Staff Security Engineer, Office of the Finance CISO
Minimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 8 years of experience with security assessments or security design reviews or threat modeling.
- 8 years of experience with security engineering, computer and network security and security protocols.
- 8 years of coding experience in one or more general purpose languages.
- 3 years of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.
Preferred qualifications:
- Experience in large-scale infrastructure security and vendor risk management.
- Experience in security architecture, risk management, and compliance frameworks (e.g., Sarbanes-Oxley Act (SOX), General Data Protection Regulation (GDPR)).
About the job
Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
As a Staff Security Engineer, you will drive the security strategy for Google’s global financial infrastructure. You will act as a strategic liaison between Enterprise cyber-security teams, Product Area (PA) cyber-security teams, and business units, ensuring that Google’s financial data remains secure and processes stay compliant. You will focus on safeguarding massive-scale migrations, maturing third-party Software-as-a-Service (SaaS) governance, and architecting security boundaries for next-generation agentic AI integrations within the finance domain.
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.US: $207000 - $301000 (USD) + 20% bonus target + bonus + equity + benefits
Learn more about benefits at Google.
Responsibilities
- Define and own the product area cyber-security strategy, setting security policies and standards. Influence enterprise security strategy with product area level needs.
- Establish and drive a continuous, harmonized view of the cyber-security posture for the Finance Product Area. Identify key security gaps in people, processes, and technology.
- Act as the Pillar Point of Contact (PoC) for the Product Area Security Scorecard (PASS) to develop and execute remediation plans.
- Scope and oversee strategic remediation projects, ensuring integration of security controls from ideation to operation. Act as a technical expert across Corporate Engineering, Finance, and Enterprise Security to remediate systemic risks.
- Own product area level risk committees and represent the product area in Enterprise Cyber-security Risk Forums and Audits.

