job details

Back to jobs search

Jobs search results

2,428 jobs matched
Back to jobs search

Security Engineer, Abuse Vulnerability Rewards Program

GoogleSeattle, WA, USA; Washington D.C., DC, USA
Note: By applying to this position you will have an opportunity to share your preferred working location from the following: Seattle, WA, USA; Washington D.C., DC, USA.

Minimum qualifications:

  • Bachelor's degree or equivalent practical experience.
  • 5 years of experience with security assessments, security design reviews, or threat modeling.
  • 5 years of experience with security engineering, computer and network security, and security protocols.
  • 5 years of experience coding in one or more general purpose languages.

Preferred qualifications:

  • Experience with writing Python code in production environments.
  • Experience working with external parties or in a publicly-facing role.
  • Experience with generative AI or similar AI/ML systems.
  • Experience working in bug bounties.
  • Excellent problem-solving and critical thinking skills, with attention to detail in an ever-changing environment.

About the job

There's no such thing as a "safe system" - only safer systems. Our Security team works to create and maintain the safest operating environment for Google's users and developers. As a Security Engineer, you help protect network boundaries, keep computer systems and network devices hardened against attacks and provide security services to protect highly sensitive data like passwords and customer information. Security Engineers work directly with network equipment and actively monitor our systems for attacks and intrusions. You also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

You use your industry experience to own and drive the resolution of complex security incidents, policy questions and technical security issues.

The Abuse Vulnerability Rewards Program recognizes the contributions of security researchers who invest their time and effort in helping us make our products less susceptible to bad actors that intend to commit significant acts of abuse against our products and users.

The Abuse Vulnerability Rewards Program (VRP) is a bug bounty program which covers abusive use of Google's systems, including new Generative AI products. The program recognizes the contributions of security researchers who invest their time and effort in helping us make our products less susceptible to bad actors that intend to commit significant acts of abuse against our products and users. The VRP team is responsible for assessing VRP reports, interacting directly with researchers and product teams, deciding on rewards for reporters, and managing coordinated disclosure of vulnerabilities.

The US base salary range for this full-time position is $161,000-$239,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target salaries for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.

Responsibilities

  • Serve as a point of technical escalation for first-line triage and manage communication between researchers and product teams.
  • Assess reported bugs critically to determine what, if any, reward should be issued for them.
  • Grow and develop the technical capabilities of the team and of individual team members.
  • Participate in the larger VRP community and engage in cross-team projects to improve the bug bounty experience for all reporters.
  • Develop and guide the scope and handling of Generative AI issues reported to the bug bounty.

Information collected and processed as part of your Google Careers profile, and any job applications you choose to submit is subject to Google's Applicant and Candidate Privacy Policy.

Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See also Google's EEO Policy, Know your rights: workplace discrimination is illegal, Belonging at Google, and How we hire.

If you have a need that requires accommodation, please let us know by completing our Accommodations for Applicants form.

Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.

To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes.

Google apps
Main menu