Security Engineer, Android Product Security

Google Inc.

New York (NY)

On-site

USD 147,000 - 210,000

Full time

43 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Google is seeking a Security Engineer for Android Product Security in New York. You will join a cross-functional APSE team to defend Android with AI-driven security projects, triage VRP findings, and deliver comprehensive mitigations.

The role emphasizes deep Android threat understanding and collaboration with product teams. You will influence the Android ecosystem by designing AI/LLM tooling, performing in-depth vulnerability research, and applying security reviews to new features.

Qualifications

  • Bachelor's degree or equivalent practical experience.
  • 2 years of security assessments, penetration testing, or vulnerability research on the Android platform or Android applications.
  • 2 years of security engineering, computer and network security and security protocols.
  • 2 years of coding experience in one or more general purpose languages.

Responsibilities

  • Build AI/LLM-driven security tooling to scale vulnerability research and mitigation.
  • Collaborate with Android Security, Development, and Partner Engineering partners.
  • Triage VRP reports and work with cross-functional teams to implement mitigations.
  • Provide security design reviews for new Android features and drive security by design.

Skills

Security assessments
Penetration testing
Vulnerability research
Android platform security
Coding experience

Education

Bachelor's degree or equivalent practical experience

Job description

Security Engineer, Android Product Security

Share Security Engineer, Android Product Security

  • Copy link

corporate_fare Google New York, NY, USA

Mid

Experience driving progress, solving problems, and mentoring more junior team members; deeper expertise and applied knowledge within relevant area.

Share Security Engineer, Android Product Security

  • Bachelor's degree or equivalent practical experience.
  • 2 years of experience with security assessments, penetration testing, or vulnerability research on the Android platform or Android applications.
  • 2 years of experience with security engineering, computer and network security and security protocols.
  • 2 years of coding experience in one or more general purpose languages.
Preferred qualifications:
  • Experience designing and building LLM-based agentic workflows, frameworks, or automation tools specifically targeted at vulnerability research and remediation.
  • Direct experience participating in, triaging, or receiving rewards from high-impact Vulnerability Reward Programs (VRPs).
  • Experience in Android platform security research, as demonstrated by public CVEs, published whitepapers, or presentations at reputable security conferences (e.g., DEF CON, etc.).
  • Familiarity with Artificial Intelligence (AI) and Large Language Model (LLM) concepts, with a demonstrated interest in applying them to security domains.
  • Foundational understanding of the Android operating system architecture, security model, and common attack surfaces.
About the job

In this role, you will join the Android Product Security Engineering (APSE) a cross-functional team tasked with ensuring Android is the most secure and defended operating system in the world, protecting the entire ecosystem of three billion devices. You will achieve this by collaborating with internal partners across Android Security, Development, and Partner Engineering, as well as stakeholders outside of Android such as Chrome, and engage with a vast network of external partners, including SoC manufacturers and telecom carriers. You will secure this ecosystem by leading the industry-defining Android Vulnerability Reward Program (VRP) and pioneering AI-driven security engineering projects to drive advanced vulnerability research and mitigation at scale.

As a Security Engineer, you will play a pivotal role in enhancing the Android ecosystem's security posture, focusing heavily on driving AI-powered security innovation alongside operational vulnerability response.

In this role, you will build AI/LLM-driven Security Engineering projects, rather than just streamlining existing pipelines, build and deploy cross-functional AI tooling designed to proactively scale in-depth Android vulnerability research and automate complex mitigation strategies, as these tools require deep domain expertise to build effectively, the engineer is expected to have a strong, foundational understanding of Android threat vectors and attack surfaces.

You will actively participate in the Android Vulnerability Reward Program (VRP) by participating in the triage rotations and engaging with the external researcher community. You will apply platform expertise to conduct comprehensive security research, respond to vulnerabilities in both pre-release and in-market Android products, and partner directly with feature teams to implement robust mitigation solutions.

Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

US: $147000 - $210000 (USD) + 15% bonus target + equity + benefits

Learn more about benefits at Google.

  • Build cross-functional AI and Large Language Model (LLM) tooling to scale advanced vulnerability research, defensive engineering, and mitigation strategies across the organization.
  • Participate in the Android and Device VRP program in analyzing and triaging incoming Vulnerabilities, working with cross-functional teams for vulnerability management and tool building, while proactively incorporating AI/LLMs into our VRP pipeline to improve efficiency.
  • Conduct deep-dive security research into Android vulnerabilities and threat vectors, converting VRP reports into prioritized platform mitigation solutions and partner with Product/Feature teams to land them.
  • Embed security by design through providing expert product security consultation and conducting comprehensive security design reviews for new Android features.

Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See also Google's EEO Policy , Know your rights: workplace discrimination is illegal , Belonging at Google , and How we hire .

Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.

Equity is granted exclusively and discretionarily by Alphabet Inc. on the basis of an agreement concluded between you and Alphabet Inc. Alphabet Inc. is your sole contractual partner with respect to equity grants. GSU grants are not guaranteed, are discretionary, the terms of the relevant Alphabet Inc. stock plan, and your grant agreement. They have no impact on statutory payments. Current or past grants do not confer an acquired right.

