The posting
In most instances, this position requires in-person interviews as part of the hiring process.
Applicants in the County of Los Angeles: Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
Applicants in San Francisco: Qualified applications with arrest or conviction records will be considered for employment in accordance with the San Francisco Fair Chance Ordinance for Employers and the California Fair Chance Act.
In accordance with Washington state law, we are highlighting our comprehensive benefits package, which is available to all eligible US based employees. Benefits for this role include:
- Health, dental, vision, life, disability insurance
- Retirement Benefits: 401(k) with company match
- Paid Time Off: 20 days of vacation per year, accruing at a rate of 6.15 hours per pay period for the first five years of employment
- Sick Time: 40 hours/year (increased to 69 hours/year for Seattle) including 5 discretionary sick days per instance
- Maternity Leave (Short-Term Disability + Baby Bonding): 28-30 weeks
- Baby Bonding Leave: 18 weeks
- Holidays: 13 paid days per year
Note: By applying to this position you will have an opportunity to share your preferred working location from the following:
Remote locations: California, USA; Nevada, USA; Oregon, USA; Washington, USA.
Minimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 5 years of experience with security assessments or security design reviews or threat modeling.
- 5 years of experience with security engineering, computer and network security and security protocols.
- 5 years of experience coding in one or more general purpose languages.
- Experience in graph theory, malware analysis, encoding/decoding, netflow and traffic analysis, timeline, log, or email analysis.
- Experience in an investigative role, including experience in cyber threat analysis, incident response, or intrusion operations.
Preferred qualifications:
- Experience in reverse engineering and security analysis.
- Experience in network infrastructure, security, and application development.
About the job
There's no such thing as a "safe system" - only safer systems. Our Security team works to create and maintain the safest operating environment for Google's users and developers. As a Security Engineer, you help protect network boundaries, keep computer systems and network devices hardened against attacks and provide security services to protect highly sensitive data like passwords and customer information. Security Engineers work directly with network equipment and actively monitor our systems for attacks and intrusions. You also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
You use your industry experience to own and drive the resolution of complex security incidents, policy questions and technical security issues.
Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.
US: $174000 - $252000 (USD) + 15% bonus target + equity + benefits
Learn more about benefits at Google.
Responsibilities
- Synthesize complex intrusion data, telemetry, and OSINT to map and disrupt sophisticated adversary activities. Orchestrate multiple concurrent investigations, extracting high-fidelity methodologies and behavioral characteristics from technical datasets.
- Lead comprehensive lead-exploitation efforts, merging disparate datasets to produce a holistic view of adversary Tactics, Techniques, and Procedures (TTPs). Collaborate across expert teams in high-tempo environments to cluster isolated events into actionable campaign intelligence.
- Transform complex investigative findings into curated data models and client-facing reports that provide critical context and strategic attribution.
- Drive team efficiency by architecting automated workflows and custom scripting solutions.
- Pioneer the integration of AI-driven tools to enhance analysis speed and intelligence accuracy.



