Posted 3d ago

Security Engineer, Access Security Team

@ Google
New York, New York, United States
$123k-$174k/yrOnsiteFull Time
Responsibilities:Develop security strategies, Architect risk mitigation systems, Serve as technical consultant
Requirements Summary:Bachelor's degree or equivalent; 1 year security assessments/design reviews/threat modeling; 1 year coding; experience in infrastructure security or security research.
Save
Mark Applied
Hide Job
Report & Hide
Job Description

Minimum qualifications:

  • Bachelor's degree or equivalent practical experience.
  • 1 year of experience with security assessments or security design reviews or threat modeling.
  • 1 year of coding experience in one or more general purpose languages.
  • Experience with security engineering within the infrastructure security or security research space.

Preferred qualifications:

  • Experience designing and implementing distributed security systems or automated remediation frameworks at scale.
  • Experience in performing complex threat modeling for large-scale distributed systems and conducting attack path modeling and simulation to identify non-obvious lateral movement and indirect access risks.
  • Knowledge of system hardening techniques across various layers (OS, network, and application) to enforce security invariants and reduce the attack surface of critical production services.
  • Understanding of identity and access management (IAM), mandatory access control (MAC), principle of least privilege, and zero-trust architectures in production environments.

About the job

The PRISM (Proactive Access Risk Intelligence and Security Mitigations) team is part of the Access Security Team organization. We proactively focus on uncovering broad risks across the access landscape, gathering and distilling access intelligence from internal systems to fortify security, and deploying comprehensive measures to ensure every angle of access is understood and protected, including enforcing security invariants to prevent future regressions. We are also building the next-generation taxonomy for qualifying access risk, prototyping end-to-end pipelines to uncover security risks associated with agentic identities, and architecting secure-by-default solutions scaled across the enterprise.

As a Security Engineer, you will be working on security research and risk mitigation systems, help scope security problems, and contribute to projects across product areas to transform how Google manages and eliminates internal access risk.

In this role, you will be at the forefront of redefining Google’s internal access landscape. You will not just respond to risks; you will be anticipating them by building the next-generation taxonomy of access risk and architecting 'secure-by-default' solutions that protect our most critical infrastructure. From modeling complex attack paths to securing the rise of agentic identities, you will lead high-impact projects that transform how Google proactively manages risk at an enterprise scale.
The US base salary range for this full-time position is $123,000-$174,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.

Responsibilities

  • Drive the strategy for PRISM’s core pillars by identifying emerging access risks and designing technical solutions to mitigate them at scale.
  • Architect and evolve security risk mitigation systems to enable continuous, automated assessment and remediation across Google’s infrastructure.
  • Serve as a technical consultant for complex security challenges, guiding teams across Product Areas (PAs) to implement robust security invariants.
  • Contribute to and lead technical execution for the Internal Access Control program suite.
Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Google's EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our Accommodations for Applicants form.