{"id":1290879,"url":"https://alion.io/job/google-security-engineer-google-threat-intelligence","title":"Security Engineer, Google Threat Intelligence","company":{"id":82,"name":"Google","domain":"google.com","url":"https://alion.io/company/google","size_band":"11-50","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Career site","truth_index":{"grade":"B","score":75,"open_postings":113,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":30,"computed_at":"2026-09-30T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Sydney, Australia"],"countries":["AU"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":104000,"max_usd":236000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":1261},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"GCP","optional":false},{"name":"Threat Modeling","optional":false},{"name":"C++","optional":true},{"name":"Python","optional":true},{"name":"Snort","optional":true},{"name":"Suricata","optional":true},{"name":"YARA","optional":true},{"name":"YARA","optional":true}],"status":"live","first_seen_at":"2026-08-07T12:41:54Z","employer_posted_date":"2026-09-26","last_verified_at":"2026-09-30T21:40:30Z","board_verified":true,"closed_at":null,"days_open":54,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":54},"description":"About the job\nOur Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.\nGoogle's Threat Intelligence Group (GTIG) is looking for a threat intelligence analyst for our Koreas Advanced Persistent Threat (APT) mission.\nIn this role, you will produce threat intelligence focusing on serious threats to Google, our products, and our users which are consumed by hundreds of security and abuse teams across the company, all levels of leadership, and externally to the security research industry. You will specialize in thwarting government-backed threats. You will be part of a specialized team at the forefront of tracking cyber threat actors.\nGoogle Cloud accelerates every organization’s ability to digitally transform its business and industry. We deliver enterprise-grade solutions that leverage Google’s cutting-edge technology, and tools that help developers build more sustainably. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.\nResponsibilities\nIdentify, analyze, and document network signals, malware behaviors, and threat reports related to trends and developments in adversary tactics, techniques, and procedures (TTPs).\nProvide clear, actionable, and structured intelligence to product and security teams; assist in ensuring corporate and production systems are safeguarded.\nOwn the analysis efforts of multiple threat actors, and serve as a subject matter expert on how those actors might impact Google and our users.\nEnhance analysis efficiency by conceiving and implementing automation opportunities, developing Proof-of-Concept code, and collaborating with stakeholders to deploy solutions.\nBe capable of quickly identifying personal and team priorities, and able to work on assignments with minimal supervision while maintaining quality and deadlines.\nQualifications\nMinimum qualifications:\nBachelor's degree or equivalent practical experience.\n5 years of experience with security assessments, security design reviews or threat modeling.\n5 years of experience with security engineering, computer and network security and security protocols.\n5 years of experience coding in one or more general purpose languages.\nPreferred qualifications:\nPrior experience in detection engineering with YARA, Snort/Suricata, EDR rule creation.\nExperience in Python, C/C++ or scripting languages.\nExperience in reverse engineering.\nStrong understanding of network fundamentals, techniques for lateral machine movement, malware persistence mechanisms, covert channels, application security and user authentication, command and control techniques.\nVery strong communication and documentation skills.","description_format":"text","description_chars":2997,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":true},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Threat Intelligence","Information Security","Streaming & OTT Platforms","Consumer Internet Groups"],"lifecycle":[{"event":"open","at":"2026-09-26T07:46:53Z"}],"liveness":{"score":10,"band":"cold","label":"Long shot","p_open":1,"p_active":0.287,"p_room":0.36,"age_days":53,"expected_fill_days":30,"reasons":["conf:0","stale_co","velocity","win:tail","crowd:brand"],"computed_at":"2026-09-30T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/google-security-engineer-google-threat-intelligence","json_url":"https://alion.io/job/google-security-engineer-google-threat-intelligence.json","meta":{"generated_at":"2026-10-01T05:14:13Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4934,"day_limit":5000,"remaining_today":66,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}