Google

Application Security Consultant - Google Cloud Mandiant Consulting

Google

Dubai, United Arab Emirates · Full Time

Be the first to apply

Experience
3 yrs
Salary
Openings
1
Posted
8 ਘੰਟੇ ਪਹਿਲਾਂ
Work mode
In office
Education
Bachelor's degree in Cybersecurity or equivalent experience
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About the Role

Join Google Cloud's Mandiant team as an Application Security Consultant, delivering expert cybersecurity consulting to clients. This critical role involves guiding clients to proactively manage cyber threats through vulnerability assessments, threat hunting, incident response, and strategic security advice. You will be responsible for assessing the security posture of web, API, and mobile applications, leveraging industry standards and offensive security techniques to discover and exploit vulnerabilities. You will present your findings and recommendations to both technical teams and leadership stakeholders, enhancing the overall security framework.

Key Responsibilities

  • Perform thorough security evaluations of web applications, APIs, and mobile apps by identifying, exploiting, and confirming vulnerabilities in line with methodologies like OWASP WSTG, OWASP API Security Top 10, and OWASP MASTG.
  • Identify critically exploitable vulnerabilities and develop methods to weaponize them for comprehensive security testing.
  • Contribute to team growth through creating security tools, researching offensive tactics, integrating threat intelligence, and sharing expertise internally through presentations.
  • Generate detailed reports and clear presentations tailored to both technical audiences and executive leadership, serving as a trusted advisor on cybersecurity matters.
  • Support scoping of new projects, lead engagement teams from initiation through remediation, and mentor junior staff members.

Required Qualifications

  • Bachelor's degree in Cybersecurity focused on offensive security or equivalent hands-on experience.
  • At least 3 years demonstrated experience in at least three of the following areas: web application security assessment, mobile application security assessment, API security assessment, red team operations, EDR bypass techniques, exploit development, cloud security, social engineering, scripting, and custom tool development.
  • Proven experience delivering clear reports and presentations to diverse audiences, including executives and technical teams.
  • Understanding of operating system security, especially across various systems including Linux.

Preferred Qualifications

  • Recognized certifications such as BSCP, OSWE, eWPTX, eMAPT, 8ksec CMSE or relevant SANS courses related to application security.
  • Proficient in development of security tools and familiarity with languages like Python, C#, C/C++, Rust, Nim, or similar.
  • Hands-on experience conducting security assessments for web, API, and mobile platforms (iOS and Android) using OWASP standards (WSTG/ASVS, Top 10s, MASVS/MASTG).
  • Skillful with penetration testing tools including Burp Suite Professional and extensions, Postman, nuclei, ffuf, and sqlmap.

Additional Information

Applicants may select their preferred work location among Dubai (UAE), Doha (Qatar), or Riyadh (Saudi Arabia). Google is committed to creating an inclusive environment and is an equal opportunity employer. Accommodations for applicants with disabilities are available upon request via a formal accommodation process.

Minimum education

Bachelor's Degree

🤖
Online · instant AI help