About the job

In this role, you will join the Android Product Security Engineering (APSE) a cross-functional team tasked with ensuring Android is the most secure and defended operating system in the world, protecting the entire ecosystem of three billion devices. You will achieve this by collaborating with internal partners across Android Security, Development, and Partner Engineering, as well as stakeholders outside of Android such as Chrome, and engage with a vast network of external partners, including SoC manufacturers and telecom carriers. You will secure this ecosystem by leading the industry-defining Android Vulnerability Reward Program (VRP) and pioneering AI-driven security engineering projects to drive advanced vulnerability research and mitigation at scale.

As a Security Engineer, you will play a pivotal role in enhancing the Android ecosystem's security posture, focusing heavily on driving AI-powered security innovation alongside operational vulnerability response.

In this role, you will build AI/LLM-driven Security Engineering projects, rather than just streamlining existing pipelines, build and deploy cross-functional AI tooling designed to proactively scale in-depth Android vulnerability research and automate complex mitigation strategies, as these tools require deep domain expertise to build effectively, the engineer is expected to have a strong, foundational understanding of Android threat vectors and attack surfaces.

You will actively participate in the Android Vulnerability Reward Program (VRP) by participating in the triage rotations and engaging with the external researcher community. You will apply platform expertise to conduct comprehensive security research, respond to vulnerabilities in both pre-release and in-market Android products, and partner directly with feature teams to implement robust mitigation solutions.

Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

US: $147000 - $210000 (USD) + 15% bonus target + equity + benefits

Learn more about benefits at Google.

  • Build cross-functional AI and Large Language Model (LLM) tooling to scale advanced vulnerability research, defensive engineering, and mitigation strategies across the organization.
  • Participate in the Android and Device VRP program in analyzing and triaging incoming Vulnerabilities, working with cross-functional teams for vulnerability management and tool building, while proactively incorporating AI/LLMs into our VRP pipeline to improve efficiency.
  • Conduct deep-dive security research into Android vulnerabilities and threat vectors, converting VRP reports into prioritized platform mitigation solutions and partner with Product/Feature teams to land them.
  • Embed security by design through providing expert product security consultation and conducting comprehensive security design reviews for new Android features.

Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See also Google's EEO Policy , Know your rights: workplace discrimination is illegal , Belonging at Google , and How we hire .

Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.

Equity is granted exclusively and discretionarily by Alphabet Inc. on the basis of an agreement concluded between you and Alphabet Inc. Alphabet Inc. is your sole contractual partner with respect to equity grants. GSU grants are not guaranteed, are discretionary, the terms of the relevant Alphabet Inc. stock plan, and your grant agreement. They have no impact on statutory payments. Current or past grants do not confer an acquired right.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer, Android Product Security
Security Engineer, Android Product Security

Google • New York (NY)

On-site
USD 147,000 - 211,000
Security Engineer, Android Product Security
Security Engineer, Android Product Security

Socket.dev • New York (NY)

On-site
USD 147,000 - 210,000
Information Security Engineer, Product Security Engineering
Information Security Engineer, Product Security Engineering

Google Inc. • New York (NY)

On-site
USD 147,000 - 210,000
Health insurance
401(k) with company match
Paid time off
+4
Engineering Director, Product Security, Core
Engineering Director, Product Security, Core

Google Inc. • Sunnyvale (CA), Northern (KY)

Hybrid
USD 307,000 - 427,000
Equity
Bonus target
Benefits
Senior Security Engineer, Product Security Engineering, Cloud CISO
Senior Security Engineer, Product Security Engineering, Cloud CISO

Google • United States

On-site
USD 174,000 - 253,000
Health, dental, vision, life
401(k) with company match
Paid time off
+1
Staff Security Engineer Manager
Staff Security Engineer Manager

Google • Sunnyvale (CA)

On-site
USD 180,000 - 301,000
Health, dental, vision, life, and long
Disability insurance
401(k) with company match
+5
Staff Security Engineer, Product Security Engineering, Cloud CISO
Staff Security Engineer, Product Security Engineering, Cloud CISO

Google Inc. • New York (NY)

Hybrid
USD 207,000 - 300,000
Health & life insurance
401(k) with company match
Paid time off
+3
Senior Security Engineer, Android Anti-Malware
Senior Security Engineer, Android Anti-Malware

Google Inc. • Kirkland (WA)

On-site
USD 174,000 - 252,000
Engineering Director, Product Security, Core
Engineering Director, Product Security, Core

Google • United States

On-site
USD 307,000 - 427,000
Equity grant
Bonus target
Staff Security Engineer, Product Security Engineering, Cloud CISO
Staff Security Engineer, Product Security Engineering, Cloud CISO

Google • United States

On-site
USD 207,000 - 300,000
Health insurance
Dental & vision coverage
401(k) with company match
+3