Beranda Loker Detail
G
Information & Communication Technology 🏢 Full Time ⭐️ Terverifikasi

Staff Security Engineer, Third Party Security Diligence

Google
Singapore
Estimasi Gaji
SGD 180.000 – SGD 280.000
Live Update
11 Mei 2026
Batas Akhir
11 Mei 2027

Deskripsi Pekerjaan

As a Staff Security Engineer within Alphabet’s Third-Party (3P) Risk Management program, you will be a foundational technical leader driving the security posture of our vast ecosystem of vendors and partners. You will define and implement rigorous security standards for third-party assessments, ensuring that external entities meet Google’s highest security criteria.

In this pivotal role, you will collaborate with engineering, legal, and procurement teams to identify, assess, and mitigate security risks associated with third-party software, cloud services, and infrastructure. You will also lead technical due diligence processes, interpret security findings, and work closely with vendors to remediate vulnerabilities and enforce compliance.

Tanggung Jawab

  • Lead and conduct comprehensive technical due diligence and security assessments for high-risk third-party vendors.
  • Design, implement, and maintain scalable security frameworks and governance models for Third-Party Risk Management (TPRM).
  • Evaluate complex security architectures, including cloud environments, APIs, and software supply chains.
  • Collaborate cross-functionally with Product, Engineering, and Legal teams to integrate security controls into vendor contracts and procurement processes.
  • Advise internal stakeholders on risk remediation strategies and drive resolution of critical security findings.
  • Stay abreast of emerging security threats, vulnerabilities, and compliance standards (e.g., SOC2, ISO 27001) applicable to vendor risk.
  • Mentor junior security engineers and contribute to the evolution of the 3P risk management strategy.

Kualifikasi

  • Bachelor’s degree in Computer Science, Information Security, or a related technical field, or equivalent practical experience.
  • 5+ years of experience in information security, penetration testing, or third-party risk management.
  • Deep understanding of cloud security principles, specifically within Google Cloud Platform (GCP) or AWS/Azure.
  • Experience with Vendor Risk Management (VRM) tools and security assessment methodologies.
  • Strong analytical skills with the ability to evaluate technical findings and communicate risk to non-technical audiences effectively.
  • Excellent problem-solving skills and a proactive approach to identifying potential security gaps.

Keahlian yang Dibutuhkan

Third-Party Risk Management Vendor Risk Third Party Security Security Engineering Due Diligence Cloud Security Compliance SOC2 ISO 27001

Siap Mengambil Tantangan Ini?

Pastikan resume Anda sudah siap. Kirimkan lamaran Anda sekarang sebelum tanggal deadline.

Lamar Sekarang

Lowongan Terkait

Rekomendasi pekerjaan serupa untuk Anda

Lihat Semua