Security Engineer, Detection
Listed on 2026-07-18
-
IT/Tech
Cybersecurity, Systems Engineer, Network Security
Google, Reston, VA, USA
Required Qualifications- Bachelor's degree or equivalent practical experience.
- 1 year of experience with security assessments or security design reviews or threat modeling.
- 1 year of coding experience in one or more general purpose languages.
- Experience with security engineering, computer and network security and security protocols.
- Experience in responding to security problems in target-rich environments, looking at security alerts, front-line analysis, and response.
- Expertise with signals development, threat hunting, and threat modeling.
- Expertise in the analysis of large data sets and intrusion detection systems.
- Knowledge of modern AI/ML frameworks and tools, including experience in prompt engineering.
Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
The Detection team develops and maintains the signals, tools, and infrastructure we use, constantly evolving them to match sophisticated attackers. As a Security Engineer in the Infrastructure Detection domain, you will bridge the boundary between Google Cloud Platform (GCP) and production (network, data center). Our outlook is to establish a self-defending enterprise where no adversary can exploit or abuse our global infrastructure undetected.
You will help us transition from manual, reactive security models to proactive, highly automated, and AI‑driven defense systems capable of sublinear coverage growth. You will help protect network boundaries, harden systems against attacks, and actively build the intelligent automation required to defend highly sensitive data at an unprecedented scale.
- Design, implement, and maintain high‑fidelity detections across critical infrastructure focus areas, including compute (GKE), supply chain, IAM/API (LOAS, Cloud IAM), and network.
- Partner with program teams to deploy agentic detection engineering workflows, shifting defenses from “Detect and Respond” to machine‑speed “Infer and Interrupt.”
- Ground detection logic in factual threat data by leveraging proven exploit paths from Red teams, Orange teams, and the Vulnerability Reward Program (VRP).
- Reduce manual triage toil and operational burden by optimizing feedback loops between prevention, detection, and response.
- Participate in a 24/7 global operation that hunts for and responds to security events on Google's networks. Perform investigations on a wide variety of events from various sources to determine whether they pose a threat to Google.
US: $123,000 - $175,000 (USD) + 15% bonus target + equity + benefits. Learn more about benefits at Google.
EEO StatementGoogle is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law.
See also Google's EEO Policy, Know your rights: workplace discrimination is illegal, Belonging at Google, and How we hire.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).