Threat Operations Lead, Google Defense Intelligence
Job description
Applicants in San Francisco: Qualified applications with arrest or conviction records will be considered for employment in accordance with the San Francisco Fair Chance Ordinance for Employers and the California Fair Chance Act.
In accordance with Washington state law, we are highlighting our comprehensive benefits package, which is available to all eligible US based employees. Benefits for this role include:
• Health, dental, vision, life, disability insurance
• Retirement Benefits: 401(k) with company match
• Paid Time Off: 20 days of vacation per year, accruing at a rate of 6.15 hours per pay period for the first five years of employment
• Sick Time: 40 hours/year (increased to 69 hours/year for Seattle) including 5 discretionary sick days per instance
• Maternity Leave (Short-Term Disability + Baby Bonding): 28-30 weeks
• Baby Bonding Leave: 18 weeks
• Holidays: 13 paid days per year
Applicants in the County of Los Angeles: Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
Note: By applying to this position you will have an opportunity to share your preferred working location from the following:
Remote locations: District of Columbia, USA; California, USA; Georgia, USA; Illinois, USA; New York, USA; Washington, USA. Minimum qualifications:
• Bachelor's degree or equivalent practical experience.
• 10 years of experience with security assessments or security design reviews or threat modeling.
• 10 years of experience with security engineering, computer and network security and security protocols.
• 10 years of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.
• Experience in people management.
Preferred qualifications:
• Deep technical expertise in threat research, exploit and vulnerability analysis, and the execution of intelligence-led disruption strategies.
• Expertise in developing specialized teams to identify, analyze, and counter emerging threats and tactics.
• Track record of building specialized technical teams, optimizing organizational health, and driving operational excellence.
• Demonstrated ability to scale threat analysis and accelerate intelligence velocity using agentic workflows.
• Exceptional communication skills in translating complex analysis and campaigns for leadership and executives.
About the job
Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
Operating within the Google Threat Intelligence Group (GTIG), the Google Defense Intelligence (GDI) team identifies, attributes, and counters sophisticated global cyber threats and sits alongside its peer teams of Advanced Persistent Threat Intelligence and Cyber Crime Intelligence under the Threat Operations organization. GDI’s mission is to protect Google’s ecosystem by tracking and disrupting advanced adversaries within specialized threat domains (such as Information Operations and commercial surveillance vendors), monitoring threat actors to stay ahead of AI-driven exploitation and enablement, and providing rapid response and threat hunting for developing global exploitation and threats.
As the manager of Google Defense Intelligence, you will direct operational execution and investigative strategy for security engineers and analysts. You will oversee complex campaign investigations, convert intelligence into systemic mitigations, and deliver strategic risk assessments to Google leadership while scaling global defenses alongside peers in parallel teams. We succeed in collaborative, high-tempo, innovative problem-solving, balancing real-time response with long-term issue tracking. Our team fosters technical curiosity and cross-functional collaboration to solve complex security issues at Google scale.
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.
US: $262000 - $364000 (USD) + 25% bonus target + equity + benefits
Learn more about benefits at Google .
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.
US: $262000 - $364000 (USD) + 25% bonus target + equity + benefits
Learn more about benefits at Google .
Responsibilities
• Threat hunting and advanced attribution to unmask and disrupt sophisticated global adversary campaigns .
• Provide high-fidelity strategic assessments and threat landscape analysis to guide leadership risk management and enable defense.
• Drive sustainable capacity and performance through toil-reducing automation and streamlined workflows.
• Oversee the integration of agentic workflows and advanced analytics into core investigative capabilities.
• Manage early-warning escalation life-cycles and cross-functional response to emerging, high-exposure threats.
Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Google's EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our Accommodations for Applicants form .