{"schemaVersion":"jobsearcher.job.v1","id":"f717e3847c5a22e6747c5bc3","url":"https://jobsearcher.com/jobs/f717e3847c5a22e6747c5bc3","canonicalUrl":"https://jobsearcher.com/jobs/f717e3847c5a22e6747c5bc3","title":"Security Engineer, Enterprise Detection Engineering","description":"Minimum qualifications:Bachelor's degree or equivalent practical experience.2 years of experience with security assessments or security design reviews or threat modeling.2 years of experience with security engineering, computer and network security and security protocols.2 years of coding experience in one or more general purpose languages.Preferred qualifications:3 years of experience in detection engineering, security operations (SOC), threat hunting, or incident response.Experience building and tuning detections on enterprise surfaces (macOS, Linux, Windows endpoints, Google Workspace/SaaS).Familiarity with the MITRE ATT&CK framework and threat modeling methodologies.Knowledge of AI and agentic systems and concepts.About the jobOur Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.The Enterprise Detection organization monitors Alphabet's first and third party endpoint platforms and systems to detect/prevent cyber threats. Our mission is to safeguard the integrity of Google’s enterprise by defending the endpoint platforms our employees and systems rely on every day via engineering high-fidelity detections that protect Google from human and AI/agentic hackers and exploits at scale.As a Security Engineer in Enterprise Detection, you will be responsible for securing Google's enterprise footprint. This includes corporate endpoints (macOS, Linux, Windows, ChromeOS), off Google and second-party/third-party entities (e.g., Aqs/Bets), and infrastructure powering internal AI services/agents. You will design, implement, and maintain high-fidelity detection to identify external threat actors and insider threats before they cause harm. You will work with minimal assistance to solve well-scoped problems involving multiple interconnected systems, collaborating closely with incident response, enterprise security, and engineering teams. You are expected to execute project work separately, participate in design discussions, and begin developing deep technical expertise in enterprise threat detection. You will be responsible for threat modeling, developing, automating, and maturing detection capabilities end-to-end.Individual pay is determined by factors including job-related skills, experience, and relevant education or training.US: $147000 - $211000 (USD) + 15% bonus target + equity + benefitsResponsibilitiesLearn more about benefits at Google .Scope detection requirements for enterprise surfaces, focusing on high-risk areas such as Insider Exfiltration, Access Abuse, and Malicious Process Execution.Design and implement detection rules for systems involving multiple interconnected components, ensuring comprehensive coverage across enterprise surfaces.Assess security risks separately and justify detection strategies based on threat intelligence and risk models. Design and implement improvements to existing detections to reduce false positives, minimize resource usage (GCU, RAM, Disk), and decrease end-to-end detection latency (targeting P50 Participate in post-exercise analysis (e.g., Red Team, Purple Team) to identify detection gaps, document findings, and implement remediation detections.Propose and implement incremental improvements to detection engineering pipelines, testing frameworks (e.g., synthetic event generation), and automation tooling.Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Google's EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our Accommodations for Applicants form .","company":"Google","rawCompany":"google","city":"San Jose","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-07-16T12:19:08.185Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security Engineer, Enterprise Detection Engineering","description":"Minimum qualifications:Bachelor's degree or equivalent practical experience.2 years of experience with security assessments or security design reviews or threat modeling.2 years of experience with security engineering, computer and network security and security protocols.2 years of coding experience in one or more general purpose languages.Preferred qualifications:3 years of experience in detection engineering, security operations (SOC), threat hunting, or incident response.Experience building and tuning detections on enterprise surfaces (macOS, Linux, Windows endpoints, Google Workspace/SaaS).Familiarity with the MITRE ATT&CK framework and threat modeling methodologies.Knowledge of AI and agentic systems and concepts.About the jobOur Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.The Enterprise Detection organization monitors Alphabet's first and third party endpoint platforms and systems to detect/prevent cyber threats. Our mission is to safeguard the integrity of Google’s enterprise by defending the endpoint platforms our employees and systems rely on every day via engineering high-fidelity detections that protect Google from human and AI/agentic hackers and exploits at scale.As a Security Engineer in Enterprise Detection, you will be responsible for securing Google's enterprise footprint. This includes corporate endpoints (macOS, Linux, Windows, ChromeOS), off Google and second-party/third-party entities (e.g., Aqs/Bets), and infrastructure powering internal AI services/agents. You will design, implement, and maintain high-fidelity detection to identify external threat actors and insider threats before they cause harm. You will work with minimal assistance to solve well-scoped problems involving multiple interconnected systems, collaborating closely with incident response, enterprise security, and engineering teams. You are expected to execute project work separately, participate in design discussions, and begin developing deep technical expertise in enterprise threat detection. You will be responsible for threat modeling, developing, automating, and maturing detection capabilities end-to-end.Individual pay is determined by factors including job-related skills, experience, and relevant education or training.US: $147000 - $211000 (USD) + 15% bonus target + equity + benefitsResponsibilitiesLearn more about benefits at Google .Scope detection requirements for enterprise surfaces, focusing on high-risk areas such as Insider Exfiltration, Access Abuse, and Malicious Process Execution.Design and implement detection rules for systems involving multiple interconnected components, ensuring comprehensive coverage across enterprise surfaces.Assess security risks separately and justify detection strategies based on threat intelligence and risk models. Design and implement improvements to existing detections to reduce false positives, minimize resource usage (GCU, RAM, Disk), and decrease end-to-end detection latency (targeting P50 Participate in post-exercise analysis (e.g., Red Team, Purple Team) to identify detection gaps, document findings, and implement remediation detections.Propose and implement incremental improvements to detection engineering pipelines, testing frameworks (e.g., synthetic event generation), and automation tooling.Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Google's EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our Accommodations for Applicants form .","datePosted":"2026-07-16T12:19:08.185Z","dateModified":"2026-07-16T12:19:08.185Z","hiringOrganization":{"@type":"Organization","name":"Google","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Jose","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"f717e3847c5a22e6747c5bc3"},"url":"https://jobsearcher.com/jobs/f717e3847c5a22e6747c5bc3"}}