Staff Security Engineer

3 Months ago • 8-8 Years • Cyber Security

Job Summary

Job Description

As a Staff Security Engineer at YouTube, you'll be responsible for identifying security issues and implementing security controls, tools, and services to improve security systems and processes. You'll also lead the security strategy for YouTube, review and develop secure operational practices, and provide security guidance for engineers and support staff. You'll lead and consult on security incidents across YouTube products, responding to vulnerabilities with repos, mitigation, and hardening. You'll engage with pen testing teams to identify vulnerabilities and use techniques including reverse engineering, fuzzing, and static analysis. You'll also review designs for security gaps and explore foundational/Large Language Model (LLM) models for identifying security gaps in product areas.
Must have:
  • Bachelor's degree or equivalent experience
  • 8 years of experience with security assessments, design reviews, or threat modeling
  • 8 years of experience with security engineering, computer and network security, and security protocols
  • 8 years of coding experience in one or more general purpose languages
  • 3 years of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment
  • Identify security issues and implement and design security controls, tools, and services
  • Lead the security strategy for YouTube
  • Review and develop secure operational practices, and provide security guidance for engineers and support staff
  • Lead and consult on security incidents across YouTube products
Good to have:
  • Technical Security Certifications (OSCP, SANS-SEC460/SEC542/SEC560/SEC588, etc.)
  • Experience in development with a focus on Secure Software Development Lifecycle (SSDLC)
  • Experience in security skills (e.g., analysis, debugging, tracing)
  • Understanding of full software stack from devices (embedded, mobile, web) to frontend serving stack, back-end, video streaming systems, global networking, crypto, protocols
  • Ability to lead teams of people in ambiguous situations through influence and not authority
  • Excellent communication skills and a data-driven problem solving approach towards complex challenges
  • Respond to vulnerabilities with repos, mitigation, and hardening
  • Engage with pen testing teams to identify vulnerabilities and use techniques including reverse engineering, fuzzing, and static analysis
  • Review designs for security gaps, both with one-time and longer term engagements
  • Explore foundational/Large Language Model (LLM) models for identifying security gaps in product areas

Job Details

Minimum qualifications:

  • Bachelor's degree or equivalent practical experience.
  • 8 years of experience with security assessments or security design reviews or threat modeling.
  • 8 years of experience with security engineering, computer and network security and security protocols.
  • 8 years of coding experience in one or more general purpose languages.
  • 3 years of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.

Preferred qualifications:

  • Technical Security Certifications (OSCP, SANS-SEC460/SEC542/SEC560/SEC588, etc.).
  • Experience in development with a focus on Secure Software Development Lifecycle (SSDLC).
  • Experience in security skills (e.g., analysis, debugging, tracing).
  • Understanding of full software stack from devices (embedded, mobile, web) to frontend serving stack, back-end, video streaming systems, global networking, crypto, protocols.
  • Ability to lead teams of people in ambiguous situations through influence and not authority.
  • Excellent communication skills and a data-driven problem solving approach towards complex challenges.

About the job

Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

The YouTube Security Engineering team builds and deploys a combination of reactive and proactive systems to manage security threats against the platform and the community. Whereas common practice in fighting abuse relies heavily on enforcement, the team is investing in innovative strategies and designs for prevention. The YouTube teams design solutions and deploy large systems that span multiple Google clusters, thousands of Google employees, millions of creators and billions of users. To succeed, the security team must recognize and neutralize the greatest security threats facing the platform, while promoting a culture of responsibility and the application of security best-practices throughout YouTube.

At YouTube, we believe that everyone deserves to have a voice, and that the world is a better place when we listen, share, and build community through our stories. We work together to give everyone the power to share their story, explore what they love, and connect with one another in the process. Working at the intersection of cutting-edge technology and boundless creativity, we move at the speed of culture with a shared goal to show people the world. We explore new ideas, solve real problems, and have fun — and we do it all together.

Responsibilities

  • Identify security issues and implement and design security controls, tools, and services to improve security systems and processes.
  • Lead the security strategy for YouTube. Review and develop secure operational practices, and provide security guidance for engineers and support staff.
  • Lead and consult on security incidents across YouTube products. Respond to vulnerabilities with repos, mitigation, and hardening.
  • Engage with pen testing teams to identify vulnerabilities and use techniques including reverse engineering, fuzzing, and static analysis.
  • Review designs for security gaps, both with one-time and longer term engagements. Explore foundational/Large Language Model (LLM) models for identifying security gaps in product areas.

