HireFT
Browse JobsHow it worksPricingAboutSuccess Stories
    Back to jobs
    GO

    Google

    Technology

    Senior Strategic Security Consultant, Mandiant, Google Cloud

    Atlanta, United StatesOn-SiteFull-time5+ yrs experiencePosted 6d ago
    All Google jobs

    Job description

    info_outline
    XThe application window will be open until at least October 2, 2026. This opportunity will remain online based on business needs which may be before or after the specified date.Note: By applying to this position you will have an opportunity to share your preferred working location from the following:
    In-office locations: Atlanta, GA, USA.
    Remote location(s): United States.

    Minimum qualifications:

    • Bachelor's degree in Computer Science, Information Systems, Cyber-security, related technical field, or equivalent practical experience.
    • 5 years of experience assessing and developing cyber-security solutions and programs across security domains.
    • 5 years of experience in delivering cyber outcomes, identifying mission risks, and devising solutions.
    • Ability to travel up to 30% of the time as needed.

    Preferred qualifications:

    • Certifications related to specific cloud platforms.
    • Experience implementing industry-leading practices around cyber risks and cloud security for clients’ cloud security frameworks using industry standards.
    • Experience with cloud governance, with the ability to convey governance principles to cloud computing in terms of policies.
    • Experience deploying and maintaining security testing infrastructures (SAST, DAST, SCA, network/container vulnerability scanners) across hybrid ecosystems and multi-cloud environments.
    • Proficiency in the Open Web Application Security Project (OWASP) Top 10, Common Weakness Enumeration (CWE), Threat Modeling Methodologies, and integrating security controls into Agile and Developer Security Operation environments.

    About the job

    As a Mandiant Strategic Security Consultant, you will lead and support projects on behalf of clients that assess, test, or build their security programs. Project teams may range from 2 to 5 colleagues. Clients will range from start-up companies looking to supplement their security team to Fortune 100 companies that need fresh ideas to enhance their perspective on the security program. You will provide guidance and advice to our client on best practices and managing the risks for their security program.
    In this role, you will lead strategic consulting engagements focused on Applied Security (AppSec) and Vulnerability Management. You will design secure SDLC roadmaps, establish industry-standard policies (Developer Security Operations, Threat Modeling), and collaborate with clients to implement continuous security testing across cloud and on-prem platforms.Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.Individual pay is determined by factors including job-related skills, experience, and relevant education or training.
    US: $138000 - $200000 (USD) + 15% bonus target + equity + benefits
    Learn more about benefits at Google.

    Responsibilities

    • Lead strategic security consulting engagements, maturity assessments, and gap analyses against industry frameworks (OWASP SAMM, BSIMM, NIST SSDF) to deliver risk-reduction roadmaps for cloud and on-premises environments.
    • Architect and secure Developer Security Operations pipelines by designing technical blueprints and integrating automated security gates (SAST, DAST, SCA) seamlessly into developer workflows.
    • Establish governance structures and facilitated risk-tiering workshops to define remediation service-level agreements, exception handling, and prioritization metrics (CVSS, EPSS) across multi-cloud and legacy infrastructure.
    • Support application threat modeling (STRIDE) and architect security reviews early in the Software Development Life Cycle (SDLC) to identify design flaws and provide engineering teams with strategies.
    • Pioneer application landscape discovery and Software Bill of Materials (SBOM) mapping to manage supply chain risks, while advising on the deployment of enterprise AppSec and Virtual Machine technologies (e.g., Qualys, Tenable, Snyk, Checkmarx).

    Job details are sourced from the employer's original posting.

    Open job posting
    GO

    About the company

    Google

    Google is a multinational technology company focusing on search, artificial intelligence, cloud computing, and online advertising. It develops and provides a wide range of internet-related services and products.

    View all Google jobsabout.google
    Industry
    Technology
    Founded
    1998
    Open roles
    3001

    Interested in this role?

    Apply with HireFT

    Free to start — no card required.

    Your fit

    How well do you match?

    Sign in to see how your résumé lines up with this role.