About the job Google Threat Intelligence Group (GTIG) tracks government-backed cyber operations ... The Google Defense Production (GDP) team bridges threat analysis and executive action. We ...
About the job Google Threat Intelligence Group (GTIG) tracks government-backed cyber operations ... The Google Defense Production (GDP) team bridges threat analysis and executive action. We ...
Cyber Threat Analyst
Linthicum, MD · On-site
Uses Jira to to track analysis tasks and communicate status. May leverage tools such as Virus Total, Google Threat Intelligence, Recorded Future, etc. to obtain, fuse, and analyze cyber threat ...
Cyber Threat Analyst
Linthicum, MD · On-site
Uses Jira to to track analysis tasks and communicate status. May leverage tools such as Virus Total, Google Threat Intelligence, Recorded Future, etc. to obtain, fuse, and analyze cyber threat ...
Cyber Threat Analyst
Linthicum, MD · On-site
Uses Jira to to track analysis tasks and communicate status. May leverage tools such as Virus Total, Google Threat Intelligence, Recorded Future, etc. to obtain, fuse, and analyze cyber threat ...
Cyber Threat Analyst
Linthicum, MD · On-site
Uses Jira to to track analysis tasks and communicate status. May leverage tools such as Virus Total, Google Threat Intelligence, Recorded Future, etc. to obtain, fuse, and analyze cyber threat ...
Cyber Threat Analyst
Linthicum, MD · On-site
Uses Jira to to track analysis tasks and communicate status. May leverage tools such as Virus Total, Google Threat Intelligence, Recorded Future, etc. to obtain, fuse, and analyze cyber threat ...
Cyber Threat Analyst
Linthicum, MD · On-site
Uses Jira to to track analysis tasks and communicate status. May leverage tools such as Virus Total, Google Threat Intelligence, Recorded Future, etc. to obtain, fuse, and analyze cyber threat ...
Threat Intelligence Reporting and Strategic Insights Analyst, GTIG
Reston, VA · On-site
$147 - $213/hr
About the job Google Threat Intelligence Group (GTIG) tracks government-backed cyber operations ... The Google Defense Production (GDP) team bridges threat analysis and executive action. We ...
Threat Intelligence Reporting and Strategic Insights Analyst, GTIG
Reston, VA · On-site
$147 - $213/hr
About the job Google Threat Intelligence Group (GTIG) tracks government-backed cyber operations ... The Google Defense Production (GDP) team bridges threat analysis and executive action. We ...
Cyber Threat Intel Analyst
Washington, DC · On-site
$160 - $220/hr
Not to mention, we're now powered by Google, meaning we offer our customers an AI-powered platform ... Basic to intermediate technical analysis skills such as infrastructure analysis, malware analysis ...
Cyber Threat Intel Analyst
Washington, DC · On-site
$160 - $220/hr
Not to mention, we're now powered by Google, meaning we offer our customers an AI-powered platform ... Basic to intermediate technical analysis skills such as infrastructure analysis, malware analysis ...
Cyber Threat Intel Analyst CTO / Threat & AI Research Washington, D.C.
Washington, DC · On-site
$160 - $220/hr
Not to mention, we're now powered by Google , meaning we offer our customers an AI-powered platform ... Basic to intermediate technical analysis skills such as infrastructure analysis, malware analysis ...
Cyber Threat Intel Analyst CTO / Threat & AI Research Washington, D.C.
Washington, DC · On-site
$160 - $220/hr
Not to mention, we're now powered by Google , meaning we offer our customers an AI-powered platform ... Basic to intermediate technical analysis skills such as infrastructure analysis, malware analysis ...
Lead Cyber Threat Analyst
Washington, DC · On-site
Hands-on experience with cloud threat analysis (AWS, Azure, Google Cloud Platform) and container security. * Ability to lead advanced threat hunting campaigns and mentor junior analysts.
Lead Cyber Threat Analyst
Washington, DC · On-site
Hands-on experience with cloud threat analysis (AWS, Azure, Google Cloud Platform) and container security. * Ability to lead advanced threat hunting campaigns and mentor junior analysts.
$160 - $220/hr
Not to mention, we're now powered by Google , meaning we offer our customers an AI-powered platform ... Basic to intermediate technical analysis skills such as infrastructure analysis, malware analysis ...
$160 - $220/hr
Not to mention, we're now powered by Google , meaning we offer our customers an AI-powered platform ... Basic to intermediate technical analysis skills such as infrastructure analysis, malware analysis ...
