Security Engineer, Third Party Security Diligence

Google

Singapore

On-site

SGD 70,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Google seeks a Security Engineer for their Singapore office, focusing on safeguarding third-party engagements. The role involves conducting security diligence and collaborating with teams to enhance security processes.

The ideal candidate has at least 2 years of experience in security assessments and engineering, with proficiency in programming languages like Python and Java. This role is critical for managing risks associated with third-party vendors and ensuring data protection.

Qualifications

  • 2 years of experience with security assessments, design reviews, or threat modeling.
  • 2 years of experience with security engineering, computer and network security.
  • 2 years of coding experience in one or more general-purpose languages.

Responsibilities

  • Conduct comprehensive security diligence for third-party vendors.
  • Develop tools and automation for security processes.
  • Collaborate with internal stakeholders on security guidance.

Skills

Security assessments
Threat modeling
Security engineering
C/C++/Java/Go/Python

Education

Bachelor's degree or equivalent

Job description

Security Engineer, Third Party Security Diligence

Location: Singapore | Level: Mid

Minimum Qualifications
  • Bachelor's degree or equivalent practical experience.
  • 2 years experience with security assessments, design reviews, or threat modeling.
  • 2 years experience with security engineering, computer and network security, and security protocols.
  • 2 years experience coding in one or more general‑purpose languages (e.g., Python, SQL, C, C++, Java, Go).
Preferred Qualifications
  • Demonstrated experience and strong background in relevant enterprise security domains, particularly in threat modeling, security assessments, authentication and access controls, SaaS security, cloud security and data protection.
  • Experience with security engineering, security architecture or consulting.
  • Proven ability to independently produce high‑quality engineering artifacts (design docs, code reviews, or risk assessments) that require minimal revision.
  • Ability to drive and deliver risk reduction outcomes with high autonomy and limited oversight.
  • Excellent verbal and written communication skills.
About the job

There's no such thing as a "safe system" - only safer systems. Our Security team works to create and maintain the safest operating environment for Google's users and developers. As a Security Engineer, you help protect network boundaries, keep computer systems and network devices hardened against attacks and provide security services to protect highly sensitive data like passwords and customer information. Security Engineers work directly with network equipment and actively monitor our systems for attacks and intrusions. You also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

You use your industry experience to own and drive the resolution of complex security incidents, policy questions and technical security issues.

SPMA (Security and Privacy for Mergers, Acquisitions and Alphabet) team’s mandate focuses on reducing Acquisitions, third‑party and Cloud risk to Google and Alphabet.

SPMA executes its mandate through three key verticals:

  • Mergers, Acquisitions and Alphabets (M&A): Effectively and safely raise the security bar for Google’s off‑Google entities, helping companies navigate Google’s security landscape and processes.
  • Alphabet Use of Cloud (AUC): Manage and minimize risk from Alphabet’s use of public clouds (GCP).
  • Third‑party/Vendor Security Diligence (3PSD): Ensure effective governance and minimize risk from Alphabet’s use of third‑party vendors.

This role sits within the Third Party/Vendor Security Diligence (3PSD) vertical, focusing on third-party security. Alphabet’s Third Party Security Diligence program ensures security of our third‑party engagements, and is part of a broader third‑party risk management ecosystem.

The Core team builds the technical foundation behind Google’s flagship products. We are owners and advocates for the underlying design elements, developer platforms, product components and infrastructure at Google.

Responsibilities
  • Conduct comprehensive security diligence for critical and high‑risk third‑party vendors, evaluating their controls against Google’s requirements, identifying risks, and recommending remediation.
  • Contribute to engineering improvement of the Third Party Security Diligence (3PSD) program by developing tools, automation and proposing process enhancements.
  • Assist in integrating 3PSD tools with the wider OneTPRM ecosystem and support data analysis to identify risk trends.
  • Collaborate with internal stakeholders such as vendor managers and Product teams on third‑party engagements, providing security guidance.
  • Develop and maintain deep technical expertise in security domains relevant to third‑party risk (e.g., cloud, application security, IAM) and help create reusable security patterns and best practices.

Google is a proud equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity or expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See also Google’s EEO Policy, Know your rights: workplace discrimination is illegal, Belonging at Google, and How we hire.

If you have a need that requires accommodation, please let us know by completing our Accommodations for Applicants form.

Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Security Engineer, Third Party Security Diligence
Staff Security Engineer, Third Party Security Diligence

Google • Singapore

On-site
SGD 120,000 - 160,000
Senior Security Engineer, Enterprise SaaS Security
Senior Security Engineer, Enterprise SaaS Security

Google India • Singapore

On-site
SGD 80,000 - 120,000
Senior Security Engineer, Enterprise SaaS Security
Senior Security Engineer, Enterprise SaaS Security

Google • Singapore

On-site
SGD 180,000 - 300,000
Senior Software Engineer, Cloud and Third Party Platform Security
Senior Software Engineer, Cloud and Third Party Platform Security

Google • Singapore

On-site
SGD 90,000 - 120,000
Security Engineer, Enterprise Data Protection
Security Engineer, Enterprise Data Protection

Google • Singapore

On-site
SGD 70,000 - 100,000
Software Engineer III, Cloud and Third-Party Platform Security
Software Engineer III, Cloud and Third-Party Platform Security

Google • Singapore

On-site
SGD 80,000 - 120,000
Information Security Engineer, Early Career, Product Security
Information Security Engineer, Early Career, Product Security

Google • Singapore

On-site
SGD 60,000 - 80,000
Software Engineering Manager, Cloud and Third-Party Platform Security
Software Engineering Manager, Cloud and Third-Party Platform Security

Google • Singapore

On-site
SGD 220,000 - 320,000
Senior Security Engineering Manager, Enterprise Security AI
Senior Security Engineering Manager, Enterprise Security AI

Google India • Singapore

On-site
SGD 100,000 - 140,000
Security Engineer, Google Threat Intelligence
Security Engineer, Google Threat Intelligence

Google Inc. • Singapore

On-site
SGD 120,000 - 180,000