jobs in Sourceo

全职 Security Engineer, Third Party Security Diligence 工作, 薪水, Sourceo 公司招聘中 - Ricebowl

Security Engineer, Third Party Security Diligence

Sourceo

Singapore

分享
保存

工作地点

  • Singapore

职位描述

岗位职责

About the job

There's no such thing as a "safe system" - only safer systems. Our Security team works to create and maintain the safest operating environment for Google's users and developers. As a Security Engineer, you help protect network boundaries, keep computer systems and network devices hardened against attacks and provide security services to protect highly sensitive data like passwords and customer information. Security Engineers work directly with network equipment and actively monitor our systems for attacks and intrusions. You also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

You use your industry experience to own and drive the resolution of complex security incidents, policy questions and technical security issues.

SPMA (Security and Privacy for Mergers, Acquisitions and Alphabet) team’s mandate is focused on reducing Acquisitions, third-party and Cloud risk to Google and Alphabet.

SPMA executes on its mandate through three key verticals:

  • Mergers, Acquisitions and Alphabets (M&A): Effectively and safely raise the security bar for Google’s Off Google entities (Acquisitions and Bets); helping companies navigate Google’s security landscape and processes, thereby safely and securely integrating/divesting/separating them.
  • Alphabet Use of Cloud (AUC): Manage and minimize risk from Alphabet’s use of public clouds (GCP).
  • Third-party/Vendor Security Diligence (3PSD): Ensure effective governance and minimize risk from Alphabet’s use of third-party vendors.

This role sits within the Third Party/Vendor Security Diligence (3PSD) vertical, focusing on third-party security. Alphabet’s Third Party Security Diligence program ensures security of our third-party engagements, and is part of a broader third-party risk management ecosystem.The Core team builds the technical foundation behind Google’s flagship products. We are owners and advocates for the underlying design elements, developer platforms, product components, and infrastructure at Google. These are the essential building blocks for excellent, safe, and coherent experiences for our users and drive the pace of innovation for every developer. We look across Google’s products to build central solutions, break down technical barriers and strengthen existing systems. As the Core team, we have a mandate and a unique opportunity to impact important technical decisions across the company.

Responsibilities

  • Conduct comprehensive security diligence for critical and high-risk third-party vendors, evaluating their controls against Google's requirements, identifying risks, and recommending remediation.

Contribute to the engineering improvement of the Third Party Security Diligence (3PSD) program by developing tools, automation, and proposing process enhancements.

Assist in technically integrating 3PSD tools with the wider OneTPRM ecosystem and support data analysis to identify risk trends.

Collaborate with and provide security guidance to internal stakeholders like vendor managers and Product teams on third-party engagements.

  • Develop and maintain deep technical expertise in security domains relevant to third-party risk (e.g., cloud, application security, IAM) and help create reusable security patterns and best practices.

Information collected and processed as part of your Google Careers profile, and any job applications you choose to submit is subject to Google's [Applicant and Candidate Privacy Policy](./privacy-policy).

重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多