Senior Security Engineer, Access Security

GoogleNew York City, New YorkOn-siteFull-timeSenior, 5–8 yearsListed 1 hour ago

Apply now

About this role

Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

Our team is the central engineering group responsible for reducing access abuse risks across our production infrastructure. We drive this mission through comprehensive security programs focused on user data protection, AI model oversight, access management, outage prevention, and securing core infrastructure.
As a Security Engineer, you will be working on security research and risk mitigation systems, helping to scope security problems, and contributing to cross-functional projects that transform how we manage and eliminate internal access risk globally.

In this role, you will be at the forefront of redefining our internal access landscape. You will not just respond to risks, but anticipate them by building the next-generation taxonomy of access risk and architecting 'secure-by-default' solutions that protect our most critical infrastructure. From modeling complex attack paths to securing emerging technologies like agentic identities, you will lead projects that proactively manage risk at an enterprise scale.
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

US: $174000 - $252000 (USD) + 15% bonus target + equity + benefits

Learn more about benefits at Google (https://www.google.com/about/careers/applications/benefits/).

Minimum qualifications:

- Bachelor's degree or equivalent practical experience.

- 5 years of experience with security assessments or security design reviews or threat modeling.

- 5 years of experience with security engineering, computer and network security and security protocols.

- 5 years of coding experience in one or more general purpose languages.

- 1 year of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.

Preferred qualifications:

- Experience in building or managing security posture management frameworks that provide continuous visibility and automated governance over infrastructure risks.

- Understanding of identity and access management (IAM), mandatory access control (MAC), principle of least privilege, and zero-trust architectures in production environments.

- Technical knowledge of system hardening techniques across various layers (OS, network, and application) to enforce security invariants and reduce the attack surface of critical production services.

- Proven expertise in performing complex threat modeling for large-scale distributed systems and conducting attack path modeling and simulation to identify non-obvious lateral movement and indirect access risks.

- Identify security issues and implement and design security controls, tools, and services to improve security systems and processes.

- Drive the strategy for the teams core pillars by identifying emerging access risks and designing technical solutions to mitigate them at scale.

- Architect and evolve security risk mitigation systems to enable continuous, automated assessment and remediation across Google’s infrastructure.

- Serve as a technical consultant for complex security issues, guiding teams across Product Areas (PAs) to implement security invariant.