Senior Strategic Security Consultant, Mandiant, Google Cloud (English)
Summary
Senior consultant advising enterprises and governments on maturing security programs, focusing on AI adoption and cloud security, by assessing risks, designing roadmaps, and implementing SOC/CDC technologies.
As a Mandiant Strategic Security Consultant, you will lead and support projects on behalf of clients that assess, test, or build their security programs. Project teams may range from 2 to 5 colleagues. Clients will range from start-up companies looking to supplement their security team to Fortune 100 companies that need fresh ideas to enhance their perspective on the security program. You will provide guidance and advice to the client on best practices and managing the risks for their security program.
Canada: $166000 - $171000 (CAD) + 15% bonus target + equity + benefits
Learn more about benefits at Google.
- Lead engagements using National Institute of Standards and Technology Artificial Intelligence Risk Management Framework (NIST AI RMF), ISO 42001, and Google Secure AI Framework (SAIF) to establish guardrails safeguarding enterprise AI adoption.
- Evaluate security via threat modeling and secure MLOps. Integrate Mandiant intelligence to enhance model-driven detection and safeguard against adversarial risks like prompt injection.
- Develop scalable strategies and infrastructure roadmaps for core Cyber Defense Center (CDC) and SOC technologies across multi-cloud environments.
- Optimize logging, telemetry, and detection strategies. Stress-test SOC/IR playbooks against real-world threat scenarios informed by frontline intelligence.
- Conduct comprehensive maturity assessments across people, processes, and technology controls while authoring runbooks to empower consulting teams.
Minimum qualifications:
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, related technical field, or equivalent practical experience.
- 5 years of experience assessing and developing cybersecurity solutions and programs across security domains.
- 5 years of experience in delivering cyber outcomes, identifying mission risks, and devising solutions.
- Ability to communicate in English fluently to work with internal partners and customer teams.
- Ability to travel up to 30% of the time as needed.
Preferred qualifications:
- Experience performing AI Security Assessments, including SAST and DAST testing methodology.
- Experience implementing industry-leading practices around cyber risks and cloud security for clients’ cloud security frameworks using industry standards..
- Experience with software development life cycle, including identifying vulnerabilities within code.
- Knowledge of tools used in security event analysis, incident response, computer forensics, network and end-point architecture, or other security operational areas.
- Understanding of cyber defense operations to include the incident response, containment, and remediation process, cyber threat intelligence, or security architecture.