JobsCloseBy Editorial Insights
Google is seeking a Security Engineer for the Cloud Red Team within the Cloud CISO organization in New York City, onsite and full time, to simulate real adversaries, plan attacks, identify vulnerabilities, and translate findings into actionable remediation. Key requirements include a bachelor’s or equivalent experience, two years in technical security, and hands on vulnerability assessment and exploitation; preferred qualifications highlight three plus years in offensive cloud security, AI experience, exploit development, and programming in Python, Go, or Bash, plus the ability to clearly convey risks to technical and non technical audiences. To apply effectively, showcase cloud red team projects, threat modeling work, exploit development, and quantifiable impact, and tailor your resume to emphasize collaboration with product and security teams. US pay range: 147k-211k plus 15% bonus and equity.
Minimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 2 years of experience in a technical security role (e.g., security engineering, security research, DevSecOps, or incident response).
- Experience with vulnerability assessments and vulnerability exploitation.
- Experience in security and ethical hacking.
Preferred qualifications:
- 3 years of offensive security experience (red teaming, vulnerability research, pen testing, etc - not just running tools) in Cloud environment.
- Experience with Artificial Intelligence.
- Ability to develop custom exploits, modify existing exploits, and bypass security controls.
- Fluency in programming languages relevant to security and cloud automation (e.g., Python, Go, Bash).
- Being able to clearly and concisely articulate complex technical findings, risks, and remediation strategies to both technical and non-technical audiences, both verbally and in writing.
About the job
Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
As a part of the Product Security Engineering team within the Cloud CISO organization, you will be responsible for helping ensure every product in Cloud is as secure as it can be, and increasing the security in the infrastructure underlying all our products.
As a part of the Cloud Red Team, your mission is to evaluate our ability to detect and respond to known and unknown threats by simulating real-world adversaries that aim to compromise and persist in Cloud’s infrastructure. In short: Hack Cloud to make hacking Cloud harder.
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.
US: $147000 - $211000 (USD) + 15% bonus target + equity + benefits
Learn more about
benefits at Google.
Responsibilities
- Collaborate within a highly-skilled team to plan and execute attacks against Cloud’s products, services, and infrastructure, while building tools and infrastructure to support attacker goals.
- Identify vulnerabilities and attack vectors proactively within Cloud services, configurations, and related technologies.
- Engage in threat modeling exercises to identify potential attack paths and weaknesses in Cloud architectures and deployments.
- Develop realistic and relevant attack scenarios based on current threat intelligence and the specific Cloud environment being assessed.
- Create reports that capture the insights gained during an attack and present them to a variety of audiences