Google logo

Senior Offensive Security Consultant, Mandiant, Google Cloud

Google
Chicago, IL, USAHybridSoftware EngineeringMid-Level$138,000 - $200,000Posted: 8 days ago
Apply NowOpens Google's site

About the role

Senior Offensive Security Consultant, Mandiant, Google Cloud

corporate\_fare

Google

place

Boulder, CO, USA

; New York, NY, USA

; +5 more

laptop\_windows

Remote eligible

info\_outline

X

The application window will be open until at least September 10, 2026. This opportunity will remain online based on business needs which may be before or after the specified date.

Applicants in the County of Los Angeles: Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.

Applicants in San Francisco: Qualified applications with arrest or conviction records will be considered for employment in accordance with the San Francisco Fair Chance Ordinance for Employers and the California Fair Chance Act.Note: By applying to this position you will have an opportunity to share your preferred working location from the following:

In-office locations: Boulder, CO, USA; New York, NY, USA; Chicago, IL, USA; Atlanta, GA, USA.

Remote location(s): Arizona, USA; California, USA; Colorado, USA.

Minimum qualifications:

Bachelor's degree in Computer Science, Information Systems, Cybersecurity, a related technical field, or equivalent practical experience.

5 years of experience with pen testing and red teaming functions, including network, web application, mobile, cloud, social engineering, scripting, or tool development.

Experience with tools used for wireless, web application, and network security testing.

Ability to travel up to 20% of the time.

Preferred qualifications:

Certifications related to offensive security including OSCE, OSEP, OSEE, OSCP, CCSAS, CCT, INF, or relevant SANS courses.

5 years of experience in three of the following security areas: network, web application/mobile, cloud, social engineering, scripting, tool development.

Experience in four or more of the following: network protocols, threat intelligence analysis, system and network administration, project management, developing applications, technical incident response processes, source code review, reverse engineering.

Experience implementing or assessing information security implementation or assessment of security controls.

Experience with developing documentation and explaining technical details in a concise manner.

About the job

Mandiant's Red Team delivers adversarial emulation engagements. This may involve delivering a Threat Intel-led Red Team for a large enterprise, preparing command and control infrastructure, and developing social engineering campaigns. The execution of the exercise can involve executing phishing campaigns and attempting to compromise internet-facing systems.

When internal to the environment, it includes conducting privilege escalation and lateral movement within customer networks, hunting for objectives with little to no information provided by the customer, and exfiltrating data from the network—all while avoiding detection from the customer security operations teams.

Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world.

Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

US: $138000 - $200000 (USD) + 15% bonus target + equity + benefits

Learn more about benefits at Google.

Responsibilities

Perform red and purple team assessments, assumed breach assessments (e.g., red team engagements with a pre-deployed implant), ransomware readiness reviews (e.g., assessing susceptibility to modern ransomware threats), threat analysis, and social engineering assessments.

Conduct external and internal wireless assessments, web and mobile applications testing, and embedded system assessments.

Recognize and safely utilize attacker tools, tactics, and procedures.

Develop comprehensive and accurate reports and presentations for both technical and executive audiences.

Advise clients on security practices for remediating discovered issues.

Minimum requirements

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or equivalent experience
  • 5 years of pen testing and red teaming experience across network, web, mobile, cloud, social engineering, scripting, or tool development
  • Experience with wireless, web application, and network security testing tools and ability to travel up to 20%

This listing was parsed by AI and may not be complete. Check the official posting on Google's site for the most accurate information.

Ready to apply?
Applications are handled on Google's own careers site.
Apply Now

More roles at Google

Principal Engineer, AlloyDB
Chicago, IL, USA · Hybrid
View →
Marketing and Communications Manager, GCE Marketing, Global Commercial Enablement
Chicago, IL, USA · Hybrid
View →
Applied AI and Commercial Operations Specialist
Chicago, IL, USA · Hybrid
View →
Global Data Transformation Lead, Large Customer Sales
Chicago, IL, USA · Hybrid
View →
Partner Engineering Manager, Universal Commerce Protocol
Chicago, IL, USA · Hybrid
View →