Minimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 5 years of experience with security assessments or security design reviews or threat modeling.
- 5 years of experience with security engineering, computer and network security and security protocols.
- 5 years of coding experience in one or more general purpose languages.
- 1 year of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.
Preferred qualifications:
- 5 years of experience in security engineering, threat modeling, and application security.
- Deep expertise in account security mechanisms, identity and access management (IAM), and modern authentication standards (e.g., OAuth 2.0, OIDC, FIDO/Passkeys, SAML).
- Demonstrated experience building or deploying AI agents, LLMs, or agentic workflows for security automation, threat detection, or user-facing product features.
- Proven track record of identifying novel security vulnerabilities (e.g., threat research, bug bounties, security advisories) and implementing systemic engineering fixes.
About the job:
Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
As a Senior Security Engineer within the Workspace Account Security and Integrity team, you will drive the technical strategy to defend Workspace accounts and protect the Google Workspace and Cloud customers against advanced and evolving threats. Operating at the frontier of account security, adversarial analysis, and agentic AI, you will lead in-depth searchs into account vulnerabilities and pioneer the next generation of automated defense tools.
US: $174000 - $252000 (USD) + 15% bonus target + equity + benefits
Learn more about benefits at Google.
Responsibilities:
- Drive the technical strategy and threat modeling for Workspace account security, identifying systemic weaknesses in authentication, recovery, and API integration paths.
- Lead vulnerability research and adversarial simulation to expose novel account takeover (ATO) and Made for Abuse (MFA) techniques.
- Design and build advanced agentic systems, debugging tools, and simulators to autonomously detect, analyze, and mitigate complex account security threats.
- Architect and deploy customer-facing agentic tools that empower Workspace and Google Cloud customers to proactively monitor and secure their own environments.
- Lead the investigation of high-severity account security incidents, developing long-term mitigations and patches in collaboration with product engineering teams.
Learn more about this Employer on their Career Site
