NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Cybersecurity Consultant in United States of America
11 days ago
Apply with autofill
Apply with autofill
Google·SaaS·11 days ago
11 days ago

Senior Strategic Security Consultant, Mandiant, Google Cloud

Atlanta, United States of AmericaFull-timeHybridSenior · 5+ yearsCybersecurity Consultant

Sign up free to see how well your resume matches this role.

Boost your chances at Google

How you compare FREE

?
Your scoreYour score: not yet known
→
48
Top 10%Top 10%: 48 out of 100

Top 10% of NextRaise users matched against Cybersecurity Consultant roles in United States.

Must-have skills for this role

  • sast
  • dast
  • sca
  • owasp samm

PDF or DOCX · no account needed

Apply faster with autofill FREEThe NextRaise extension autofills your application in one click.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Lead strategic security consulting engagements, maturity assessments, and gap analyses against industry frameworks (OWASP SAMM, BSIMM, NIST SSDF) to deliver risk-reduction roadmaps for cloud and on-premises environments.
  • Architect and secure Developer Security Operations pipelines by designing technical blueprints and integrating automated security gates (SAST, DAST, SCA) seamlessly into developer workflows.
  • Establish governance structures and facilitated risk-tiering workshops to define remediation service-level agreements, exception handling, and prioritization metrics (CVSS, EPSS) across multi-cloud and legacy infrastructure.
  • Support application threat modeling (STRIDE) and architect security reviews early in the Software Development Life Cycle (SDLC) to identify design flaws and provide engineering teams with strategies.
  • Pioneer application landscape discovery and Software Bill of Materials (SBOM) mapping to manage supply chain risks, while advising on the deployment of enterprise AppSec and Virtual Machine technologies (e.g., Qualys, Tenable, Snyk, Checkmarx).

What they're looking for

  • Bachelor's degree in Computer Science, Information Systems, Cyber-security, related technical field, or equivalent practical experience.
  • 5 years of experience assessing and developing cyber-security solutions and programs across security domains.
  • 5 years of experience in delivering cyber outcomes, identifying mission risks, and devising solutions.
  • Ability to travel up to 30% of the time as needed.

Nice to have

  • Certifications related to specific cloud platforms.
  • Experience implementing industry-leading practices around cyber risks and cloud security for clients’ cloud security frameworks using industry standards.
  • Experience with cloud governance, with the ability to convey governance principles to cloud computing in terms of policies.
  • Experience deploying and maintaining security testing infrastructures (SAST, DAST, SCA, network/container vulnerability scanners) across hybrid ecosystems and multi-cloud environments.
  • Proficiency in the Open Web Application Security Project (OWASP) Top 10, Common Weakness Enumeration (CWE), Threat Modeling Methodologies, and integrating security controls into Agile and Developer Security Operation environments.

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

As a Mandiant Strategic Security Consultant, you will lead and support projects on behalf of clients that assess, test, or build their security programs. Project teams may range from 2 to 5 colleagues. Clients will range from start-up companies looking to supplement their security team to Fortune 100 companies that need fresh ideas to enhance their perspective on the security program. You will provide guidance and advice to our client on best practices and managing the risks for their security program.

In this role, you will lead strategic consulting engagements focused on Applied Security (AppSec) and Vulnerability Management. You will design secure SDLC roadmaps, establish industry-standard policies (Developer Security Operations, Threat Modeling), and collaborate with clients to implement continuous security testing across cloud and on-prem platforms.Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

US: $138000 - $200000 (USD) + 15% bonus target + equity + benefits

Learn more about benefits at Google.

Responsibilities:

  • Lead strategic security consulting engagements, maturity assessments, and gap analyses against industry frameworks (OWASP SAMM, BSIMM, NIST SSDF) to deliver risk-reduction roadmaps for cloud and on-premises environments.
  • Architect and secure Developer Security Operations pipelines by designing technical blueprints and integrating automated security gates (SAST, DAST, SCA) seamlessly into developer workflows.
  • Establish governance structures and facilitated risk-tiering workshops to define remediation service-level agreements, exception handling, and prioritization metrics (CVSS, EPSS) across multi-cloud and legacy infrastructure.
  • Support application threat modeling (STRIDE) and architect security reviews early in the Software Development Life Cycle (SDLC) to identify design flaws and provide engineering teams with strategies.
  • Pioneer application landscape discovery and Software Bill of Materials (SBOM) mapping to manage supply chain risks, while advising on the deployment of enterprise AppSec and Virtual Machine technologies (e.g., Qualys, Tenable, Snyk, Checkmarx).

Minimum qualifications:

  • Bachelor's degree in Computer Science, Information Systems, Cyber-security, related technical field, or equivalent practical experience.
  • 5 years of experience assessing and developing cyber-security solutions and programs across security domains.
  • 5 years of experience in delivering cyber outcomes, identifying mission risks, and devising solutions.
  • Ability to travel up to 30% of the time as needed.

Preferred qualifications:

  • Certifications related to specific cloud platforms.
  • Experience implementing industry-leading practices around cyber risks and cloud security for clients’ cloud security frameworks using industry standards.
  • Experience with cloud governance, with the ability to convey governance principles to cloud computing in terms of policies.
  • Experience deploying and maintaining security testing infrastructures (SAST, DAST, SCA, network/container vulnerability scanners) across hybrid ecosystems and multi-cloud environments.
  • Proficiency in the Open Web Application Security Project (OWASP) Top 10, Common Weakness Enumeration (CWE), Threat Modeling Methodologies, and integrating security controls into Agile and Developer Security Operation environments.
SaaS

Company

GoogleSaaS
Atlanta, United States of America

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Google's careers site·first seen 15 Sept 2026·last verified 15 Sept 2026·How we source jobs

Similar jobs

  • Retail Security Systems Technician at Johnson ControlsLouisville, United States of America–match not yet calculated
  • Senior Security Response & Emergency Representative at Wells FargoCHARLOTTE, United States of America–match not yet calculated
  • Security Officer - On Call at millerknollZeeland, United States of America–match not yet calculated
  • Armed Security Officer for CWD at sentaraVirginia Beach, United States of America–match not yet calculated
  • Senior Information Security Professional (Government) at attReston, United States of America–match not yet calculated

Browse more jobs

  • Cybersecurity Consultant jobs in United States
  • IT Consultant jobs in United States
  • Business Analyst jobs in United States
  • Digital Transformation Consultant jobs in United States
  • Cybersecurity Consultant jobs in Germany
  • Cybersecurity Consultant jobs in India