← Back to all jobs

Senior Security Engineer, Access Security

Google · United States · Posted 2026-08-11

Apply on the company site →

Job description

Identify security issues and implement and design security controls, tools, and services to improve security systems and processes. Drive the strategy for PRISM’s core pillars by identifying emerging access risks and designing technical solutions to mitigate them at scale. Architect and evolve security risk mitigation systems to enable continuous, automated assessment and remediation across Google’s infrastructure. Serve as a technical consultant for complex security issues, guiding teams across Product Areas (PAs) to implement security invariant. Contribute to and lead technical execution for the Internal Access Control (INTACT) program suite, including Privilege Access Management (PAM), Model Oversight, Access-Control andTooling (MOAT), and Infrastructure Existential Threats (IET). Minimum Qualifications: Bachelor's degree or equivalent practical experience. 5 years of experience with security assessments or security design reviews or threat modeling. 5 years of experience with security engineering, computer and network security and security protocols. 5 years of coding experience in one or more general purpose languages. 1 year of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment. Preferred Qualifications: Experience in building or managing security posture management frameworks that provide continuous visibility and automated governance over infrastructure risks. Proven expertise in performing complex threat modeling for large-scale distributed systems and conducting attack path modeling and simulation to identify non-obvious lateral movement and indirect access risks. Technical knowledge of system hardening techniques across various layers (OS, network, and application) to enforce security invariants and reduce the attack surface of critical production services. Understanding of identity and access management (IAM), mandatory access control (MAC), principle of least privilege, and zero-trust architectures in production environments.