Note: By applying to this position you will have an opportunity to share your preferred working location from the following:
In-office locations: Zürich, Switzerland.
Remote location(s): Switzerland.
- Bachelor's degree in Computer Science, Cybersecurity, a related field, or equivalent practical experience.
- 5 years of experience in threat intelligence, intrusion analysis, vulnerability researcher, or a similar security role.
- Experience with threat intelligence platforms and tools (e.g., VirusTotal, SIEMs).
- Knowledge of Android and Chrome security and internals.
- Deep understanding of attacker Tactics, Techniques, and Procedures (TTPs).
- Proven ability to lead complex threat research projects independently.
- Strong analytical, problem-solving, and communication skills.
- Skills in malware analysis, reverse engineering, or vulnerability analysis.
- Proficiency in scripting or querying languages (e.g., Python, GoogleSQL).
Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
Join the Google Threat Intelligence Group's (GTIG) Exploits Mission. The Exploits Mission focuses on protecting users from targeted exploitation, primarily from government-backed attackers and Commercial Surveillance Vendors (CSVs), through the detection, analysis, and ultimate prevention of vulnerabilities and exploits, with a special focus on 0-day attacks.
We provide timely, actionable intelligence and coordinate with internal and external partners to fix critical vulnerabilities and secure user devices.
As a Security Engineer on our team, you will conduct in-depth research on threat groups, their Tactics, Techniques, and Procedures (TTPs), and the malware they employ. You'll utilize Google's powerful internal intelligence platforms, Nirvana and mGraph, to model threat activity and generate actionable insights. This role involves close collaboration with various teams across GTIG and Google to develop and implement effective countermeasures, contributing directly to threat disruption and enhancing our collective security posture. We are looking for engineers passionate about threat research who can lead projects and mentor others.
- Lead complex technical analyses, modeling threat activity, TTPs, and Indicators of Compromise (IOCs) across internal platforms (mGraph, Nirvana).
- Create and deploy detection signatures (autoqueries, Watchtower rules) to maintain visibility over threat actors and assist in closing security gaps.
- Produce polished, high-quality technical intelligence documentation and actor profiles to deliver actionable insights to internal and external stakeholders.
- Influence technical direction within your scope, mentor junior engineers, and collaborate with cross-functional Google teams to support threat disruption efforts. Collaborate with security engineers and product teams in designing innovative exploit mitigations.
- Identify and execute opportunities for continuous improvement: analytic collection, process optimization, and automation.
Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Google's EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our Accommodations for Applicants form.