Staff Security Engineer

1 Month ago • 8-8 Years • Cyber Security

About the job

Job Description

The Staff Security Engineer at YouTube's Security Engineering team is responsible for identifying and mitigating security threats across the platform. This involves designing and implementing security controls, tools, and services; leading security strategies; developing secure operational practices; responding to vulnerabilities and security incidents; collaborating with pen testing teams; reviewing designs for security gaps; and exploring LLM models for security improvements. The role requires extensive experience in security assessments, design reviews, threat modeling, security engineering, and coding, as well as leadership and communication skills. The team works to prevent abuse and promote security best practices throughout YouTube, impacting millions of creators and billions of users.
Must have:
  • 8+ years security experience
  • Security assessments/design reviews
  • Threat modeling & security engineering
  • Coding expertise (multiple languages)
  • Team leadership/risk analysis
Good to have:
  • Technical Security Certifications
  • SSDLC experience
  • Security skills (analysis, debugging)
  • Understanding of full software stack
  • Leadership in ambiguous situations
  • Excellent communication skills
Not hearing back from companies?
Unlock the secrets to a successful job application and accelerate your journey to your next opportunity.

Minimum qualifications:

  • Bachelor's degree or equivalent practical experience.
  • 8 years of experience with security assessments or security design reviews or threat modeling.
  • 8 years of experience with security engineering, computer and network security and security protocols.
  • 8 years of coding experience in one or more general purpose languages.
  • 3 years of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.

Preferred qualifications:

  • Technical Security Certifications (OSCP, SANS-SEC460/SEC542/SEC560/SEC588, etc.).
  • Experience in development with a focus on Secure Software Development Lifecycle (SSDLC).
  • Experience in security skills (e.g., analysis, debugging, tracing).
  • Understanding of full software stack from devices (embedded, mobile, web) to frontend serving stack, back-end, video streaming systems, global networking, crypto, protocols.
  • Ability to lead teams of people in ambiguous situations through influence and not authority.
  • Excellent communication skills and a data-driven problem solving approach towards complex challenges.

About the job

Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

The YouTube Security Engineering team builds and deploys a combination of reactive and proactive systems to manage security threats against the platform and the community. Whereas common practice in fighting abuse relies heavily on enforcement, the team is investing in innovative strategies and designs for prevention. The YouTube teams design solutions and deploy large systems that span multiple Google clusters, thousands of Google employees, millions of creators and billions of users. To succeed, the security team must recognize and neutralize the greatest security threats facing the platform, while promoting a culture of responsibility and the application of security best-practices throughout YouTube.

At YouTube, we believe that everyone deserves to have a voice, and that the world is a better place when we listen, share, and build community through our stories. We work together to give everyone the power to share their story, explore what they love, and connect with one another in the process. Working at the intersection of cutting-edge technology and boundless creativity, we move at the speed of culture with a shared goal to show people the world. We explore new ideas, solve real problems, and have fun — and we do it all together.

Responsibilities

  • Identify security issues and implement and design security controls, tools, and services to improve security systems and processes.
  • Lead the security strategy for YouTube. Review and develop secure operational practices, and provide security guidance for engineers and support staff.
  • Lead and consult on security incidents across YouTube products. Respond to vulnerabilities with repos, mitigation, and hardening.
  • Engage with pen testing teams to identify vulnerabilities and use techniques including reverse engineering, fuzzing, and static analysis.
  • Review designs for security gaps, both with one-time and longer term engagements. Explore foundational/Large Language Model (LLM) models for identifying security gaps in product areas.
View Full Job Description

Add your resume

80%

Upload your resume, increase your shortlisting chances by 80%

About The Company

A problem isn't truly solved until it's solved for all. Googlers build products that help create opportunities for everyone, whether down the street or across the globe. Bring your insight, imagination and a healthy disregard for the impossible. Bring everything that makes you unique. Together, we can build for everyone.

View All Jobs

Get notified when new jobs are added by Google

Similar Jobs

Activision - 2025 US Summer Internship - Software Engineering

Activision, United States (On-Site)

Google - Product Growth Manager, Google Ads

Google, United States (On-Site)

Aristocrat Gaming - Senior Helpdesk Analyst

Aristocrat Gaming, India (Hybrid)

Hasbro - IT Security Engineer - Cloud

Hasbro, United States (On-Site)

Magna International - Sr. Penetration Test Engineer

Magna International, India (On-Site)

The Workshop - Head of Information Security

The Workshop, Spain (Hybrid)

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

NinjaVan - SSE-Fullstack Developer

NinjaVan, India (On-Site)

Paypal - Staff Software Engineer - Java

Paypal, India (Hybrid)

Witzeal - Android Developer

Witzeal, India (On-Site)

CloudHire - Full Stack Developer - Angular & Node

CloudHire, India (Remote)

Sandsoft Games - Senior Full-Stack Developer Web

Sandsoft Games, Saudi Arabia (On-Site)

Performio - Senior Software Engineer

Performio, India (Hybrid)

PortalOne,  Inc  - Unreal Engine Developer

PortalOne, Inc , Norway (On-Site)

Easygo - Social Media Community Manager Kick

Easygo, Australia (On-Site)

Get notifed when new similar jobs are uploaded