> Markdown version of [/jobs/ext/3054375-senior-software-engineer-product-security-deepmind](https://www.wearedevelopers.com/jobs/ext/3054375-senior-software-engineer-product-security-deepmind). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Software Engineer, Product Security, DeepMind - **Company:** Google LLC - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $207,000.0 - $300,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Artificial Intelligence, Software System Penetration Testing, Bioinformatics, C++ (Programming Language), Static Program Analysis, Cyber Security, Computer Programming, Computer Engineering, Core Foundation, Mobile Application Software, Python (Programming Language), Red Team (Cyber Security), Web Application Security, TypeScript, Software Vulnerability Management, Mobile Os, Software Security, Swift (Programming Language), Kotlin, Information Technology, Web Api, Golang - **Published:** September 24, 2026 - **Apply:** https://www.manhattanjobs.com/job.asp?id=3394857393&tx=JL6963FFI&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Bachelor's degree in Computer Science, Cybersecurity, Computer Engineering, or equivalent practical experience. * 8 years of coding experience in general-purpose languages (e.g., JavaScript/TypeScript, Java/Kotlin, Swift, Python, Go, C++). * 5 years of experience in application security engineering (web application security, mobile client security, web API security, or client-side cryptography). * 5 years of experience in security operations (e.g., vulnerability management, bug bounty triage, penetration testing, red team engagement, or operational incident handling). * 5 years of experience testing, and launching software products., * Master's degree or PhD in Computer Science, Cybersecurity, Computer Engineering, or a related technical field. * Experience in a technical leadership role leading project teams and setting technical direction. * Expertise in modern web and mobile OS security models. * Strong background in automated scanning, static/dynamic code analysis and fuzzing. * Proven track record operating in an on-call operational capacity, managing live security escalations, and collaborating with cross-functional Incident Response teams. ## Description The GDM Product Security Team serves as the single point of accountability for GDM's product security posture by providing embedded, specialized security expertise across infrastructure and product development lifecycles, from early design through production operations. The team ensures GDM's products and systems remain a secure and reliable frontier AI platform by bridging product development with Google's horizontal security functions and the GDM Security and Privacy organization. In this role, you will embed with product teams to drive application security across GDM's flagship consumer and developer surfaces, including GeminiApps and AI Studio. You will perform comprehensive security reviews, design client-side data protection mechanisms, audit web and mobile application attack surfaces, and implement secure paved paths for developer teams. A core foundation of this role is a demonstrated background in security operations-you will actively own vulnerability triage, evaluate external bug bounty (Vulnerability Reward Program) submissions, respond to application security incidents, and participate in rotational operational security on-call coverage. Artificial intelligence will be one of humanity's most transformative inventions. At Google DeepMind, we are a pioneering AI lab with exceptional interdisciplinary teams focused on advancing AI development to solve complex global challenges and accelerate high-quality product innovation for billions of users. We use our technologies for widespread public benefit and scientific discovery, ensuring safety and ethics are always our highest priority. We are pushing the boundaries across multiple domains. Our global teams offer diverse learning opportunities and varied career pathways for those driven to achieve exceptional results through collective effort.Individual pay is determined by factors including job-related skills, experience, and relevant education or training. US: $207000 - $300000 (USD) + 20% bonus target + equity + benefits, * Perform security evaluations and code audits across web and mobile (Android/iOS) applications on a recurring cadence, identifying flaws and driving remediation to completion. * Conduct in-depth search architecture reviews, code-level security audits, and feature-level threat assessments for GDM products. * Build and continuously maintain threat models for GDM web/mobile products and client-facing AI capabilities, addressing unique risks around third-party integrations, agentic features, and client-side data privacy. * Develop secure-by-default client libraries, SDKs, and templates that make application security seamless for GDM product developers. * Serve as an active member of the rotational security operations on-call team. Information collected and processed as part of your Google Careers profile, and any job applications you choose to submit is subject to Google'sApplicant and Candidate Privacy Policy (./privacy-policy) . Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See alsoGoogle's EEO Policy (https://www.google.com/about/careers/applications/eeo/) ,Know your rights: workplace discrimination is illegal (https://careers.google.com/jobs/dist/legal/EEOC_KnowYourRights_10_20.pdf) ,Belonging at Google (https://about.google/belonging/) , andHow we hire (https://careers.google.com/how-we-hire/) . If you have a need that requires accommodation, please let us know by completing ourAccommodations for Applicants form (https://goo.gl/forms/aBt6Pu71i1kzpLHe2) . Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting. To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes. Equity is granted exclusively and discretionarily by Alphabet Inc. on the basis of an agreement concluded between you and Alphabet Inc. Alphabet Inc. is your sole contractual partner with respect to equity grants. GSU grants are not guaranteed, are discretionary, are subject to approval by the Alphabet Inc. board of directors or its delegate, the terms of the relevant Alphabet Inc. stock plan, and your grant agreement. They have no impact on statutory payments. Current or past grants do not confer an acquired right. ## Related Videos - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Kotlin Multiplatform - True power of native code reuse](https://www.wearedevelopers.com/videos/4-kotlin-multiplatform-true-power-of-native-code-reuse) - [Web APIs you might not know about](https://www.wearedevelopers.com/videos/281-web-apis-you-might-not-know-about) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) ## Related Articles - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 129 - Now that's what I call private data!](https://www.wearedevelopers.com/magazine/468-dev-digest-129-now-that-s-what-i-call-private-data) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)