Skip to main content
Posted 14 June, 2026
Google

Staff Security Engineer, Office of the Finance CISO

New York NY USA Full Time

Minimum qualifications:

  • Bachelor's degree or equivalent practical experience.
  • 8 years of experience with security assessments or security design reviews or threat modeling.
  • 8 years of experience with security engineering, computer and network security and security protocols.
  • 8 years of coding experience in one or more general purpose languages.
  • 3 years of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.

Preferred qualifications:

  • Experience in large-scale infrastructure security and vendor risk management.
  • Experience in security architecture, risk management, and compliance frameworks (e.g., Sarbanes-Oxley Act (SOX), General Data Protection Regulation (GDPR)).

About the job

Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

As a Staff Security Engineer, you will drive the security strategy for Google’s global financial infrastructure. You will act as a strategic liaison between Enterprise cyber-security teams, Product Area (PA) cyber-security teams, and business units, ensuring that Google’s financial data remains secure and processes stay compliant. You will focus on safeguarding massive-scale migrations, maturing third-party Software-as-a-Service (SaaS) governance, and architecting security boundaries for next-generation agentic AI integrations within the finance domain.

Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

US: $207000 - $301000 (USD) + 20% bonus target + bonus + equity + benefits

Learn more about benefits at Google.

Responsibilities

  • Define and own the product area cyber-security strategy, setting security policies and standards. Influence enterprise security strategy with product area level needs.
  • Establish and drive a continuous, harmonized view of the cyber-security posture for the Finance Product Area. Identify key security gaps in people, processes, and technology.
  • Act as the Pillar Point of Contact (PoC) for the Product Area Security Scorecard (PASS) to develop and execute remediation plans.
  • Scope and oversee strategic remediation projects, ensuring integration of security controls from ideation to operation. Act as a technical expert across Corporate Engineering, Finance, and Enterprise Security to remediate systemic risks.
  • Own product area level risk committees and represent the product area in Enterprise Cyber-security Risk Forums and Audits.
Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Google's EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our Accommodations for Applicants form.