Threat Analyst, Cyber Espionage, Mandiant



United States · Remote
Posted on Wednesday, May 24, 2023

Note: Google’s hybrid workplace includes remote roles.

Remote location: United States.


Minimum qualifications:

  • 2 years of experience leading investigations into and generating novel leads on espionage activity.
  • Experience writing and presenting on various topics and assessments for an audience with mixed backgrounds.
  • Experience correlating and attributing malicious activity based on technical and geopolitical factors.
  • Experience tracking adversaries via network infrastructure and malicious artifacts.

Preferred qualifications:

  • Experience with technical analysis, including the creation of file, host, and network signatures leveraging multiple malware and network detection platforms, static and dynamic malware analysis, host forensics, or other technical topics.
  • Experience identifying and prioritizing cyber threats for investigation.
  • Experience mentoring and supervising analysts.
  • Experience developing tools to uncover targeted activity leveraging large data sets.
  • Understanding of the geopolitical drivers of cyber espionage, with a focus in a particular region.
  • Understanding of attacker methodology and methodologies used to search for adversarial activity.

About the job

Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. By scaling decades of frontline experience, Mandiant helps organizations to be confident in their readiness to defend against and respond to cyber threats. Mandiant is now part of Google Cloud.

In this role, you will work to a broad set of Mandiant Intelligence priorities to handle a variety of complex assignments and situations. Using your knowledge of fundamental concepts across a wide range of intelligence disciplines, you will select and apply appropriate work methods, procedures, techniques, and practices.

Google Cloud accelerates organizations’ ability to digitally transform their business with the best infrastructure, platform, industry solutions and expertise. We deliver enterprise-grade solutions that leverage Google’s cutting-edge technology – all on the cleanest cloud in the industry. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.

The US base salary range for this full-time position is $126,000-$189,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.


  • Conduct and lead comprehensive research into the Tactics, Techniques and Procedures (TTPs) and motivation of state sponsored espionage campaigns and actors.
  • Prioritize research according to customer priorities and requests.
  • Produce and review written reporting on state sponsored espionage.
  • Conduct high-profile briefings to inform and present Mandiant’s findings to our customers and stakeholders.
  • Maintain awareness of geopolitical trends affecting the cyber threat landscape, including cyber operations and missions, vulnerabilities, malware development, third-party risk, geopolitics, and significant global events.

Information collected and processed as part of your Google Careers profile, and any job applications you choose to submit is subject to Google's Applicant and Candidate Privacy Policy.

To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees or any other organization location. Google is not responsible for any fees related to unsolicited resumes.

At Google, we’re committed to building a workforce that is more representative of the users we serve and creating a culture where everyone feels like they belong. To learn more about our diversity, equity, inclusion commitments and how we’re building belonging, please visit our Belonging page for more information.

We welcome and encourage people who are expecting and/or parents-to-be to apply to this or any other role at Google.

Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles.