Principal Engineer, Google Compute Platform Security

Google

New York (NY)

Hybrid

USD 307,000 - 427,000

Full time

31 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health, dental, vision, life, andDis能力
401(k) with company match
Paid time off 20 days/year
Sick time 40 hours/year (Seattle 69)
Maternity leave 28–30 weeks
Baby Bonding leave 18 weeks
13 paid holidays

Job summary

Google is seeking a Principal Engineer for the GCE Platform Security team to lead the security posture of Google Compute Engine, safeguarding the global infrastructure that powers Google Cloud and related AI workloads.

You will guide defensive architecture across control planes and node data planes, addressing emerging AI-driven threat vectors and hardware-level vulnerabilities, while collaborating with diverse engineering teams to raise the bar on cloud security.

Qualifications

  • Bachelor's degree in Computer Science, Computer Engineering, or equivalent practical experience.
  • 15 years of professional software development experience, or 13 years with an advanced degree.
  • Experience architecting, developing, and securing low-level systems software across the virtualization and operating systems stack (e.g., hypervisors such as KVM/Cloud Hypervisor/QEMU, Linux kernel internals, VMMs, firmware, or hardware-assisted virtualization).
  • Advanced degree (Master's or PhD) in Computer Science, Computer Engineering, Cybersecurity, or a related technical field.
  • 20 years of software engineering experience, with leadership in cloud platform security, hypervisor security, hardware/CPU security, or OS defense.
  • Experience anticipating and defending against emerging adversarial capabilities, including AI/LLM-accelerated vulnerability discovery, automated exploit synthesis, and autonomous agentic threat vectors.
  • Experience in cross-organizational technical leadership, executive communication, and building consensus across large, multi-disciplinary engineering organizations (Hardware/Silicon).
  • Expertise in hardware-software security co-design, including CPU microarchitectural vulnerability mitigation, hardware root-of-trust, vTPM, and Confidential Computing.

Responsibilities

  • Serve as the overall technical authority for GCE Platform Security, defining and driving the multi-year security strategy across control planes and node data planes.
  • Formulate defenses to counter autonomous agentic threat vectors and LLM-assisted exploitation tools, with automated vulnerability discovery and rapid incident response.
  • Architect hardware-level defenses and isolation to mitigate CPU vulnerabilities and side-channel threats.
  • Lead security defenses and privilege reduction across hypervisors, VMMs, and host kernels, implementing sandboxing and defense against virtualization escapes.
  • Drive host security and isolation with zero-trust architectures and hardware-assisted security functions.

Skills

15+ years software development
Security architecture
Hypervisor security
OS security

Education

Bachelor's degree in Computer Science/Computer Engineering or equivalent practical experience
Advanced degree (Master's/PhD) in CS/CE/Cybersecurity or related field

Tools

KVM
QEMU
Linux kernel
VMMs

Job description

In accordance with Washington state law, we are highlighting our comprehensive benefits package, which is available to all eligible US based employees. Benefits for this role include:



  • Health, dental, vision, life, disability insurance

  • Retirement Benefits: 401(k) with company match

  • Paid Time Off: 20 days of vacation per year, accruing at a rate of 6.15 hours per pay period for the first five years of employment

  • Sick Time: 40 hours/year (increased to 69 hours/year for Seattle) including 5 discretionary sick days per instance

  • Maternity Leave (Short-Term Disability + Baby Bonding): 28-30 weeks

  • Baby Bonding Leave: 18 weeks

  • Holidays: 13 paid days per year


Note: By applying to this position you will have an opportunity to share your preferred working location from the following:


Seattle, WA, USA; Kirkland, WA, USA; New York, NY, USA; Sunnyvale, CA, USA


Minimum qualifications:


  • Bachelor's degree in Computer Science, Computer Engineering, or equivalent practical experience.

  • 15 years of professional software development experience, or 13 years with an advanced degree.

  • Experience architecting, developing, and securing low-level systems software across the virtualization and operating systems stack (e.g., hypervisors such as KVM/Cloud Hypervisor/QEMU, Linux kernel internals, VMMs, firmware, or hardware-assisted virtualization).


Preferred qualifications:


  • Advanced degree (Master's or PhD) in Computer Science, Computer Engineering, Cybersecurity, or a related technical field.

  • 20 years of software engineering experience, with experience with industry leadership in cloud platform security, hypervisor security, hardware/CPU security, or operating system defense.

  • Experience anticipating and defending against emerging adversarial capabilities, including AI/LLM-accelerated vulnerability discovery, automated exploit synthesis, and autonomous agentic threat vectors.

  • Experience in cross-organizational technical leadership, executive communication, and building consensus across large, multi-disciplinary engineering organizations (Hardware/Silicon).

  • Expertise in hardware-software security co-design, including CPU microarchitectural vulnerability mitigation (speculative execution, side-channel analysis), hardware root-of-trust, vTPM, and Confidential Computing.


About The Job

As Principal Engineer for GCE Platform Security, you will serve as the premier technical authority, executive architect, and overall owner for the end-to-end security posture of Google Compute Engine (GCE) - protecting the foundational global infrastructure that powers Google Cloud, Core Google services, and advanced AI research labs and mission-critical enterprise workloads.


