
Senior Security Engineer, Chrome Product Security at Google
About the role
info_outline
XIn accordance with Washington state law, we are highlighting our comprehensive benefits package, which is available to all eligible US based employees. Benefits for this role include:
- Health, dental, vision, life, disability insurance
- Retirement Benefits: 401(k) with company match
- Paid Time Off: 20 days of vacation per year, accruing at a rate of 6.15 hours per pay period for the first five years of employment
- Sick Time: 40 hours/year (increased to 69 hours/year for Seattle) including 5 discretionary sick days per instance
- Maternity Leave (Short-Term Disability + Baby Bonding): 28-30 weeks
- Baby Bonding Leave: 18 weeks
- Holidays: 13 paid days per year
Note: By applying to this position you will have an opportunity to share your preferred working location from the following: Kirkland, WA, USA; Seattle, WA, USA.
Minimum qualifications:
-
Bachelor's degree or equivalent practical experience.
-
5 years of experience with security assessments or security design reviews or threat modeling.
-
5 years of experience with security engineering, computer and network security and security protocols.
-
5 years of coding experience in one or more general purpose languages.
-
1 year of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.
Preferred qualifications:
- 5 years of experience with data privacy, security systems, or computer and network security.
- Experience in security assessments, vulnerability management, security research, or vulnerability investigation.
- Experience with software release management.
About the job
Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
The Product Security team is responsible for maintaining critical operations processes within the Chrome Security team.
Security Engineers on this team are responsible for vulnerability management, security incident response, coordinations and disclosures, and security update release management. Each member of the Product Security team has ownership of one or more aspects of managing security outcomes in Chrome, such as through security reviews, consulting, Vulnerability Rewards Program (VRP)/bug bounty, and security outreach.
You will be working with the Product Security team to maintain and improve the quality of our vulnerability management and security bug triage processes, and working with members of the wider Chrome Security team to lead on security outreach efforts, such as security advocacy and post-mortems of critical and high security issues.
The US base salary range for this full-time position is $174,000-$252,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.
Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.
Responsibilities
-
Identify security issues and implement and design security controls, tools, and services to improve security systems and processes.
-
Lead efforts working across Chrome Security in identifying risks, managing security outcomes, and creating executive briefings for Chrome leadership. Provide security expertise and guidance to a set of Chrome engineering and business teams.
-
Lead key security outreach efforts, such as managing the security post-mortem process and security advocacy.
-
Validate, and triage reports of security issues from internal teams, automation, and external security reporters.
-
Participate in incident response of Chrome security incidents.
Required skills
Security engineering
Threat modeling
Secure coding
Product security
Code review
About Google
Kirkland
Headquarters