Google

Senior Security Engineer, Access Security

Google$174K — $252K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree or equivalent practical experience
  • 5+ years in security assessments, security design reviews, or threat modeling
  • 5+ years of experience in security engineering and network security protocols
  • 5+ years of coding in one or more general-purpose languages
  • 1+ year in a technical leadership role or leading risk analysis in an enterprise setting

Responsibilities

  • Identify and design security controls and tools to enhance security systems
  • Drive strategy for access risk mitigation through technical solutions
  • Architect risk mitigation systems for continuous assessment and remediation
  • Advise teams on complex security issues to ensure implementation of security standards
  • Lead execution of programs related to Internal Access Control and associated protocols

Benefits

  • Comprehensive health, wellness, and retirement plans
  • Flexible working hours and remote work options
  • Opportunities for professional development and career advancement
  • Access to cutting-edge technology and tools
  • Collaborative work environment with a focus on innovation
Full Job Description
Minimum qualifications:
  • Bachelor's degree or equivalent practical experience.
  • 5 years of experience with security assessments or security design reviews or threat modeling.
  • 5 years of experience with security engineering, computer and network security and security protocols.
  • 5 years of coding experience in one or more general purpose languages.
  • 1 year of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.

Preferred qualifications:
  • Experience in building or managing security posture management frameworks that provide continuous visibility and automated governance over infrastructure risks.
  • Proven expertise in performing complex threat modeling for large-scale distributed systems and conducting attack path modeling and simulation to identify non-obvious lateral movement and indirect access risks.
  • Technical knowledge of system hardening techniques across various layers (OS, network, and application) to enforce security invariants and reduce the attack surface of critical production services.
  • Understanding of identity and access management (IAM), mandatory access control (MAC), principle of least privilege, and zero-trust architectures in production environments.


About the job

Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

PRISM is the central engineering team responsible for the reduction of Production Infrastructure Access Abuse risks, which is driven through the collection of INTACT programs, including User Data Protection (UDP), AI Model Oversight, Access and Tooling (MOAT), Malicious Outages (MalOut) and Trusted Core Access (TCA).

We are looking for a Security Engineer who is interested in working on security research and risk mitigation systems, help scope security problems, and contribute to projects within Privacy, Safety, and Security (PSS) and across Product Areas (PAs) to transform how Google manages and eliminates internal access risk.

As a Security Engineer on the PRISM team, you will be at the forefront of redefining Google's internal access landscape. You will not just be responding to risks; you will be anticipating them by building the next-generation taxonomy of access risk and architecting 'secure-by-default' solutions that protect our most critical infrastructure. From modeling complex attack paths to securing the rise of agentic identities, you will lead projects that transform how Google proactively manages risk at an enterprise scale.

Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

US: $174000 - $252000 (USD) 15% bonus target equity benefits

Learn more about benefits at Google .

Responsibilities
  • Identify security issues and implement and design security controls, tools, and services to improve security systems and processes.
  • Drive the strategy for PRISM's core pillars by identifying emerging access risks and designing technical solutions to mitigate them at scale.
  • Architect and evolve security risk mitigation systems to enable continuous, automated assessment and remediation across Google's infrastructure.
  • Serve as a technical consultant for complex security issues, guiding teams across Product Areas (PAs) to implement security invariant.
  • Contribute to and lead technical execution for the Internal Access Control (INTACT) program suite, including Privilege Access Management (PAM), Model Oversight, Access-Control andTooling (MOAT), and Infrastructure Existential Threats (IET).


About Google

Google is a multinational technology company that specializes in Internet-related services and products. These include online advertising technologies, search engine, cloud computing, software, and hardware. Google was founded in 1998 by Larry Page and Sergey Brin while they were Ph.D. students at Stanford University. The company has grown tremendously since then and has become one of the most valuable companies in the world. Google's mission is to organize the world's information and make it universally accessible and useful.
Learn more about Google
Size
156,500 employees
Market Cap
$1,115.4 billion
Industry
Net Income
$40.2 billion
Founded
1998
5 Year Trend
+23.3%
Revenue
$182.5 billion
NASDAQ

Similar Jobs

More Jobs at Google

More Information Technology Jobs

Find similar Senior Security Engineer, Access Security jobs: