Google

Privacy and Security Technical Assurance, Risk, Compliance and Integrity

Google$136K — $197K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or equivalent experience.
  • 7 years in cybersecurity, technical assurance, IT audit, pen testing, or second line of defense risk management.
  • Experience in enterprise-wide technical project planning and execution with legal and compliance teams.
  • Experience designing security control testing methodologies and risk assessments for software, infrastructure, or AI/ML systems.

Responsibilities

  • Provide critical oversight as a second line of defense, maintaining technical assurance testing frameworks for AI/ML and security ecosystems.
  • Design and execute technical testing of both current and new cybersecurity and AI controls to validate them.
  • Lead cross-functional security testing initiatives to assess risks in AI product areas and engineering teams.
  • Communicate testing results and control gaps effectively to technical leadership, legal counsel, and executives.
  • Translate testing insights into actionable recommendations for engineering teams regarding emerging AI threats.

Benefits

  • Health, dental, vision, life, and disability insurance.
  • 401(k) retirement plan with company match.
  • 20 days of vacation per year, accruing at 6.15 hours per pay period for the first five years.
  • 40 hours of sick time per year, increasing for Seattle-based roles.
  • 28-30 weeks of maternity leave for short-term disability baby bonding.
  • 18 weeks of baby bonding leave.
  • 13 paid holidays per year.
Full Job Description
info_outline
X
This role may also be located in our Playa Vista, CA campus.

In accordance with Washington state law, we are highlighting our comprehensive benefits package, which is available to all eligible US based employees. Benefits for this role include:

  • Health, dental, vision, life, disability insurance
  • Retirement Benefits: 401(k) with company match
  • Paid Time Off: 20 days of vacation per year, accruing at a rate of 6.15 hours per pay period for the first five years of employment
  • Sick Time: 40 hours/year (increased to 69 hours/year for Seattle) including 5 discretionary sick days per instance
  • Maternity Leave (Short-Term Disability Baby Bonding): 28-30 weeks
  • Baby Bonding Leave: 18 weeks
  • Holidays: 13 paid days per year


Note: By applying to this position you will have an opportunity to share your preferred working location from the following: Austin, TX, USA; Los Angeles, CA, USA; Washington D.C., DC, USA.

Minimum qualifications:
  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or equivalent practical experience.
  • 7 years of experience in cybersecurity, technical assurance, IT audit, pen testing, or working within a second line of defense risk management function.
  • Experience with enterprise-wide or cross-functional technical project planning and execution, including partnering with legal, policy, or compliance teams.
  • Experience designing and executing security control testing methodologies and risk assessments for software, infrastructure, or AI/ML systems.

Preferred qualifications:
  • Advanced degree in Computer Science, Cybersecurity, Artificial Intelligence, or a related field.
  • Professional AI security or audit certifications such as CISSP, CISA, CISM, AIGP, AAIA, ISO 27001/42001 Lead Auditor or equivalent technical certifications.
  • Experience working within a technology company or "Big Tech" ecosystem, navigating complex, hyper-scale infrastructure and distributed risk environments.
  • Proven experience operating in a second line of defense role, including providing separate tests, control testing, and oversight to first-line business and engineering teams.
  • Deep technical understanding of AI/ML specific vulnerabilities (e.g., adversarial attacks, training data extraction, prompt injection).


About the job

The Risk, Compliance and Integrity organization (RCI) brings together critical compliance, assurance, risk, and governance functions across the company to help meet compliance needs and enable our businesses to innovate securely. Operating as a critical second line of defense, we manage our operations through risk-based prioritization, technical validation, oversight, and consistent engagement with product engineering and legal counsel.

In this role, you will demands a deep understanding of AI/ML architectures, offensive security testing methodologies, and threat modeling, coupled with the ability to separately test existing and emerging cybersecurity and AI controls. As a second-line leader, you will need the ability to collaborate effectively across the engineering organization, provide constructive issues, and influence at all levels.

In addition to a deep technical security foundation, this role requires exceptional program management capabilities. The successful person will have a demonstrated ability to track, report on, and effectively manage complex technical assurance initiatives from inception to completion. This includes defining clear testing objectives, establishing metrics, monitoring the first line's remediation progress, and ensuring timely and accurate reporting to engineering stakeholders and risk committees.

Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

US: $136000 - $197000 (USD) 15% bonus target bonus equity benefits

Learn more about benefits at Google .

Responsibilities
  • Provide separate oversight and issues as a critical second line of defense function, establishing and maintaining comprehensive technical assurance testing frameworks for AI/ML and traditional security ecosystems.
  • Design and execute technical assurance testing across both existing and emerging cybersecurity and AI controls to validate their design and operating effectiveness.
  • Lead and coordinate cross-functional security testing initiatives (e.g., targeted control validation, AI red teaming, architecture reviews) to separately assess risks across AI product areas and engineering teams.
  • Advocate for AI security assurance, effectively communicating testing results, control deficiencies, threat models, and mitigation strategies to first-line technical leadership, legal counsel and executive stakeholders.
  • Enhance awareness of emerging AI threats, translating testing insights into actionable engineering recommendations.

About Google

Google is a multinational technology company that specializes in Internet-related services and products. These include online advertising technologies, search engine, cloud computing, software, and hardware. Google was founded in 1998 by Larry Page and Sergey Brin while they were Ph.D. students at Stanford University. The company has grown tremendously since then and has become one of the most valuable companies in the world. Google's mission is to organize the world's information and make it universally accessible and useful.
Learn more about Google
Size
156,500 employees
Market Cap
$1,115.4 billion
Industry
Net Income
$40.2 billion
Founded
1998
5 Year Trend
+23.3%
Revenue
$182.5 billion
NASDAQ

Similar Jobs

More Jobs at Google

More Information Technology Jobs

Find similar Privacy and Security Technical Assurance, Risk, Compliance and Integrity jobs: