New offer - be the first one to apply!

July 31, 2025

Senior Security Engineer, Vulnerability Management

Senior • On-site

$166,000 - $244,000/yr

Sunnyvale, CA

Minimum qualifications:

  • Bachelor's degree or equivalent practical experience.
  • 5 years of experience with security assessments or security design reviews or threat modeling.
  • 5 years of experience with security engineering, computer and network security and security protocols.
  • 5 years of coding experience in one or more general purpose languages.
  • 1 year of experience leading teams in a technical capacity or leading technical risk analysis in an enterprise environment.

Preferred qualifications:

  • Experience in vulnerability management or in software supply chain security.

About the job

Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

In this role, in AutoVM's security program engineering group you are responsible for designing and supporting a variety of vulnerability management efforts. You will be focusing on Delivered Software (e.g., Chrome, Android, SDKs etc).

You will be working with a group of engineers addressing a set of technologies, expanding and maintaining our offering with a combination of standard and Google-specific technologies, supported by the bulk of AutoVM's global infrastructure and scanner engineering teams. You will balance security-heavy design with software engineering-focused execution, as AutoVM gets things done at scale through automated software components.

You will engage with executive stakeholder engagement across many Protect Areas (PAs), and resolve technical issues across the cyber security industry.


The US base salary range for this full-time position is $166,000-$244,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.

Responsibilities

  • Manage a wide array of unsolved problems in vulnerability management in the AutoVM, Delivered Software Task Team, and ensure principal engineers run apt-get upgrades regularly.
  • Understand real-world vulnerability management (VM) issues, including identifying the right scanners for each situation, optimizing scanning program success, and meeting the needs of various stakeholders across multiple Product Areas.
  • Work on software that is directly shipped to customers, including Android and Chrome, designing and supporting vulnerability management solutions for key customer-visible codebases, in partnership with the relevant PAs.
  • Balance security-heavy program design work with software engineering efforts, as all AutoVM execution is built on large-scale, software-heavy components.