Security Engineer, Android Product Security

Google Google · Big Tech · New York, NY +1

Security Engineer for Android Product Security, focusing on building AI/LLM-driven security engineering projects and tooling to scale vulnerability research, defensive engineering, and mitigation strategies. The role involves analyzing and triaging vulnerabilities, conducting security research, and embedding security by design.

What you'd actually do

  1. Build cross-functional AI and Large Language Model (LLM) tooling to scale advanced vulnerability research, defensive engineering, and mitigation strategies across the organization.
  2. Participate in the Android and Device VRP program in analyzing and triaging incoming Vulnerabilities, working with cross-functional teams for vulnerability management and tool building, while proactively incorporating AI/LLMs into our VRP pipeline to improve efficiency.
  3. Conduct deep-dive security research into Android vulnerabilities and threat vectors, converting VRP reports into prioritized platform mitigation solutions and partner with Product/Feature teams to land them.
  4. Embed security by design through providing expert product security consultation and conducting comprehensive security design reviews for new Android features.

Skills

Required

  • security assessments
  • penetration testing
  • vulnerability research on the Android platform or Android applications
  • security engineering
  • computer and network security
  • security protocols
  • coding experience in one or more general purpose languages

Nice to have

  • designing and building LLM-based agentic workflows, frameworks, or automation tools specifically targeted at vulnerability research and remediation
  • participating in, triaging, or receiving rewards from high-impact Vulnerability Reward Programs (VRPs)
  • Artificial Intelligence (AI) and Large Language Model (LLM) concepts, with a demonstrated interest in applying them to security domains
  • Android platform security research
  • Android operating system architecture
  • security model
  • common attack surfaces

What the JD emphasized

  • AI-driven security engineering projects
  • build and deploy cross-functional AI tooling
  • scale in-depth Android vulnerability research
  • automate complex mitigation strategies
  • strong, foundational understanding of Android threat vectors and attack surfaces
  • AI and Large Language Model (LLM) tooling
  • AI/LLMs into our VRP pipeline

Other signals

  • AI-driven security engineering projects
  • build and deploy cross-functional AI tooling
  • scale in-depth Android vulnerability research
  • automate complex mitigation strategies
  • LLM-driven Security Engineering projects