EngineerJobs.io
← Back to all jobs

Job Description

The Security Engineer, Detection role focuses on designing and maintaining high-fidelity detections and automated defenses to safeguard Google's backend infrastructure across GCP and production networks. The position emphasizes threat hunting, forensics, and collaborating with software engineers to proactively remediate security flaws and vulnerabilities. This onsite role is based in Reston, VA and offers a salary range of USD 123,000 to 175,000 per year. A bachelor’s degree or equivalent practical experience is required.

Responsibilities

  • Design, implement, and sustain precise detection capabilities across key infrastructure domains, including compute (GKE), supply chain, IAM and API controls (LOAS, Cloud IAM), and network.
  • Collaborate with program teams to deploy detection engineering workflows that accelerate defenses from detection to automatic interruption at machine speed.
  • Anchor detection logic in validated threat data by leveraging exploit paths from Red Team, Orange Team exercises, and the Vulnerability Reward Program (VRP).
  • Lower manual triage and operational burden by refining feedback loops among prevention, detection, and response.
  • Contribute to a 24/7 global security operations program that hunts for and addresses security events across Google networks; investigate a wide variety of events from multiple sources to assess threat relevance.

Requirements

  • A bachelor’s degree or equivalent practical experience.
  • At least one year of experience in security assessments, security design reviews, or threat modeling.
  • At least one year of coding experience in one or more general purpose languages.
  • Experience in security engineering, computer and network security, and knowledge of security protocols.

Technologies

  • GKE
  • LOAS
  • Cloud IAM
  • Google Cloud Platform (GCP)
  • AI/ML frameworks
  • Prompt engineering

Benefits

  • 15% target bonus
  • Equity

About the Job

The Security team is dedicated to creating and maintaining the safest operating environment for Google's users and developers. Security Engineers monitor network equipment and systems for attacks and intrusions, while collaborating with software engineers to proactively identify and remediate security flaws and vulnerabilities. The Detection team builds and maintains signals, tools, and infrastructure to counter sophisticated attackers, developing advanced detection mechanisms for attacker techniques, automating remediation, conducting threat hunting, and performing network and systems forensics, as well as malware and indicator analysis.

As a Security Engineer in the Infrastructure Detection domain, you will be at the forefront of securing Alphabet's backend platforms and hardware, bridging Google Cloud Platform (GCP) and production environments (network and data center). The goal is to establish a self-defending enterprise where adversaries cannot exploit or abuse the global infrastructure undetected.

Preferred Qualifications

  • Experience responding to security problems in target-rich environments, including frontline analysis and response to security alerts.
  • Expertise in signals development, threat hunting, and threat modeling.
  • Proficiency in analyzing large data sets and intrusion detection systems.
  • Knowledge of modern AI/ML frameworks and tools, including experience with prompt engineering.

Similar Jobs