In this high-impact strategic role, your leadership spans the complete architectural continuum between the distributed Control Plane and the foundational Data Plane. Across the control plane, you will architect robust, scalable defenses for multi-tenant orchestration, resource lifecycle management, zero-trust identity and access boundaries, supply-chain integrity, and high-assurance compliance for regulated and public-sector cloud environments. Across the node data plane, you will lead deep systems security architecture across hypervisors, virtual machine monitors (VMMs), host operating systems, kernel subsystems, and hardware-level isolation mechanisms.


Crucially, you will navigate a rapidly transforming threat landscape shaped by the emergence of agentic threat vectors enabled through advanced LLMs, where automated, AI-driven vulnerability discovery and exploit generation compress attacker timelines to machine speed. You will lead proactive defense-in-depth across the platform - mitigating hardware and microarchitectural CPU vulnerabilities (e.g., speculative execution, transient execution side-channels, and address space isolation), eliminating memory safety exploitation risks across the virtualization stack, and advancing host deprivileging and zero-trust host architectures.


Furthermore, you will advocate for next-generation virtualization security designs - leveraging custom silicon for isolation, establishing multi-domain security boundaries, and architecting secure runtime substrates for next-generation AI workloads, high-density sandboxed execution environments, and massive accelerator clusters.


Google Cloud accelerates every organization’s ability to digitally transform its business and industry. We deliver enterprise-grade solutions that leverage Google’s cutting-edge technology, and tools that help developers build more sustainably. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.


Individual pay is determined by factors including job-related skills, experience, and relevant education or training.


US: $307000 - $427000 (USD) + 30% bonus target + equity + benefits


Responsibilities

Learn more about benefits at Google .



  • Serve as the overall technical authority and executive owner for GCE Platform Security, defining and driving the multi-year security strategy across distributed global control planes and low-level node data planes.

  • Formulate architectural and operational defenses to counter the rapid emergence of autonomous agentic threat vectors and LLM-assisted exploitation tools, establishing automated vulnerability discovery, proactive mitigation frameworks, and rapid incident response capabilities across the fleet.

  • Architect robust, hardware-level defenses and isolation boundaries to eliminate and mitigate hardware CPU vulnerabilities, speculative execution side-channels, transient execution threats, and cross-tenant leakage

  • Lead security defenses and privilege reduction across hypervisor technologies, virtual machine monitors (VMMs), host kernels, and low-level runtimes, implementing sandboxing and defense against virtualization escapes.

  • Drive the architectural outlook for host security and isolation, advancing host deprivileging, zero-trust host architectures, hardware-assisted offloading of security and lifecycle functions.


Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Google's EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our Accommodations for Applicants form .

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Engineer, Google Compute Platform Security
Principal Engineer, Google Compute Platform Security

Google • Sunnyvale (CA)

On-site
USD 307,000 - 427,000
Health insurance
401(k) with company match
Paid time off
+1
Principal Engineer, Google Compute Platform Security
Principal Engineer, Google Compute Platform Security

Google • Seattle (WA)

On-site
USD 307,000 - 427,000
Health insurance
401(k) with company match
Paid time off - 20 days
+4
Principal Engineer, Google Compute Platform Security
Principal Engineer, Google Compute Platform Security

Google • Kirkland (WA)

On-site
USD 307,000 - 427,000
Health insurance
401(k) with company match
Vacation: 20 days per year
+4
Principal Engineer, Google Compute Platform Security
Principal Engineer, Google Compute Platform Security

Google Inc. • New York (NY)

Hybrid
USD 307,000 - 427,000
Health insurance
Dental and vision insurance
Life and disability insurance
+6
Security Engineer II, Hybrid Cloud Guidelines
Security Engineer II, Hybrid Cloud Guidelines

Google • New York (NY)

On-site
USD 123,000 - 174,000
Health insurance
401(k) with company match
PTO 20 days per year
+4
Security Engineer II, Hybrid Cloud Guidelines
Security Engineer II, Hybrid Cloud Guidelines

Google • San Jose (CA)

On-site
USD 123,000 - 174,000
Security Engineer II, Hybrid Cloud Guidelines
Security Engineer II, Hybrid Cloud Guidelines

Google • United States

Hybrid
USD 123,000 - 174,000
Health insurance
401(k) with company match
Paid time off
+4
Security Engineer II, Hybrid Cloud Guidelines
Security Engineer II, Hybrid Cloud Guidelines

Google • Seattle (WA)

On-site
USD 123,000 - 174,000
Health insurance
Dental insurance
Vision insurance
+2
Security Engineer II, Hybrid Cloud Guidelines
Security Engineer II, Hybrid Cloud Guidelines

Google • Kirkland (WA)

Hybrid
USD 123,000 - 174,000
Health insurance
401(k) match
Paid time off
+4
Staff Security Engineer, Google Distributed Cloud, Federated Security
Staff Security Engineer, Google Distributed Cloud, Federated Security

Google • Seattle (WA)

On-site
USD 207,000 - 300,000
Health insurance
Dental insurance
Vision insurance
+8