Senior Security Engineer, Trust and Safety Workspace
GoogleMinimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 5 years of experience with security assessments or security design reviews or threat modeling.
- 5 years of experience with security engineering, computer and network security and security protocols.
- 5 years of coding experience in one or more general purpose languages.
- 1 year of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.
Preferred qualifications:
- Master’s degree or PhD in Computer Science, Cybersecurity, or a related technical field, or equivalent practical experience.
- Experience in account security mechanisms, identity and access management (IAM), and modern authentication standards (e.g., OAuth 2.0, OIDC, FIDO/Passkeys, SAML).
- Experience building or deploying AI agents, LLMs, or agentic workflows for security automation, threat detection, or user-facing product features.
- Understanding of anti-abuse systems, bot detection, and mitigations against malicious automation (credential stuffing, bulk creation).
- Ability to identify novel security vulnerabilities (e.g., threat research, bug bounties, security advisories) and implementing systemic engineering fixes.
About the job:
The Trust and Safety Workspace Account Security and Integrity (AIS) team is dedicated to protecting Google Workspace and Cloud customers from account-based threats. The mission is to safeguard the integrity of Workspace accounts by delivering a unified, scalable defense against account hijacking, takeover (ATO), and malicious automation. We operate at the critical intersection of product security and abuse prevention, balancing robust security controls with a frictionless experience for both individual users and enterprise organizations. By studying adversarial behavior and building state-of-the-art telemetry and agentic defense systems, we ensure a secure, trusted, and resilient ecosystem that protects our customers' businesses, data, and users.
As a Senior Security Engineer, you will drive the technical strategy to defend Workspace accounts and protect the Google Workspace and Cloud customers against advanced and evolving threats. Operating at the frontier of account security, adversarial analysis, and agentic AI, you will lead research into account vulnerabilities and pioneer the next generation of automated defense tools. In this role, you will not only identify and patch critical vulnerabilities but also architect novel, customer-facing agentic systems that empower Google Workspace and Cloud customers to defend their own environments. You will provide strong technical leadership, collaborate closely with product engineering and threat intelligence teams, and mentor junior engineers to scale our defensive capabilities.
Responsibilities:
- Drive the technical strategy and threat modeling for Workspace account security, identifying systemic weaknesses in authentication, recovery, and API integration paths.
- Lead vulnerability research and adversarial simulation to expose novel account takeover (ATO) and "Made for Abuse" (MFA) techniques.
- Design and build advanced agentic systems, debugging tools, and simulators to autonomously detect, analyze, and mitigate complex account security threats.
- Architect and deploy customer-facing agentic tools that empower Workspace and Google Cloud customers to proactively monitor and secure their own environments.
- Lead the investigation of high-severity account security incidents, developing robust, long-term mitigations and patches in collaboration with Product Engineering teams.