Skip to main content
Google logo

Cloud Abuse Security Engineer

Google
1 day ago
Full-time
On-site
Zürich, ZH

Google is hiring a Cloud Abuse Security Engineer to join its Cloud CISO team in Zürich, onsite. You’d operate within the Cloud Abuse Security Engineering (CASE) group, protecting Google Cloud, its customers, and the broader internet from threats that originate inside Google Cloud. The role blends monitoring with hands-on engineering, and you’ll partner with software engineers to identify security flaws and fix vulnerabilities. This position is full-time and based on site in Zürich, ZH, and it’s a good match if you enjoy threat hunting, building detections, and collaborating across teams.

Within Google Cloud’s security ecosystem, the Cloud CISO group owns the product security strategy and helps guard a wide swath of infrastructure. The CASE team is focused on preventing abuse and safeguarding users and the internet from threats that originate within Google Cloud, making your work feel meaningful at planet-wide scale.

A day in the CASE room

Your daily work will revolve around finding better ways to detect abuse, including outbound attacks, botnets, DDoS, and other behaviors that violate GCP’s terms. You’ll build high-fidelity detections from raw network and host telemetry, hunt for threats, and respond proactively when you identify issues. You’ll also create and maintain tools to collect abuse reports and threat intelligence data, turning streams of information into actionable protection for Google Cloud and its users.

What you’ll need to join the team

  • A bachelor’s degree or equivalent practical experience.
  • At least two years of hands-on work in areas like cloud security research, network security, intrusion detection systems, threat intelligence, or threat detection.
  • Familiarity with defensive security concepts, including adversary tactics and techniques, security frameworks, and logging practices.
  • Solid grounding in networking, core Internet protocols, and analyzing suspicious network traffic.

Nice-to-haves

  • Background in host or memory forensics and related detections.
  • Excellent written and verbal communication along with strong documentation skills.

A Swiss base for securing Google Cloud

This is a full-time, onsite role based in Zürich, ZH.

Advice for applicants

Lead with your most relevant experience on your resume, placing emphasis on work in cloud security research, network security, IDS, threat intelligence, or threat detection, and share tangible outcomes of your work.

When you describe the must-have skills, give concrete examples of how you’ve applied defensive security concepts, tactics, frameworks, and logging, and show how those practices were implemented in real deployments.

In interviews, be prepared to discuss a threat hunt you led, how you built a detection from raw telemetry, and how you collaborated with software engineers to fix security flaws or vulnerabilities.

Asking a thoughtful question can set you apart: inquire how the CASE team translates threat intelligence into concrete product-security improvements and how success is measured within Google Cloud’s security strategy.