Job Description
Minimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 5 years of experience in cyber security, threat intelligence, or threat analysis.
- Experience in intelligence aggregation, evaluating threat coverage gaps, or threat modeling.
- Experience with automation via coding or scripting, as well as querying data using SQL to support threat hunting or intelligence gathering.
- Ability to communicate in English fluently to support cross-team relationship management and publish quality advisories.
Preferred qualifications:
- Experience evaluating defensive capabilities and producing actionable threat advisories.
- Experience working collaboratively with Detection and Response (D and R) and operational teams to drive security improvements.
- Deep understanding of common attacker tactics, tools, and techniques (TTPs), as well as agentic threats and internal abuse vectors.
- Excellent problem-solving, investigative skills, and the ability to explain complex detection or control gaps to diverse audiences.
About the job
You will be a key member of the newly established Threat Intelligence Operations (TIO) function. You will contextualize threat intelligence specifically for Alphabet. You will be responsible for providing actionable intelligence to proactively identify coverage gaps and strengthen the overall security posture of the organization.The Core team builds the technical foundation behind Google’s flagship products. We are owners and advocates for the underlying design elements, developer platforms, product components, and infrastructure at Google. These are the essential building blocks for excellent, safe, and coherent experiences for our users and drive the pace of innovation for every developer. We look across Google’s products to build central solutions, break down technical barriers and strengthen existing systems. As the Core team, we have a mandate and a unique opportunity to impact important technical decisions across the company.Responsibilities
- Combine public reporting with internal security data from sources such as threat scenarios consolidated in Optimus and Enterprise Security Intelligence.
- Evaluate known threats against current defensive and protective capabilities to identify coverage gaps, leveraging code reviews to assess the efficacy of technical defenses and detection logic.
- Conduct limited, focused manual hunting to ensure intelligence remains grounded in operational reality.
- Produce high-quality threat assessments to get threat scenarios integrated into threat catalogue and engineering roadmaps.