Today
Top Secret
Unspecified
Unspecified
IT - Security
Remote/Hybrid• (Off-Site/Hybrid)
Note: Google's hybrid workplace includes remote and in-office roles. By applying to this position you will have an opportunity to share your preferred working location from the following:
In-office locations: Reston, VA, USA.
Remote location(s): Maryland, USA; Virginia, USA.Minimum qualifications:
Preferred qualifications:
About the job
Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
In this role, you will be responsible for designing, building, and automating the custom tooling used to emulate real-world adversaries against our AI infrastructure. You will have a background in software development, an understanding of offensive security tradecraft, and for reverse engineering and vulnerability research. You will help in creating sophisticated tools to issue and improve our defenses through an adversarial mindset.
Google Public Sector brings the magic of Google to the mission of government and education with solutions purpose-built for enterprises. We focus on helping United States public sector institutions accelerate their digital transformations, and we continue to make significant investments and grow our team to meet the complex needs of local, state and federal government and educational institutions.
The US base salary range for this full-time position is $166,000-$244,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.
Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.
Responsibilities
Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Google's EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our Accommodations for Applicants form.
In-office locations: Reston, VA, USA.
Remote location(s): Maryland, USA; Virginia, USA.Minimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 5 years of experience as a software developer, including experience with security-related projects.
- Experience with security assessments, design reviews, or threat modeling.
- Experience in at least two of the following programming languages: Python, Go, C++, or Assembly.
- Active US Government Top Secret/Sensitive Compartmentalized Information (TS/SCI) security clearance.
Preferred qualifications:
- Certification in Offensive Security Exploit Developer (OSED), GIAC Certified Exploit Researcher and Advanced Penetration Tester (GXPN), or Offensive Security Certified Professional (OSCP).
- 8 years of experience in offensive security, including developing custom payloads and automation tools.
- Experience with developing for containerized or cloud-native applications.
- Experience with reverse engineering tools like IDA Pro, Ghidra, or x64dbg.
- Experience in an exploit development or a similar offensive development role.
- Ability to research and develop exploits for identified vulnerabilities.
About the job
Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
In this role, you will be responsible for designing, building, and automating the custom tooling used to emulate real-world adversaries against our AI infrastructure. You will have a background in software development, an understanding of offensive security tradecraft, and for reverse engineering and vulnerability research. You will help in creating sophisticated tools to issue and improve our defenses through an adversarial mindset.
Google Public Sector brings the magic of Google to the mission of government and education with solutions purpose-built for enterprises. We focus on helping United States public sector institutions accelerate their digital transformations, and we continue to make significant investments and grow our team to meet the complex needs of local, state and federal government and educational institutions.
The US base salary range for this full-time position is $166,000-$244,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.
Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.
Responsibilities
- Design and build custom payloads, implants, C2 frameworks, and automation scripts to support red team and penetration testing engagements, using languages like Python, Go, C++, and Assembly.
- Develop attacker tactics, techniques, and procedures (TTPs) to enable scalable and repeatable testing of our security controls.
- Perform static and dynamic analysis of binaries and applications to discover vulnerabilities, understand functionality, and bypass security controls.
- Work directly with the Forensics subject matter experts (SME) during reverse engineering to analyze malware, assess its impact, and help develop detection signatures and analytics.
- Investigate and develop methods to circumvent security controls, break AI model guardrails, and evade detection within containerized environments, as well as assist with security architecture reviews and penetration tests.
Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Google's EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our Accommodations for Applicants form.
group id: RTX191830