Security Engineer, Google Threat Intelligence

Google

Sydney

On-site

AUD 180,000 - 280,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Google’s Security team in Sydney seeks a Threat Intelligence Analyst to produce actionable intelligence on serious threats to Google, products, and users. You will work with GTIG to track government-backed actors, craft analyses, and support security and abuse teams across the company.

The role requires deep expertise in TTPs, network security, and threat actor analysis, with collaboration across engineering and product teams to mitigate risks and protect users worldwide.

Qualifications

  • Bachelor's degree or equivalent practical experience.
  • 5 years of experience with security assessments, security design reviews or threat modeling.
  • 5 years of experience with security engineering, computer and network security and security protocols.
  • 5 years of experience coding in one or more general purpose languages.

Responsibilities

  • Identify, analyze, and document network signals, malware behaviors, and threat reports related to trends and developments in adversary tactics, techniques, and procedures (TTPs).
  • Provide clear, actionable intelligence to product and security teams; assist in safeguarding corporate and production systems.
  • Own the analysis efforts of multiple threat actors, and serve as a SME on how those actors might impact Google and our users.
  • Enhance analysis efficiency by automating, developing POC code, and deploying solutions with stakeholders.
  • Identify priorities and work on assignments with minimal supervision while meeting deadlines.

Skills

Security assessments
Threat modeling
Security design reviews
Security engineering
Programming languages
Communication & documentation

Education

Bachelor's degree or equivalent

Tools

YARA
Snort/Suricata
EDR rule creation
Python
C/C++

Job description

For Sydney applicants: At Google, we have a vision of empowerment and equitable opportunity for all Aboriginal and Torres Strait Islander peoples and commit to building reconciliation through Google’s technology, platforms and people and we welcome Indigenous applicants. Please see our Reconciliation Action Plan for more information.

For Singapore applicants: Google will be prioritizing applicants who have a current right to work in Singapore, and do not require Google's sponsorship of a visa.

Note: By applying to this position you will have an opportunity to share your preferred working location from the following: Sydney NSW, Australia; Singapore.

Minimum Qualifications
  • Bachelor's degree or equivalent practical experience.
  • 5 years of experience with security assessments, security design reviews or threat modeling.
  • 5 years of experience with security engineering, computer and network security and security protocols.
  • 5 years of experience coding in one or more general purpose languages.
Preferred Qualifications
  • Prior experience in detection engineering with YARA, Snort/Suricata, EDR rule creation.
  • Experience in Python, C/C++ or scripting languages.
  • Experience in reverse engineering.
  • Strong understanding of network fundamentals, techniques for lateral machine movement, malware persistence mechanisms, covert channels, application security and user authentication, command and control techniques.
  • Very strong communication and documentation skills.
About The Job

Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities. Google's Threat Intelligence Group (GTIG) is looking for a threat intelligence analyst for our Koreas Advanced Persistent Threat (APT) mission. In this role, you will produce threat intelligence focusing on serious threats to Google, our products, and our users which are consumed by hundreds of security and abuse teams across the company, all levels of leadership, and externally to the security research industry. You will specialize in thwarting government-backed threats. You will be part of a specialized team at the forefront of tracking cyber threat actors. Google Cloud accelerates every organization’s ability to digitally transform its business and industry. We deliver enterprise-grade solutions that leverage Google’s cutting-edge technology, and tools that help developers build more sustainably. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.

Responsibilities
  • Identify, analyze, and document network signals, malware behaviors, and threat reports related to trends and developments in adversary tactics, techniques, and procedures (TTPs).
  • Provide clear, actionable, and structured intelligence to product and security teams; assist in ensuring corporate and production systems are safeguarded.
  • Own the analysis efforts of multiple threat actors, and serve as a subject matter expert on how those actors might impact Google and our users.
  • Enhance analysis efficiency by conceiving and implementing automation opportunities, developing Proof-of-Concept code, and collaborating with stakeholders to deploy solutions.
  • Be capable of quickly identifying personal and team priorities, and able to work on assignments with minimal supervision while maintaining quality and deadlines.

Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Google's EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our Accommodations for Applicants form .

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer, Google Threat Intelligence
Security Engineer, Google Threat Intelligence

Google • Sydney

On-site
AUD 120,000 - 180,000
Threat Intelligence Security Engineer - Threat Analysis
Threat Intelligence Security Engineer - Threat Analysis

Google • Sydney

On-site
AUD 120,000 - 180,000
Threat Intelligence Engineer - Advanced Security & APT
Threat Intelligence Engineer - Advanced Security & APT

Google • Sydney

On-site
AUD 180,000 - 280,000
Detection and SOAR Engineer, Mandiant Consulting, Google Cloud
Detection and SOAR Engineer, Mandiant Consulting, Google Cloud

Google Inc. • Sydney

Hybrid
AUD 120,000 - 180,000
Group Product Manager, Information and Infrastructure Protection
Group Product Manager, Information and Infrastructure Protection

Google • Sydney

On-site
AUD 180,000 - 240,000
Lead Engineer - GCP
Lead Engineer - GCP

CyberCX • Canberra

On-site
AUD 100,000 - 130,000
Flexible working arrangements
Additional paid leave options
Salary packaging options
+5
Customer Engineer, Cloud AI Platform, Google Cloud
Customer Engineer, Cloud AI Platform, Google Cloud

Google • Sydney

On-site
AUD 130,000 - 160,000
Equal opportunity employer
Commitment to diversity and inclusion
Security Platform Engineer (Google SecOps & BindPlane)
Security Platform Engineer (Google SecOps & BindPlane)

Paxus - Technology + Digital Talent • Sydney

On-site
AUD 150,000 - 190,000
Engineering Manager, Site Reliability Engineering
Engineering Manager, Site Reliability Engineering

Google Inc. • Sydney

On-site
AUD 180,000 - 260,000
Applied Solutions Architect
Applied Solutions Architect

Google • Council of the City of Sydney

On-site
AUD 180,000 - 240,000