Careers
Careers

job details

Back to jobs search

Jobs search results

2,815 jobs matched
Back to jobs search

Security Consultant, Application and Vulnerability Management, Public Sector

GoogleNew York, NY, USA

Minimum qualifications:

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, a related technical field, or equivalent practical experience.
  • 5 years of experience in delivering cyber outcomes, identifying mission risks, and devising solutions.
  • Experience with evaluating infrastructure and web application security vulnerabilities, assessing risk and impact, developing mitigation strategies, and implementing remediation.
  • Experience with vulnerability management and web application security assessment tools (e.g., Nessus, Rapid7, InsightAppSec, Burp Suite, OWASP ZAP) and methodologies.

Preferred qualifications:

  • Experience in implementing industry-leading practices around cyber risks and cloud security for clients’ cloud security frameworks using industry standards.
  • Experience with cloud governance, including Cloud-Native Application Protection Platforms (CNAPP) and ability to convey governance principles to cloud computing in terms of policies.
  • Experience in Cloud technologies and native applications such as containers, functions, Kubernetes, and app services.
  • Experience with programming frameworks and scripting such as Python and PowerShell to automate vulnerability management tasks.
  • Experience with spreadsheets, for performing data analysis through VLookup and pivot tables.
  • Excellent time and project management skills.

About the job

In this role, you will support the Vulnerability Management program for a large municipality and help them manage the threats posed by software and infrastructure vulnerabilities with a focus on risk for prioritization of remediation. You will research, analyze and brief management and team members on relevant Common Vulnerabilities and Exposures (CVE’s), Common Vulnerability Scoring System (CVSS) ratings, Vector Strings, NVD, Mitre, attack vectors and mitigations for various technologies. Technical familiarity with vulnerability management and application security testing tools will be required to help design, architect and build scanning infrastructure and tools (i.e., manage, configure and conduct scans across various systems and networks).

Google Public Sector brings the magic of Google to the mission of government and education with solutions purpose-built for enterprises. We focus on helping United States public sector institutions accelerate their digital transformations, and we continue to make significant investments and grow our team to meet the complex needs of local, state and federal government and educational institutions.

The US base salary range for this full-time position is $132,000-$194,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.

Responsibilities

  • Conduct analysis to assess vulnerability impact and risk through industry research, and generate reports in scanning tools.
  • Present technical briefings and written vulnerability reports to team members and agency stakeholders including intel research, risk assessment, CVE’s, vendor hardware/software, Open Web Application Security Project (OWASP) and industry trends.
  • Apply cyber security standards and best practices to develop remediation plans for technical and web application vulnerabilities.
  • Work with agencies to advocate the vulnerability program around areas of cybersecurity posture, program enhancement, risk reduction, vulnerability management scanning tool performance, scan results, credentialed scans, triage scan performance issues, socialize risk and remediation, and other vulnerability management issues.

Information collected and processed as part of your Google Careers profile, and any job applications you choose to submit is subject to Google's Applicant and Candidate Privacy Policy.

Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See also Google's EEO Policy, Know your rights: workplace discrimination is illegal, Belonging at Google, and How we hire.

If you have a need that requires accommodation, please let us know by completing our Accommodations for Applicants form.

Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.

To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes.

Google apps
Main menu