Senior Staff Security Researcher, Device Security Tech Lead

Google LLC Kirkland , WA 98034

Posted 7 days ago

XNote: By applying to this position you will have an opportunity to share your preferred working location from the following: Mountain View, CA, USA; Kirkland, WA, USA; New York, NY, USA.

Minimum qualifications:

  • Master's degree in computer science, engineering, or equivalent practical experience.

  • 10 years of experience as a security engineer or researcher in areas like microchip security, BootROM, bootloaders, TEE, Android, Linux kernel or wireless communications, covering hardware and software.

  • 5 years of experience as a security engineer or research lead with an organizational or industry building impact, identifying and writing exploits for vulnerabilities in device components and hardened attack surfaces using a combination of code and binary review, static, and dynamic analysis.

Preferred qualifications:

  • Experience as a finder of numerous CVEs, successful participation in Capture the Flag events (CTF), Vulnerability Rewards Programs (VRP), security competitions such as Pwn2Own, or industry recognition.

  • Experience in a leadership role, guiding and developing technical talent.

  • Experience presenting novel security research at conferences, being a keynote speaker, or giving industry recognized security training.

  • Knowledge of software hardening technologies and an ability to identify deficiencies in them and recommend their proper use.

About the job

Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

The goal is to embed security practices throughout the product life-cycle, ensuring the trustworthiness of the devices, apps, software services, and platforms that the product area develops.

The Security team is composed of engineers that prevent, detect, and mitigate vulnerabilities across a variety of product lines and services, and collaborates with product development teams on system design, hardening, code analysis, security testing, and other security assurance functions with the goal of minimizing the risk of abuse and increasing the cost of vulnerability exploitation.

In this role, you will drive technical engagements focused on the identification of novel attack vectors, vulnerabilities, and the development of exploits for on-device targets. You will be responsible for the technical direction of vulnerability research and exploit development program, whose scope includes a number of Made-by-Google device product lines covering phones, tablets, wearables, content streamers, cameras, and other smart home devices. The main layers of the device stack that you will work on are SoC, ROM and firmware, operating system, including RTOS, Trusted Execution Environment (TEE) and security controllers, wireless connectivity, and other subsystems.

Google's mission is to organize the world's information and make it universally accessible and useful. Our Devices & Services team combines the best of Google AI, Software, and Hardware to create radically helpful experiences for users. We research, design, and develop new technologies and hardware to make our user's interaction with computing faster, seamless, and more powerful. Whether finding new ways to capture and sense the world around us, advancing form factors, or improving interaction methods, the Devices & Services team is making people's lives better through technology.

The US base salary range for this full-time position is $237,000-$337,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target salaries for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.

Responsibilities

  • Develop risk-driven offensive security project roadmaps that balance new products under development and products that have already launched.

  • Lead offensive security engagements with participants from product teams, platform teams, and security assurance groups.

  • Conduct security research to discover novel attack vectors and vulnerabilities, and demonstrate their exploitability, lead collaboration initiatives with other offensive security teams at Google and with external partners.

  • Drive fundamental improvements to products and platforms to address exposure, risk threats, and vulnerability patterns.

  • Define the technical ideas of offensive security program and mentor members of the offensive security team.

Information collected and processed as part of your Google Careers profile, and any job applications you choose to submit is subject to Google's Applicant and Candidate Privacy Policy.

Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See also Google's EEO Policy, Know your rights: workplace discrimination is illegal, Belonging at Google, and How we hire.

If you have a need that requires accommodation, please let us know by completing our Accommodations for Applicants form.

Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.

To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes.


icon no score

See how you match
to the job

Find your dream job anywhere
with the LiveCareer app.
Mobile App Icon
Download the
LiveCareer app and find
your dream job anywhere
App Store Icon Google Play Icon
lc_ad

Boost your job search productivity with our
free Chrome Extension!

lc_apply_tool GET EXTENSION

Similar Jobs

Want to see jobs matched to your resume? Upload One Now! Remove

Senior Staff Security Researcher, Device Security Tech Lead

Google LLC