Senior Security Engineer, Trust and Safety Workspace
The Trust and Safety Workspace Account Security and Integrity (AIS) team is dedicated to protecting Google Workspace and Cloud customers from account-based threats. The mission is to safeguard the integrity of Workspace accounts by delivering a unified, scalable defense against account hijacking, takeover (ATO), and malicious automation. We operate at the critical intersection of product security and abuse prevention, balancing robust security controls with a frictionless experience for both individual users and enterprise organizations. By studying adversarial behavior and building state-of-the-art telemetry and agentic defense systems, we ensure a secure, trusted, and resilient ecosystem that protects our customers' businesses, data, and users.
As a Senior Security Engineer, you will drive the technical strategy to defend Workspace accounts and protect the Google Workspace and Cloud customers against advanced and evolving threats. Operating at the frontier of account security, adversarial analysis, and agentic AI, you will lead research into account vulnerabilities and pioneer the next generation of automated defense tools. In this role, you will not only identify and patch critical vulnerabilities but also architect novel, customer-facing agentic systems that empower Google Workspace and Cloud customers to defend their own environments. You will provide strong technical leadership, collaborate closely with product engineering and threat intelligence teams, and mentor junior engineers to scale our defensive capabilities.
- Drive the technical strategy and threat modeling for Workspace account security, identifying systemic weaknesses in authentication, recovery, and API integration paths.
- Lead vulnerability research and adversarial simulation to expose novel account takeover (ATO) and "Made for Abuse" (MFA) techniques.
- Design and build advanced agentic systems, debugging tools, and simulators to autonomously detect, analyze, and mitigate complex account security threats.
- Architect and deploy customer-facing agentic tools that empower Workspace and Google Cloud customers to proactively monitor and secure their own environments.
- Lead the investigation of high-severity account security incidents, developing robust, long-term mitigations and patches in collaboration with Product Engineering teams.
Minimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 5 years of experience with security assessments or security design reviews or threat modeling.
- 5 years of experience with security engineering, computer and network security and security protocols.
- 5 years of coding experience in one or more general purpose languages.
- 1 year of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.
Preferred qualifications:
- Master’s degree or PhD in Computer Science, Cybersecurity, or a related technical field, or equivalent practical experience.
- Experience in account security mechanisms, identity and access management (IAM), and modern authentication standards (e.g., OAuth 2.0, OIDC, FIDO/Passkeys, SAML).
- Experience building or deploying AI agents, LLMs, or agentic workflows for security automation, threat detection, or user-facing product features.
- Understanding of anti-abuse systems, bot detection, and mitigations against malicious automation (credential stuffing, bulk creation).
- Ability to identify novel security vulnerabilities (e.g., threat research, bug bounties, security advisories) and implementing systemic engineering fixes.
About the Company
Google is a technology company that specializes in Internet-related services and products, which include online advertising technologies, a search engine, cloud computing, software, and hardware. It is considered one of the Big Five American information technology companies, alongside Amazon, Apple, Meta, and Microsoft.
More jobs at Google
-
Lead Technical Program Manager, Fiber Infrastructure Engineering and Delivery
New York, NY, USA; Addison, TX, USA · · Sep 10, 2026
-
Cloud AI Engineer, Technical Onboarding Center
Bengaluru, Karnataka, India; Hyderabad, Telangana, India; Gurgaon, Haryana, India · · Sep 10, 2026
-
Software Engineering Manager, Gmail Security and Safety
Sunnyvale, CA, USA · · Sep 10, 2026
-
Senior Software Engineer, Full Stack
San Jose, CA, USA · · Sep 10, 2026
-
Software Engineering Manager, Cloud SQL, SQL Server
Kirkland, WA, USA · · Sep 10, 2026