Technical Program Manager III, Security and Firmware, Platforms and Devices
Google's projects, like our users, span the globe and require managers to keep the big picture in focus while being able to dive into the unique engineering challenges we face daily. As a Technical Program Manager at Google, you lead complex, multi-disciplinary engineering projects using your engineering expertise. You plan requirements with internal customers and usher projects through the entire project lifecycle. This includes managing project schedules, identifying risks and clearly communicating them to project stakeholders. You're equally at home explaining your team's analyses and recommendations to executives as you are discussing the technical trade-offs in product development with engineers.
Using your extensive technical and leadership expertise, you manage projects of various size and scope, identifying future opportunities, improving processes and driving the technical directions of your programs.
Fuchsia is Google's open-source, capability-based operating system, built on the Zircon microkernel and shipping on Google Nest devices. Our Security, Privacy, and Firmware program makes sure every product built on Fuchsia boots and updates reliably, is secure by design, and respects user privacy. The work spans the bootloader and verified boot, trusted execution environments, OS hardening, vulnerability response, and privacy reviews for every platform release. We partner with Android, product teams, Legal, and silicon vendors, and much of the platform is developed in the open at fuchsia.dev.
Fuchsia is a modern, open source operating system that is simple, secure, updatable, and performant. It’s a general purpose OS, designed to power an ecosystem of hardware and software, and provides core operating system functions like system resource management, a driver framework, and software abstractions.
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.US: $163000 - $236000 (USD) + 15% bonus target + equity + benefits
Learn more about benefits at Google.
Responsibilities
- Define the multi-quarter roadmap for operating system security, privacy, and firmware, translating ambiguous requirements into structured programs with clear milestones, risk ratings, and exit criteria.
- Manage programs for the platform's boot and update stack including verified boot, over-the-air updates, and recovery while aligning release milestones and firmware readiness with external silicon vendors.
- Direct security and privacy launch approval processes for platform releases and new hardware form factors by coordinating privacy design reviews, audits, and legal alignment to ensure secure, on-time delivery.
- Guide vulnerability management and incident response initiatives from the OS level down to vendor firmware, tracking findings against severity-based SLOs and upstreaming patches to reduce measurable risk.
- Cultivate strategic cross-organizational partnerships to deliver platform capabilities like hardware-backed key management, while building scalable tooling (including AI-assisted workflows) and streamlining review processes to improve organizational efficiency.
Minimum qualifications:
- Bachelor's degree in a technical field, or equivalent practical experience.
- 5 years of experience in program management.
- Experience in security engineering standards and practices, or managing security or privacy programs.
- Experience working with operating systems, firmware, or embedded software development teams.
Preferred qualifications:
- 5 years of experience managing cross-functional or cross-team projects.
- Experience with platform security technologies such as secure/verified boot, bootloaders, trusted execution environments (TEEs), hardware-backed key management, SELinux, or fuzzing.
- Experience managing technical programs for bootloaders or system firmware (e.g., U-Boot, UEFI, Android bootloaders), including flashing, A/B and over-the-air (OTA) updates, recovery, and production signing-key processes.
- Knowledge of privacy and security regulatory frameworks (e.g., GDPR, DMA, health data policies) and Android compatibility requirements (CDD/CTS/VTS).