Google

Software Engineer, External API Security

Google New York, New York, United States · $147K–$210K/yr

Software Development · 10,001+ employees

6 h ago
Mid (2-5 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will develop AI-assisted API vulnerability scanning systems and drive remediation campaigns to secure Google's public-facing API boundaries. Additionally, you will collaborate with infrastructure teams to establish secure-by-default deployment architectures and enforce security policies.

What they look for

Software development Security engineering Vulnerability analysis Identity and access management Secure coding Security architecture Web APIs Microservices Go Java Python Automated code refactoring Agent-based AI Security policy enforcement

Requirements

Candidates must have a bachelor's degree and at least 2 years of experience in software development and security-related roles. Proficiency in programming languages like Go, Java, or Python and experience with API security are highly preferred.

Benefits

Bonus target Equity Health insurance

Full description

Minimum qualifications:

  • Bachelor's degree or equivalent practical experience.
  • 2 years of experience with software development in one or more programming languages, or 1 year of experience with an advanced degree.
  • 2 years of experience building software for security (e.g., vulnerability analysis, identity and access management).

Preferred qualifications:

  • Experience with agent-based artificial intelligence systems.
  • Experience in software security domains including secure coding practices, vulnerability analysis, or security architecture.
  • Experience designing, building, or securing web APIs and microservices.
  • Experience developing software with one or more general-purpose programming language including Go, Java, or Python.
  • Experience running automated code refactoring or programmatic remediation campaigns across systems.

About the job:

The Information Security Engineering, Authorization (ISE Auth) team strives to eliminate product authorization vulnerabilities at Google, through a combination of designing and rolling out safe-by-default developer surfaces, agentic security scanning and targeted remediation projects.

Our API Security pillar focuses specifically on the risk of externally exploitable authorization weaknesses in internet-facing APIs.

As a Software Engineer in ISE Auth, you will protect user data and secure Google's public-facing API boundaries from authorization vulnerabilities. In this role, you will design secure-by-default frameworks, build advanced AI-assisted security scanning systems, and run central remediation campaigns like changes to eliminate risk at scale. You will access control capabilities across all Google products.

Individual pay is determined by factors including job-related skills, experience, and relevant education or training.

US: $147000 - $210000 (USD) + 15% bonus target + equity + benefits

Learn more about benefits at Google. Responsibilities:

  • Develop and improve AI-assisted API vulnerability scanning systems, framework improvements, and automated launch checkers to proactively identify authorization bypasses.
  • Drive central remediation campaigns to remediate systemic vulnerability classes without putting undue churn onto product teams.
  • Collaborate with core infrastructure and product teams to establish secure-by-default API deployment architectures and to pragmatically reduce risk.
  • Build and maintain infrastructure and automation for security policy enforcement, monitoring, and regression prevention.
  • Analyze emerging authorization bypass patterns and evaluate agent-based AI systems to proactively harden API access controls.