New offer - be the first one to apply!

September 17, 2025

Senior Penetration Tester, Kubernetes, Google Public Sector

Senior • Hybrid • On-site • Remote

$166,000 - $244,000/yr

Reston, VA , +1


Minimum qualifications:

  • Bachelor's degree or equivalent practical experience.
  • 5 years of experience in security engineering, with a focus on container security.
  • Experience with security assessments, design reviews, or threat modeling for containerized applications.
  • Ability to travel up to 25% of the time in order to engage with customers.
  • Active US Government Top Secret/Sensitive Compartmentalized Information (TS/SCI) security clearance.

Preferred qualifications:

  • Certifications in Certified Kubernetes Security Specialist (CKS), Offensive Security Certified Professional (OSCP), GIAC Cloud Penetration Tester (GCPN), or GIAC Web Application Tester (GWAPT).
  • Experience with securing cloud-native CI/CD pipelines.
  • Experience with container security tools such as Falco, Trivy, Twistlock, Kube-Hunter, Burp Suite, and Nmap.
  • Experience in scripting languages such as Python, Go, or Bash.
  • Understanding of the control plane (API server, etc.), worker nodes (kubelet, container runtime), pod security, networking (CNI), and IAM/RBAC mechanisms.
  • Ability to contribute to the security community (e.g., open-source projects, public research, conference presentations) related to containerization.

About the job

Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

In this role, you will be responsible for emulating real-world attack scenarios, identifying vulnerabilities in the AI environments and cloud-native ecosystems, and help to improve the overall security posture. You will have an understanding of containerization internals, common attack vectors, and pen-testing methodologies.

Google Public Sector brings the magic of Google to the mission of government and education with solutions purpose-built for enterprises. We focus on helping United States public sector institutions accelerate their digital transformations, and we continue to make significant investments and grow our team to meet the complex needs of local, state and federal government and educational institutions.

The US base salary range for this full-time position is $166,000-$244,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.

Responsibilities

  • Perform black box, grey box, and white box penetration tests against Kubernetes clusters, containerized applications, and the underlying cloud infrastructure.
  • Simulate realistic attack scenarios, target containerized and cloud environments, including initial access, exploitation, lateral movement across various environments.
  • Identify and exploit vulnerabilities in containerized components, including escape techniques, privilege escalation, runtime vulnerabilities, and insecure configurations in the control plane or network policies.
  • Automate tasks, analyze data, and develop exploits specifically for cloud-native and containerized targets.
  • Share knowledge and findings with defensive teams to improve their detection and response capabilities within containerized and cloud environments. Understand and apply purple team methodology for hardening of networks.