Senior Security Engineer, Google Distributed Cloud Air-gapped Compliance

Google Google · Big Tech · New York, NY +2

Senior Security Engineer for Google Distributed Cloud Air-Gapped, focusing on compliance with public sector, defense, critical infrastructure, and financial sector regulations (NIST SP 800-53-FedRAMP, ISO). Responsibilities include establishing governance frameworks, conducting risk assessments, overseeing engineering projects for compliance, and advising on secure implementations. Requires experience with security assessments, network security, and coding.

What you'd actually do

  1. Review and provide inputs about requirements across relevant regulatory frameworks and technical standards and determine their applicability to GDC air-gapped.
  2. Conduct implementation reviews and report on their findings.
  3. Conduct risk assessments, identify opportunities for compliance process improvements, and lead engineering projects to implement solutions for monitoring, audit tooling, reporting, alerting, and evidence generation/collection.
  4. Oversee engineering projects from a technical compliance perspective, collaborate with engineering teams on security and compliance improvements, and advise on compliant and secure implementation options during design reviews.
  5. Participate in compliance meetings, contribute subject matter expertise for decision-making and certification audits, support security assessments, develop an understanding of various compliance regimes (commercial, U.S. government, foreign governments, ISO), and assist with incident and vulnerability response.

Skills

Required

  • security assessments
  • security design reviews
  • threat modeling
  • security engineering
  • computer and network security
  • security protocols
  • coding experience

Nice to have

  • compliance

What the JD emphasized

  • compliance requirements for public sector, defense industry, critical national infrastructure, and financial sector customers
  • governance frameworks aligned with NIST SP 800-53-FedRAMP and other standards for continuous compliance
  • specialized knowledge of GDC air-gapped security protocols, architecture, security regulations, compliance controls, system-level designs, and certification audits across commercial, U.S. government, foreign governments, and International Organization for Standardization (ISO) standards