Cyber Threat Intel Analyst
Washington, DC · On-site
$160K - $220K/yr
Not to mention, we're now powered by Google, meaning we offer our customers an AI-powered platform ... Basic to intermediate technical analysis skills such as infrastructure analysis, malware analysis ...
Cyber Threat Intel Analyst
Washington, DC · On-site
$160K - $220K/yr
Not to mention, we're now powered by Google, meaning we offer our customers an AI-powered platform ... Basic to intermediate technical analysis skills such as infrastructure analysis, malware analysis ...
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
ME00600-Cyber Threat Analyst (Multiple Positions)
Annapolis, MD · On-site
$132K - $200K/yr
Working within a collaborative threat analysis team, analysts leverage intelligence reporting ... group medical plan, company paid dental, vision, life insurance, and STD/LTD plans. Salary is ...
ME00600-Cyber Threat Analyst (Multiple Positions)
Annapolis, MD · On-site
$132K - $200K/yr
Working within a collaborative threat analysis team, analysts leverage intelligence reporting ... group medical plan, company paid dental, vision, life insurance, and STD/LTD plans. Salary is ...
Experience may also include multi-source or technical threat analysis (e.g., SIGINT, ELINT, FISINT ... Group Term Life, Short-Term and Long-Term Disability is provided by Sentar to all qualifying ...
Experience may also include multi-source or technical threat analysis (e.g., SIGINT, ELINT, FISINT ... Group Term Life, Short-Term and Long-Term Disability is provided by Sentar to all qualifying ...
Experience in the analysis of CTI, supporting monitoring, detection, and response capabilities ... Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence ...
Experience in the analysis of CTI, supporting monitoring, detection, and response capabilities ... Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence ...
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious ...
Google Threat Analysis Group information
See salary details
$34K - $46.9K
4% of jobs
$46.9K - $59.8K
0% of jobs
$59.8K - $72.7K
4% of jobs
$72.7K - $85.6K
7% of jobs
$96.2K is the 25th percentile. Wages below this are outliers.
$85.6K - $98.5K
11% of jobs
$98.5K - $111.5K
5% of jobs
The median wage is $116.7K / yr.
$111.5K - $124.4K
44% of jobs
$124.4K - $137.3K
10% of jobs
$137.3K - $150.2K
11% of jobs
$150.2K - $163.1K
2% of jobs
$163.1K - $176K
0% of jobs
$34K
$112.9K
$176K
How much do google threat analysis group jobs pay per year?
What is a Google Threat Analysis Group?
A Google Threat Analysis Group (TAG) job involves identifying, tracking, and countering cyber threats that target Google, its users, and the broader internet. TAG analysts research advanced persistent threats (APTs), disinformation campaigns, and other malicious activities from state-sponsored actors and cybercriminals. They collaborate with internal security teams and external organizations to enhance digital security. The role requires expertise in cybersecurity, threat intelligence, and incident response.
What does a typical workday look like for a member of the Google Threat Analysis Group?
A typical workday for a member of the Google Threat Analysis Group involves monitoring for new and emerging security threats, analyzing malware and cyber-attack campaigns, and producing threat intelligence reports. Team members frequently collaborate with engineers, product managers, and other security specialists to respond to potential threats and strengthen defenses. Daily tasks often include conducting in-depth investigations, communicating findings internally, and sharing relevant intelligence with external partners as appropriate. The work is dynamic and high-impact, demanding agility and a proactive approach to rapidly changing threat landscapes.
What are the key skills and qualifications needed to thrive in the Google Threat Analysis Group position, and why are they important?
To thrive in the Google Threat Analysis Group, you need expertise in cybersecurity, malware analysis, digital forensics, and possess a strong analytical mindset, often backed by a degree in computer science or related field. Familiarity with security information and event management (SIEM) tools, threat intelligence platforms, scripting languages, and relevant certifications such as CISSP or GIAC is highly valuable. Strong communication, collaboration, and problem-solving skills help you effectively share findings and work with cross-functional teams. These abilities are crucial for identifying, investigating, and mitigating evolving security threats that target Google's products and users.
What cities are hiring for Google Threat Analysis Group jobs?
Cities with the most Google Threat Analysis Group job openings:
What are the most commonly searched types of Google Threat Analysis Group jobs?
The most popular types of Google Threat Analysis Group jobs are:
What states have the most Google Threat Analysis Group jobs?
States with the most job openings for Google Threat Analysis Group jobs include:
What job categories do people searching Google Threat Analysis Group jobs look for?
The top searched job categories for Google Threat Analysis Group jobs are:

Full-time
Posted 19 days ago
Key responsibilities
Support the end-to-end operationalization of GTIG's intelligence lifecycle for internal stakeholders.
Collect, correlate, and analyze data from various sources to identify adversary trends.
Pilot and integrate AI capabilities to enhance threat reporting workflows.
Google rating
8.8
Based on 103 frontline employees who took The Breakroom Quiz
48th of 247 rated software companies
Job description
X Note: By applying to this position you will have an opportunity to share your preferred working location from the following: Reston, VA, USA; New York, NY, USA.
Minimum qualifications:
- Bachelor's degree or equivalent practical experience
- 5 years of experience with finished intelligence analysis or intelligence reports.
- Experience with cyber threat intelligence and threat hunting.
Preferred qualifications:
- Experience leveraging generative AI/LLM tools (i.e., prompt engineering, LLM-driven summarization) within intelligence production workflows.
- Experience querying and analyzing datasets using SQL.
- Experience in state-sponsored cyber operations, financially-motivated cyber crime, or emerging threats to AI ecosystems.
- Proficiency in skills associated with the principles of intelligence writing and briefing with the knowledge of structured analytic techniques for intelligence analysis.
- Understanding of traditional Cyber Threat Intelligence (CTI) indicators of compromise (IOCs) and threat hunting.
- Ability to work cross-functionally across matrixed organizations to drive risk remediation, cross-team alignment.
About the job
Google Threat Intelligence Group (GTIG) tracks government-backed cyber operations, financially motivated cyber crime, information operations (IO) threat activity, and emerging AI threat vectors to defend Google and its global user base.
The Google Defense Production (GDP) team bridges threat analysis and executive action. We synthesize complex threat research into timely, requirement-driven, actionable intelligence for Google's internal defenders, executive leadership, product areas, and the broader security community.
As a Threat Intelligence Reporting and Strategic Insights Analyst, you will support the end-to-end operationalization of GTIG's intelligence lifecycle for key internal stakeholders. You will facilitate the production of high-visibility internal reports, drive stakeholder engagement, and integrate artificial intelligence (AI) tools into threat reporting workflows.
Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.Individual pay is determined by factors including job-related skills, experience, and relevant education or training.
US: $147000 - $213000 (USD) 15% bonus target equity benefits
Learn more about benefits at Google .
Responsibilities
- Drive operational threat intelligence reporting and assist in the identification and refinement of priority intelligence requirements held by internal stakeholders.
- Collect, correlate and analyze data points derived from a wide array of sources (e.g., internal telemetry, first-party GTIG mission research) to identify adversary trends.
- Support the end-to-end production lifecycle of multiple cornerstone intelligence deliverables leveraged by varied internal stakeholders and Google product areas. Produce ad hoc, requirement-driven intelligence assessments and forward-leaning analysis that anticipates threats to Google, its product areas and its users.
- Pilot and integrate AI capabilities (LLMs, NotebookLM, automated templates) to accelerate summarization, trend identification and drafting across the production workflow.
- Translate technical analysis into clear narratives and data visualizations tailored to both technical defenders and non-technical executive audiences. Leverage feedback mechanisms to refine investigative approaches and improve the clarity, impact and actionability.
Information collected and processed as part of your Google Careers profile, and any job applications you choose to submit is subject to Google's Applicant and Candidate Privacy Policy .
Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See also Google's EEO Policy , Know your rights: workplace discrimination is illegal , Belonging at Google , and How we hire .
If you have a need that requires accommodation, please let us know by completing our Accommodations for Applicants form .
Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.
To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes.
Equity is granted exclusively and discretionarily by Alphabet Inc. on the basis of an agreement concluded between you and Alphabet Inc. Alphabet Inc. is your sole contractual partner with respect to equity grants. GSU grants are not guaranteed, are discretionary, are subject to approval by the Alphabet Inc. board of directors or its delegate, the terms of the relevant Alphabet Inc. stock plan, and your grant agreement. They have no impact on statutory payments. Current or past grants do not confer an acquired right.
About Google
Sourced by ZipRecruiter
Industry
Software development and technology, communication and media
Company size
10,000+ Employees
Headquarters location
Mountain View, CA, US