Staff Security Engineer, YouTube - Google
San Bruno, CA
About the Job
Minimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 8 years of experience with security assessments or security design reviews or threat modeling.
- 8 years of experience with security engineering, computer and network security and security protocols.
- 8 years of coding experience in one or more general purpose languages.
- 3 years of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.
- 3 years of experience in incident management.
Preferred qualifications:
- Industry-recognized security certifications such as OSCP, SANS GIAC certifications (e.g., GSEC, GPEN, GWAPT).
- Experience with information security incident and threat assessments (incident response, penetration testing, vulnerability assessments).
- Understanding full software stack from devices (embedded, mobile, web) to frontend serving stack, backend, video streaming systems, global networking, crypto, protocols.
About the job
At YouTube, we believe that everyone deserves to have a voice, and that the world is a better place when we listen, share, and build community through our stories. We work together to give everyone the power to share their story, explore what they love, and connect with one another in the process. Working at the intersection of cutting-edge technology and boundless creativity, we move at the speed of culture with a shared goal to show people the world. We explore new ideas, solve real problems, and have fun — and we do it all together.
The YouTube Security engineering team builds and deploys a combination of reactive and proactive systems to manage security threats against the platform and the community. Whereas common practice in fighting abuse relies heavily on enforcement, the team is investing in innovative strategies and designs for prevention. The YouTube teams design solutions and deploy large systems that span multiple Google clusters, Google employees, creators and users. To succeed, the security team must recognize and neutralize the greatest security threats facing the platform, while promoting a culture of responsibility and the application of security best-practices throughout YouTube.
Responsibilities
- Lead the security strategy for YouTube and consult on security incidents across YouTube products.
- Review and develop secure operational practices, provide security guidance to engineers and support staff, and respond to vulnerabilities with appropriate repositories, mitigations, and hardening.
- Engage with penetration testing teams and employ techniques like reverse engineering, fuzzing, and static analysis to identify vulnerabilities.
- Review designs for security gaps, both with one-time and longer term engagements, and surface vulnerability patterns and design them out.
- Explore foundational / LLM models for identifying security gaps in product areas.