This role has closed 1mo ago. It is no longer on Google's board, so there is nothing left to apply to. The posting is kept here because you saved it or opened it; it is a record, not an offer.
Verified from career page · Posted 1mo ago
- Posted
- 1mo ago
- Workplace
- Not specified
- Salary
- Not disclosed
- Visa sponsorship
- Not specified
Posted on 6 August 2026
Work model not stated
Salary range not shared by the company
Visa sponsorship details unknown
This role has closed 1mo ago ago. It's kept as a record — see Google's open roles or the similar live roles below.
See Google's open rolesOur Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
Join the Google Threat Intelligence Group's (GTIG) Exploits Mission. The Exploits Mission focuses on protecting users from targeted exploitation, primarily from government-backed attackers and Commercial Surveillance Vendors (CSVs), through the detection, analysis, and ultimate prevention of vulnerabilities and exploits, with a special focus on 0-day attacks.
We provide timely, actionable intelligence and coordinate with internal and external partners to fix critical vulnerabilities and secure user devices.
As a Security Engineer on our team, you will conduct in-depth research on threat groups, their Tactics, Techniques, and Procedures (TTPs), and the malware they employ. You'll utilize Google's powerful internal intelligence platforms, Nirvana and mGraph, to model threat activity and generate actionable insights. This role involves close collaboration with various teams across GTIG and Google to develop and implement effective countermeasures, contributing directly to threat disruption and enhancing our collective security posture. We are looking for engineers passionate about threat research who can lead projects and mentor others.
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.
Germany: €128000 - €131000 (EUR) + 15% bonus target + equity + benefits
Learn more about benefits at Google.
Create and deploy detection signatures (autoqueries, Watchtower rules) to maintain visibility over threat actors and assist in closing security gaps.
Produce polished, high-quality technical intelligence documentation and actor profiles to deliver actionable insights to internal and external stakeholders.
Influence technical direction within your scope, mentor junior engineers, and collaborate with cross-functional Google teams to support threat disruption efforts. Collaborate with security engineers and product teams in designing innovative exploit mitigations.
Identify and execute opportunities for continuous improvement: analytic collection, process optimization, and automation.
Minimum qualifications:
Bachelor's degree in Computer Science, Cybersecurity, a related field, or equivalent practical experience.
5 years of experience in threat intelligence, intrusion analysis, vulnerability researcher, or a similar security role.
Experience with threat intelligence platforms and tools (e.g., VirusTotal, SIEMs).
Preferred qualifications:
Knowledge of Android and Chrome security and internals.
Deep understanding of attacker Tactics, Techniques, and Procedures (TTPs).
Proven ability to lead complex threat research projects independently.
Strong analytical, problem-solving, and communication skills.
Skills in malware analysis, reverse engineering, or vulnerability analysis.
Proficiency in scripting or querying languages (e.g., Python, GoogleSQL).
About Google
Google runs core product engineering out of London, Dublin, Zurich, Warsaw and Munich — not support functions. Zurich is one of its largest engineering sites anywhere, and Warsaw has grown substantially. The bar is high and the process is long, but these are genuine product teams.