Similar Jobs

DAZN - Sr Fullstack Developer | React.js | Node.js

DAZN

Hyderabad, Telangana, India (On-Site)
4 Months ago
Rocket Science - Software Engineer (Full-stack)

Rocket Science

New York, New York, United States (Hybrid)
3 Months ago
Google - Senior Software Engineer, Full Stack, Payments

Google

(On-Site)
3 Months ago
American Express - TCPS Analyst

American Express

Gurugram, Haryana, India (Hybrid)
4 Months ago
Axinous - Senior Manager, Site Reliability Engineering

Axinous

Bengaluru, Karnataka, India (On-Site)
3 Months ago
Salesforce - Physical Security Senior Administrator

Salesforce

San Francisco, California, United States (On-Site)
3 Months ago
Mayhem Studios - Security Engineer-II

Mayhem Studios

Bengaluru, Karnataka, India (On-Site)
7 Months ago
Axinous - Staff Development Software Engineer - C/Networking

Axinous

Sahibzada Ajit Singh Nagar, Punjab, India (On-Site)
3 Months ago
ByteDance - Product Solutions Architect - Enterprise Security

ByteDance

Singapore (On-Site)
3 Months ago
PwC - Cybersecurity-IAM - Sailpoint Developer-Senior Associate-Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

CloudHire - Full Stack Developer

CloudHire

Pune, Maharashtra, India (Remote)
4 Months ago
Meta - Software Engineer, iOS

Meta

Seattle, Washington, United States (On-Site)
3 Months ago
ION - SharePoint/Power Platform Developer  (366)

ION

New York, New York, United States (Hybrid)
4 Months ago
Meta - Software Engineer, iOS

Meta

Menlo Park, California, United States (On-Site)
3 Months ago
Buckman - Analista de Desenvolvimento de Software

Buckman

Sumaré, State Of São Paulo, Brazil (On-Site)
3 Months ago
Hitachi - Java Developers

Hitachi

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Thatgamecompany - Senior Multiplayer Engineer

Thatgamecompany

(Remote)
5 Months ago
Fiery - Principal Software Engineer

Fiery

Bengaluru, Karnataka, India (Hybrid)
4 Months ago
MIPS - Staff Engineer – DevOps

MIPS

Austin, Texas, United States (On-Site)
3 Months ago
Eleven Labs - FullStack Engineer (Frontend Leaning)

Eleven Labs

(Remote)
6 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Zürich, Zurich, Switzerland

PwC - Senior Associate / Manager Deals Analytics

PwC

Zürich, Zurich, Switzerland (On-Site)
3 Months ago
Google - Senior Data Scientist, Ads Metrics

Google

Zürich, Zurich, Switzerland (On-Site)
3 Months ago
PwC - Senior Manager - Data Strategy & Management

PwC

Zürich, Zurich, Switzerland (On-Site)
4 Months ago
PwC - PaPM Role

PwC

Zürich, Zurich, Switzerland (On-Site)
4 Months ago
Nagarro - Staff Consultant ,SAP Industry Solutions

Nagarro

Switzerland (Remote)
4 Months ago
Google - Senior Software Engineer

Google

Zürich, Zurich, Switzerland (On-Site)
3 Months ago
PwC - Manager - Insurance Consulting (P&C Retail & Commercial)

PwC

Zürich, Zurich, Switzerland (On-Site)
4 Months ago
PwC - Transfer Pricing Associate / Senior Associate

PwC

Zürich, Zurich, Switzerland (On-Site)
4 Months ago
Google - Apprenticeship in Digital Business, Entwickler:in EFZ, August 2025

Google

Zürich, Zurich, Switzerland (On-Site)
3 Months ago
PwC - (Senior) Associate Advisory FS Risk Consulting Team

PwC

Zürich, Zurich, Switzerland (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Axinous - Principal Software Engineer - Automation, Python

Axinous

Bengaluru, Karnataka, India (Hybrid)
3 Months ago
Nagarro - Information Security Officer (m/f/d)

Nagarro

Germany (Remote)
4 Months ago
PwC - Financial Services GRC Senior Associate

PwC

Makati, Metro Manila, Philippines (On-Site)
4 Months ago
PwC - FY25 - Talent Pool - Consulting - Associate

PwC

Jakarta, Jakarta, Indonesia (On-Site)
4 Months ago
Anavation - Deputy Program Manager

Anavation

Reston, Virginia, United States (On-Site)
4 Months ago
undefined - Senior Application Security Engineer

Hyderabad, Telangana, India (On-Site)
4 Months ago
PwC - Bilingual Technology Strategy & Transformation Director

PwC

Montreal, Quebec, Canada (On-Site)
4 Months ago
PwC - IN-Senior Associate– VDI Engineer–Strategy & Governance- Advisory - Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Dew Software - IT Security Engineer

Dew Software

Fremont, California, United States (Hybrid)
3 Months ago
PwC - IN-Senior Associate_ITGC _Strategy and Governance_ Advisory_Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

About The Company

A problem isn't truly solved until it's solved for all. Googlers build products that help create opportunities for everyone, whether down the street or across the globe. Bring your insight, imagination and a healthy disregard for the impossible. Bring everything that makes you unique. Together, we can build for everyone.

View All Jobs

Get notified when new jobs are added by Google

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug