user avatar

Senior Penetration Tester, Kubernetes, Google Public Sector

Google, Inc.

Today
Top Secret
Unspecified
Unspecified
IT - QA and Test
Remote/Hybrid (Off-Site/Hybrid)

Note: Google's hybrid workplace includes remote and in-office roles. By applying to this position you will have an opportunity to share your preferred working location from the following:

In-office locations: Reston, VA, USA.
Remote location(s): Maryland, USA; Virginia, USA.Minimum qualifications:
  • Bachelor's degree or equivalent practical experience.
  • 5 years of experience in security engineering, with a focus on container security.
  • Experience with security assessments, design reviews, or threat modeling for containerized applications.
  • Ability to travel up to 25% of the time in order to engage with customers.
  • Active US Government Top Secret/Sensitive Compartmentalized Information (TS/SCI) security clearance.

Preferred qualifications:
  • Certifications in Certified Kubernetes Security Specialist (CKS), Offensive Security Certified Professional (OSCP), GIAC Cloud Penetration Tester (GCPN), or GIAC Web Application Tester (GWAPT).
  • Experience with securing cloud-native CI/CD pipelines.
  • Experience with container security tools such as Falco, Trivy, Twistlock, Kube-Hunter, Burp Suite, and Nmap.
  • Experience in scripting languages such as Python, Go, or Bash.
  • Understanding of the control plane (API server, etc.), worker nodes (kubelet, container runtime), pod security, networking (CNI), and IAM/RBAC mechanisms.
  • Ability to contribute to the security community (e.g., open-source projects, public research, conference presentations) related to containerization.

About the job

Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

In this role, you will be responsible for emulating real-world attack scenarios, identifying vulnerabilities in the AI environments and cloud-native ecosystems, and help to improve the overall security posture. You will have an understanding of containerization internals, common attack vectors, and pen-testing methodologies.

Google Public Sector brings the magic of Google to the mission of government and education with solutions purpose-built for enterprises. We focus on helping United States public sector institutions accelerate their digital transformations, and we continue to make significant investments and grow our team to meet the complex needs of local, state and federal government and educational institutions.

The US base salary range for this full-time position is $166,000-$244,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.

Responsibilities
  • Perform black box, grey box, and white box penetration tests against Kubernetes clusters, containerized applications, and the underlying cloud infrastructure.
  • Simulate realistic attack scenarios, target containerized and cloud environments, including initial access, exploitation, lateral movement across various environments.
  • Identify and exploit vulnerabilities in containerized components, including escape techniques, privilege escalation, runtime vulnerabilities, and insecure configurations in the control plane or network policies.
  • Automate tasks, analyze data, and develop exploits specifically for cloud-native and containerized targets.
  • Share knowledge and findings with defensive teams to improve their detection and response capabilities within containerized and cloud environments. Understand and apply purple team methodology for hardening of networks.

Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Google's EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our Accommodations for Applicants form.
group id: RTX191830
Find Google, Inc. on Social Media
Network Employers
user avatar
About Us
Since our founding in 1998, Google has grown by leaps and bounds. Starting from two computer science students in a university dorm room, we now have over a hundred thousand employees, and multiple divisions within the company all focused on our mission of organizing the world‘s information and making it universally accessible and useful. Google Public Sector, a Google division, plays a critical role in applying cloud technology to solve complex problems for our nation—across U.S. federal, state, and local governments, and educational institutions. We are proud to have served the U.S. public sector for many years, and are looking for cleared professionals to join our team to help us rapidly expand our services to the government, now and into the future.

Google, Inc. Jobs


Job Category
IT - QA and Test
Clearance Level
Top Secret
Employer
Google, Inc.