Senior Staff Security Researcher, Device Security Tech Lead

Mountain View, CA, USA; Kirkland, WA, USA

Google

Google’s mission is to organize the world's information and make it universally accessible and useful.

View company page


Minimum qualifications:

  • Master's degree in computer science, engineering, or equivalent practical experience.
  • 10 years of experience as a security engineer or researcher in areas like microchip security, BootROM, bootloaders, TEE, Android, Linux kernel or wireless communications, covering hardware and software.
  • 5 years of experience as a security engineer or research lead with an organizational or industry building impact, identifying and writing exploits for vulnerabilities in device components and hardened attack surfaces using a combination of code and binary review, static, and dynamic analysis.

Preferred qualifications:

  • Experience as a finder of numerous CVEs, successful participation in Capture the Flag events (CTF), Vulnerability Rewards Programs (VRP), security competitions such as Pwn2Own, or industry recognition.
  • Experience in a leadership role, guiding and developing technical talent.
  • Experience presenting novel security research at conferences, being a keynote speaker, or giving industry recognized security training.
  • Knowledge of software hardening technologies and an ability to identify deficiencies in them and recommend their proper use.

About the job

Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

The goal is to embed security practices throughout the product life-cycle, ensuring the trustworthiness of the devices, apps, software services, and platforms that the product area develops.

The Security team is composed of engineers that prevent, detect, and mitigate vulnerabilities across a variety of product lines and services, and collaborates with product development teams on system design, hardening, code analysis, security testing, and other security assurance functions with the goal of minimizing the risk of abuse and increasing the cost of vulnerability exploitation.

In this role, you will drive technical engagements focused on the identification of novel attack vectors, vulnerabilities, and the development of exploits for on-device targets. You will be responsible for the technical direction of vulnerability research and exploit development program, whose scope includes a number of Made-by-Google device product lines covering phones, tablets, wearables, content streamers, cameras, and other smart home devices. The main layers of the device stack that you will work on are SoC, ROM and firmware, operating system, including RTOS, Trusted Execution Environment (TEE) and security controllers, wireless connectivity, and other subsystems.

Google's mission is to organize the world's information and make it universally accessible and useful. Our Devices & Services team combines the best of Google AI, Software, and Hardware to create radically helpful experiences for users. We research, design, and develop new technologies and hardware to make our user's interaction with computing faster, seamless, and more powerful. Whether finding new ways to capture and sense the world around us, advancing form factors, or improving interaction methods, the Devices & Services team is making people's lives better through technology.

The US base salary range for this full-time position is $237,000-$337,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target salaries for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.
Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.The US base salary range for this full-time position is $237,000-$337,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target salaries for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.
Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.The US base salary range for this full-time position is $237,000-$337,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target salaries for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.
Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.The US base salary range for this full-time position is $237,000-$337,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target salaries for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.
Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.

Responsibilities

  • Develop risk-driven offensive security project roadmaps that balance new products under development and products that have already launched.
  • Lead offensive security engagements with participants from product teams, platform teams, and security assurance groups.
  • Conduct security research to discover novel attack vectors and vulnerabilities, and demonstrate their exploitability, lead collaboration initiatives with other offensive security teams at Google and with external partners.
  • Drive fundamental improvements to products and platforms to address exposure, risk threats, and vulnerability patterns.
  • Define the technical ideas of offensive security program and mentor members of the offensive security team.
Define the technical ideas of offensive security program and mentor members of the offensive security team.
Apply now Apply later
  • Share this job via
  • or
Job stats:  8  0  0

Tags: Android Code analysis Computer Science CTF Exploit Exploits Linux Offensive security SOC Vulnerabilities

Perks/benefits: Conferences Equity / stock options Salary bonus Team events

Region: North America
Country: United States

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.