Senior Security Engineer, Firmware Security, Cloud CISO
Google · Kirkland, WA
$174,000–$253,000from the description
Jul 14, 2026
Kirkland, WA
Jul 21, 2026
What this job asks for AI summary
A senior individual-contributor role on Google Cloud's security engineering team, focused on keeping Cloud products and their underlying infrastructure secure. Day-to-day work involves conducting security assessments, design reviews, and vulnerability testing across a range of software and technology stacks, using methods such as reverse engineering, fuzzing, static analysis, and AI-assisted scanning. The role suits an experienced security engineer comfortable with both hands-on technical work and providing guidance to other engineers.
Senior level · 5+ years · Seattle-Tacoma-Bellevue, WA · Full-time
“or” means any one of them counts — you don't need all of them.
Posted 2 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 270 people in the Seattle-Tacoma-Bellevue, WA area plausibly meet what this posting asks for (information security analysts). range 80–480
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $165,338 (middle half $132,613–$190,632). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (10)
The posting lists Kirkland WA, Seattle WA, and Sunnyvale CA as location options; Seattle-Tacoma-Bellevue CBSA is used as the primary metro given two of the three options fall within it.
Compensation is stated as $174,000–$253,000/year plus a 15% bonus target and equity — the bonus and equity are not reflected in the min/max figures, which capture base salary only.
The degree requirement is 'Bachelor's degree or equivalent practical experience,' which means equivalent experience is explicitly accepted — treated as no hard degree gate.
'5 years of coding experience in one or more general purpose languages' is a hard gate but names no specific language; captured as a generic skill rather than a named technology.
The role title says 'Senior' but the posting's own level descriptor reads 'Mid — experience driving progress, solving problems, and mentoring more junior team members.' The seniority assessment is based on the actual requirements (5 years, security engineering scope), which support Senior; the internal level label is noted here as an anomaly.
Reverse engineering, fuzzing, static analysis, and agentic AI scanning appear in the Responsibilities section rather than under Minimum or Preferred Qualifications, so they are treated as preferred/contextual rather than hard gates.
Gemini and agentic AI tools appear only in the Responsibilities narrative ('Leverage Gemini and other AI tools…'), not in any qualifications section.
Applied cryptography and authentication appear only under Preferred Qualifications.
The alt SOC (15-1252 Software Developers) is noted because the role requires 5 years of coding experience and involves code review and vulnerability testing, giving it a meaningful software-engineering dimension alongside its primary security focus.
Ignored 3 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): general purpose programming language, reverse engineering, static analysis.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.