Senior Security Engineer, Abuse and AI VRP
Job Overview
-
Date PostedNovember 12, 2025
-
Location
-
Expiration date--
Job Description
2025-11-07T18:29:29.947Z
79639648204137158
Minimum qualifications:
- Bachelor’s degree or equivalent practical experience.
- 5 years of coding experience in one or more general purpose languages.
-
5 years of experience working in a security field such as application security, network security, or incident response.
Preferred qualifications:
- Experience with generative AI or similar AI/ML systems.
- Experience working with external parties or in a publicly-facing role.
- Experience working in bug bounties.
- Excellent problem-solving and critical thinking skills with attention to detail in an ever-changing environment.
About the job
There’s no such thing as a “safe system” – only safer systems. Our Security team works to create and maintain the safest operating environment for Google’s users and developers. As a Security Engineer, you help protect network boundaries, keep computer systems and network devices hardened against attacks and provide security services to protect highly sensitive data like passwords and customer information. Security Engineers work directly with network equipment and actively monitor our systems for attacks and intrusions. You also work with software engineers to proactively identify and fix security flaws and vulnerabilities.
You use your industry experience to own and drive the resolution of complex security incidents, policy questions and technical security issues.
The Abuse and AI Vulnerability Rewards Program (VRP) is a bug bounty program which covers abusive use of Google’s systems, including Generative AI systems such as Gemini. The VRP team is responsible for assessing reports from external security researchers, interacting directly with researchers and product teams, deciding on rewards for reporters, and managing the resolution and coordinated disclosure of vulnerabilities.
Responsibilities
- Assess the validity and severity of externally-reported security and abuse issues, including issues impacting GenAI products.
- Recreate externally-reported security and abuse issues, capturing information required by the product teams to understand and resolve.
- Serve as a point of technical escalation for the first-line triage team. Manage communication between researchers and product teams.
- Assess reported bugs to determine impact, and what, if any, reward should be issued to the researcher under VRP rules.
- Participate in the VRP community and engage in cross-team projects to improve the bug bounty experience for all reporters.
Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Google’s EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our Accommodations for Applicants form.