Senior Strategic AppSec Consultant, Mandiant, Google Cloud

Google LLC
  • Cambridge, MA
    3 days ago

    Job Description

    Senior Strategic AppSec Consultant, Mandiant, Google Cloud

    share

    Share Senior Strategic AppSec Consultant, Mandiant, Google Cloud

    • linkCopy link
    • emailEmail a friend

    corporate_fareGoogleplaceNew York, NY, USA; Atlanta, GA, USA; +3 more; +2 more

    bar_chartMid

    Mid

    Experience driving progress, solving problems, and mentoring more junior team members; deeper expertise and applied knowledge within relevant area.

    Apply

    share

    Share Senior Strategic AppSec Consultant, Mandiant, Google Cloud

    • linkCopy link
    • emailEmail a friend

    info_outline

    XNote: By applying to this position you will have an opportunity to share your preferred working location from the following: New York, NY, USA; Atlanta, GA, USA; Cambridge, MA, USA; Reston, VA, USA.

    Minimum qualifications:

    • Bachelors degree in Computer Science, Information Systems, Cybersecurity, a related technical field, or equivalent practical experience.
    • 5 years of experience assessing and developing application security (AppSec) programs and vulnerability management architectures.
    • 5 years of experience in the delivery of cyber outcomes, identification of mission risks, and development of solutions.
    • Ability to travel up to 30% of the time.

    Preferred qualifications:

    • Experience in communicating strategic roadmaps to stakeholders.
    • Experience in vulnerability management, architect governance structures, remediation SLAs, and risk prioritization workflows.
    • Familiarity of DevSecOps and infrastructure, and deploying and maintaining security testing (SAST/DAST/SCA) across hybrid and multi-cloud ecosystems.
    • Familiarity in AI/ML security of GenAI workloads, MLSecOps, and autonomous agents utilizing emerging AI frameworks and testing tools.
    • Knowledge in threat modeling, and applying OWASP Top 10 and CWE methodologies to integrate security controls into Agile pipelines.

    About the job

    As a Senior Strategic AppSec Consultant, you will lead consulting engagements and deliver results that align with the clients needs and risk profiles, with a specific focus on Application Security (AppSec) and Vulnerability Management. You will develop roadmaps, recommendations, and business strategies to drive enhancements in secure software development lifecycles (SDLC) and comprehensive vulnerability management programs. Your role involves developing policies, procedures, and standards in line with industry best practices, as well as implementing continuous security testing strategies across cloud and on-premises environments. You will identify and articulate AppSec best practices-such as Threat Modeling, DevSecOps integration, and Secure Coding-while identifying performance enhancement opportunities for Vulnerability Management programs.

    Furthermore, you will work closely with clients to implement, maintain, and optimize solutions across various platforms and collaborate with cross-functional teams to develop effective cybersecurity controls and measures with a specific focus on Application Security (AppSec), Vulnerability Management, and the secure adoption of Artificial Intelligence (AI) platforms. Your role involves developing policies, procedures, and standards in line with industry best practices (such as the NIST AI RMF), as well as implementing continuous security testing strategies.

    Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiants cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industrys best security validation ensures that Mandiant knows more about todays advanced threats than anyone.

    Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

    US: $138000 - $200000 (USD) + 15% bonus target + equity + benefits

    Learn more about benefits at Google.

    Responsibilities

    • Lead security engagements and establish Vulnerability Management governance, remediation SLAs, and continuous scanning strategies.

    • Architect secure DevSecOps pipelines by seamlessly integrating SAST, DAST, and SCA tooling, and map application landscapes to address supply chain risks.

    • Facilitate advanced AI/ML threat modeling (e.g., OWASP Top 10 for LLMs) to secure generative AI deployments, MLOps pipelines, and autonomous agents.

    • Conduct comprehensive architecture security reviews and gap analyses to mitigate risks during digital transformations and define metrics for risk reduction.

    • Collaborate with engineering teams to advise on enterprise vulnerability scanners, implement actionable mitigation strategies, and evaluate AI-driven security tooling.

    Information collected and processed as part of your Google Careers profile, and any job applications you choose to submit is subject to Googles Applicant and Candidate Privacy Policy.

    Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See also Googles EEO Policy, Know your rights: workplace discrimination is illegal, Belonging at Google, and How we hire.

    If you have a need that requires accommodation, please let us know by completing our Accommodations for Applicants form.

    Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.

    To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes.

    Equity is granted exclusively and discretionarily by Alphabet Inc. on the basis of an agreement concluded between you and Alphabet Inc. Alphabet Inc. is your sole contractual partner with respect to equity grants. GSU grants are not guaranteed, are discretionary, are subject to approval by the Alphabet Inc. board of directors or its delegate, the terms of the relevant Alphabet Inc. stock plan, and your grant agreement. They have no impact on statutory payments. Current or past grants do not confer an acquired right.

    Numbers & Facts

    LocationCambridge, MA

    Skills

    • Applications Securityunmatched
    • Artificial Intelligence (AI)unmatched
    • Artificial Intelligence (AI) Agentsunmatched
    • Best Practicesunmatched
    • Business Strategyunmatched
    • Cloud Computingunmatched
    • Communication Skillsunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Consultingunmatched
    • Cross-Functionalunmatched
    • Defense Intelligenceunmatched
    • Ecosystemsunmatched
    • English Languageunmatched
    • Equal Employment Opportunity (EEO)unmatched
    • Establish Prioritiesunmatched
    • Gap Analysisunmatched
    • Geneticsunmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Internet Securityunmatched
    • Machine Toolunmatched
    • Metricsunmatched
    • Multiplatform/Cross-Platformunmatched
    • Policy Developmentunmatched
    • Procedure Developmentunmatched
    • Recruiting/Staffing Agencyunmatched
    • Regulatory Requirementsunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Secure Codingunmatched
    • Security Architectureunmatched
    • Security Attacksunmatched
    • Service Level Agreement (SLA)unmatched
    • Software Developmentunmatched
    • Software Development Lifecycle (SDLC)unmatched
    • Stock Purchase Plansunmatched
    • Strategic Analysisunmatched
    • Supply Chainunmatched
    • Test Strategyunmatched
    • Test Toolsunmatched
    • Threat Modelingunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Vulnerability Scannersunmatched
    • Willing to Travelunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder