Minimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 5 years of experience with security assessments or security design reviews or threat modeling.
- 5 years of experience with security engineering, computer and network security and security protocols.
- 5 years of coding experience in one or more general purpose languages.
- 4 years of practical experience with digital forensic analysis
Preferred qualifications:
- Experience with the current threat landscape including common attack types and malware capabilities.
- Experience with security of two or more operating systems e.g. Android, Linux, Mac OS X, Windows.
- Experience with, and detailed understanding of, digital forensics and incident response tools such as GRR, Plaso (log2timeline), The Sleuth Kit (TSK), libyal, or alternatives like Guidance Encase, AccessData FTK, X-Ways Forensics, Cellebrite, Crowdstrike Falcon, Volatility, Mandiant MIR, etc.
- Experience with reverse engineering or firmware analysis
About the job
There's no such thing as a "safe system" - only safer systems. Our Security team works to create and maintain the safest operating environment for Google's users and developers. As a Security Engineer, you help protect network boundaries, keep computer systems and network devices hardened against attacks and provide security services to protect highly sensitive data like passwords and customer information. Security Engineers work directly with network equipment and actively monitor our systems for attacks and intrusions. You also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
You use your industry experience to own and drive the resolution of complex security incidents, policy questions and technical security issues.
Google is creating next-generation technologies that will revolutionize how billions of people connect and interact with each other and information. Security and privacy are key components of these new solutions. You are enthusiastic about information security, privacy, and technology, and want to help keep the world safe, making you a great fit for our Security Response team.
Google’s Detection and Response team finds and responds to security concerns 24/7 across 3 regions. In Security Response, you will be a member of our global on-call response team and use your security experience and Digital Forensics and Incident Response (DFIR)-specific domain knowledge to investigate and respond to escalations from across Alphabet. Security Response team members train and grow in forensic investigation and crisis management skills, specializing in one or the other as their career grows.
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.
US: $174000 - $252000 (USD) + 15% bonus target + equity + benefits
Learn more about benefits at Google.
Responsibilities
- Perform investigations on a wide variety of security and privacy events from various sources to determine whether they pose a risk to Google.
- Participate in large-scale security and privacy incidents, write incident reports, and participate in post-mortems.
- Participate in internal training to make sure forensic best practices are followed.
- Work with teams from around Google to discover new investigative and forensics capabilities.
- Develop internal and Open Source tools used to respond to incidents (e.g., digital forensic toolkits) to support Google’s unique environment.
