Software Engineer, External API Security

Google LLC
New York, NY, United States
22 days ago
Apply on www.juju.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$147,000.0 - $210,000.0
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Java (Programming Language) Application Programming Interfaces (APIs) Artificial Intelligence Bioinformatics Cyber Security Google Tools Identity and Access Management Python (Programming Language) Automation of Marketing Secure Coding Software Construction Software Engineering
+5 more
Software Security Code Restructuring Vulnerability Analysis Programming Languages Microservices

Job description

The Information Security Engineering, Authorization (ISE Auth) team strives to eliminate product authorization vulnerabilities at Google, through a combination of designing and rolling out safe-by-default developer surfaces, agentic security scanning and targeted remediation projects.

Our API Security pillar focuses specifically on the risk of externally exploitable authorization weaknesses in internet-facing APIs.

As a Software Engineer in ISE Auth, you will protect user data and secure Google’s public-facing API boundaries from authorization vulnerabilities.In this role, you will design secure-by-default frameworks, build advanced AI-assisted security scanning systems, and run central remediation campaigns like changes to eliminate risk at scale.You will access control capabilities across all Google products.

Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

US: $147000 - $210000 (USD) + 15% bonus target + equity + benefits

Learn more aboutbenefits at Google (https://www.google.com/about/careers/applications/benefits/) .

Responsibilities

  • Develop and improve AI-assisted API vulnerability scanning systems, framework improvements, and automated launch checkers to proactively identify authorization bypasses.

  • Drive central remediation campaigns to remediate systemic vulnerability classes without putting undue churn onto product teams.

  • Collaborate with core infrastructure and product teams to establish secure-by-default API deployment architectures and to pragmatically reduce risk.

  • Build and maintain infrastructure and automation for security policy enforcement, monitoring, and regression prevention.

  • Analyze emerging authorization bypass patterns and evaluate agent-based AI systems to proactively harden API access controls.

Information collected and processed as part of your Google Careers profile, and any job applications you choose to submit is subject to Google’sApplicant and Candidate Privacy Policy (./privacy-policy) .

Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See alsoGoogle’s EEO Policy (https://www.google.com/about/careers/applications/eeo/) ,Know your rights: workplace discrimination is illegal (https://careers.google.com/jobs/dist/legal/EEOC_KnowYourRights_10_20.pdf) ,Belonging at Google (https://about.google/belonging/) , andHow we hire (https://careers.google.com/how-we-hire/) .

If you have a need that requires accommodation, please let us know by completing ourAccommodations for Applicants form (https://goo.gl/forms/aBt6Pu71i1kzpLHe2) .

Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.

To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes.

Equity is granted exclusively and discretionarily by Alphabet Inc. on the basis of an agreement concluded between you and Alphabet Inc. Alphabet Inc. is your sole contractual partner with respect to equity grants. GSU grants are not guaranteed, are discretionary, are subject to approval by the Alphabet Inc. board of directors or its delegate, the terms of the relevant Alphabet Inc. stock plan, and your grant agreement. They have no impact on statutory payments. Current or past grants do not confer an acquired right.

Requirements

Experience driving progress, solving problems, and mentoring more junior team members; deeper expertise and applied knowledge within relevant area., + Bachelor’s degree or equivalent practical experience.

  • 2 years of experience with software development in one or more programming languages, or 1 year of experience with an advanced degree.

  • 2 years of experience building software for security (e.g., vulnerability analysis, identity and access management).

Preferred qualifications:

  • Experience with agent-based artificial intelligence systems.

  • Experience in software security domains including secure coding practices, vulnerability analysis, or security architecture.

  • Experience designing, building, or securing web APIs and microservices.

  • Experience developing software with one or more general-purpose programming language including Go, Java, or Python.

  • Experience running automated code refactoring or programmatic remediation campaigns across systems.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

6:29 min

Answering inquiries on SLA negotiations and observability tooling

Martin Beránek · LIVE

3:07 min

Transitioning architecture to microservices at Netflix

Steve Upton Steve Upton · World Congress 2022

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

7:11 min

Managing accessibility standards and tooling at Google

Chris Heilmann +2 · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all