 3 years of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.
- Experience with hardware and firmware security.
- Experience with reverse engineering.
About the job
There's no such thing as a "safe system" - only safer systems. Our Security team works to create and maintain the safest operating environment for Google's users and developers. As a Security Engineer, you help protect network boundaries, keep computer systems and network devices hardened against attacks and provide security services to protect highly sensitive data like passwords and customer information. Security Engineers work directly with network equipment and actively monitor our systems for attacks and intrusions. You also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
Want more jobs like this?
Get jobs in Reston, VA delivered to your inbox every week.
You are a recognized expert in at least two security domains and use your leadership skills to manage a team that sets the direction and goals for solving Google-wide problems. You identify fundamental security problems at Google and drives major security improvements in Google infrastructure.
The Product Security Engineering (PSE) team within the Cloud CISO organization is responsible for helping ensure every product Cloud ships is as secure as it can be, and for increasing the assurance levels of security in the infrastructure underlying all Cloud products including hardware/firmware.
The Off-The-Shelf Hardware Security team within PSE specializes on the hardware underpinning Cloud products. The team's mission is to protect the world's devices against all hardware and firmware security threats.
The team engages and collaborates with external vendors, internal teams, and industry bodies to ensure that the hardware and firmware used within Google Cloud products provide protection to customers and end users.
Google Cloud accelerates every organization's ability to digitally transform its business and industry. We deliver enterprise-grade solutions that leverage Google's cutting-edge technology, and tools that help developers build more sustainably. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.
The US base salary range for this full-time position is $189,000-$284,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.
Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google .
Responsibilities
- Manage a team of Security Engineers.
Scope out and identify business critical hardware/firmware devices within Cloud for team review.- Perform holistic hardware and firmware security review of critical business devices (e.g., HSMs, Servers, Switches, SSDs).
- Present and campaign the risk findings and risk mitigation recommendations to technical and organizational leadership across different organizations.
- Partner and collaborate with device vendors via regular meetings and emails in order to advocate for necessary design changes to hardware and firmware for long-term permanent improvements.