Senior Software Engineer, Product Security, DeepMind
The GDM Product Security Team serves as the single point of accountability for GDM's product security posture by providing embedded, specialized security expertise across infrastructure and product development lifecycles, from early design through production operations. The team ensures GDM’s products and systems remain a secure and reliable frontier AI platform by bridging product development with Google's horizontal security functions and the GDM Security and Privacy organization.
In this role, you will embed with product teams to drive application security across GDM's flagship consumer and developer surfaces, including GeminiApps and AI Studio. You will perform comprehensive security reviews, design client-side data protection mechanisms, audit web and mobile application attack surfaces, and implement secure paved paths for developer teams. A core foundation of this role is a demonstrated background in security operations—you will actively own vulnerability triage, evaluate external bug bounty (Vulnerability Reward Program) submissions, respond to application security incidents, and participate in rotational operational security on-call coverage.
Artificial intelligence will be one of humanity’s most transformative inventions. At Google DeepMind, we are a pioneering AI lab with exceptional interdisciplinary teams focused on advancing AI development to solve complex global challenges and accelerate high-quality product innovation for billions of users. We use our technologies for widespread public benefit and scientific discovery, ensuring safety and ethics are always our highest priority.
We are pushing the boundaries across multiple domains. Our global teams offer diverse learning opportunities and varied career pathways for those driven to achieve exceptional results through collective effort.
US: $207000 - $300000 (USD) + 20% bonus target + equity + benefits
Learn more about benefits at Google.
Responsibilities
- Perform security evaluations and code audits across web and mobile (Android/iOS) applications on a recurring cadence, identifying flaws and driving remediation to completion.
- Conduct in-depth search architecture reviews, code-level security audits, and feature-level threat assessments for GDM products.
- Build and continuously maintain threat models for GDM web/mobile products and client-facing AI capabilities, addressing unique risks around third-party integrations, agentic features, and client-side data privacy.
- Develop secure-by-default client libraries, SDKs, and templates that make application security seamless for GDM product developers.
- Serve as an active member of the rotational security operations on-call team.
Minimum qualifications:
- Bachelor's degree in Computer Science, Cybersecurity, Computer Engineering, or equivalent practical experience.
- 8 years of coding experience in general-purpose languages (e.g., JavaScript/TypeScript, Java/Kotlin, Swift, Python, Go, C++).
- 5 years of experience in application security engineering (web application security, mobile client security, web API security, or client-side cryptography).
- 5 years of experience in security operations (e.g., vulnerability management, bug bounty triage, penetration testing, red team engagement, or operational incident handling).
- 5 years of experience testing, and launching software products.
Preferred qualifications:
- Master’s degree or PhD in Computer Science, Cybersecurity, Computer Engineering, or a related technical field.
- Experience in a technical leadership role leading project teams and setting technical direction.
- Expertise in modern web and mobile OS security models.
- Strong background in automated scanning, static/dynamic code analysis and fuzzing.
- Proven track record operating in an on-call operational capacity, managing live security escalations, and collaborating with cross-functional Incident Response teams.