Careers
Careers

job details

Back to jobs search

Jobs search results

2,744 jobs matched
Back to jobs search

Senior Penetration Tester, Kubernetes, Google Public Sector

GoogleReston, VA, USA; Maryland, USA; +2 more; +1 moreRemote eligible
Note: Google's hybrid workplace includes remote and in-office roles. By applying to this position you will have an opportunity to share your preferred working location from the following:

In-office locations: Reston, VA, USA.
Remote location(s): Maryland, USA; Virginia, USA.

Minimum qualifications:

  • Bachelor's degree or equivalent practical experience.
  • 5 years of experience in security engineering, with a focus on container security.
  • Experience with security assessments, design reviews, or threat modeling for containerized applications.
  • Ability to travel up to 25% of the time in order to engage with customers.
  • Active US Government Top Secret/Sensitive Compartmentalized Information (TS/SCI) security clearance.

Preferred qualifications:

  • Certifications in Certified Kubernetes Security Specialist (CKS), Offensive Security Certified Professional (OSCP), GIAC Cloud Penetration Tester (GCPN), or GIAC Web Application Tester (GWAPT).
  • Experience with securing cloud-native CI/CD pipelines.
  • Experience with container security tools such as Falco, Trivy, Twistlock, Kube-Hunter, Burp Suite, and Nmap.
  • Experience in scripting languages such as Python, Go, or Bash.
  • Understanding of the control plane (API server, etc.), worker nodes (kubelet, container runtime), pod security, networking (CNI), and IAM/RBAC mechanisms.
  • Ability to contribute to the security community (e.g., open-source projects, public research, conference presentations) related to containerization.

About the job

Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities.

In this role, you will be responsible for emulating real-world attack scenarios, identifying vulnerabilities in the AI environments and cloud-native ecosystems, and help to improve the overall security posture. You will have an understanding of containerization internals, common attack vectors, and pen-testing methodologies.

Google Public Sector brings the magic of Google to the mission of government and education with solutions purpose-built for enterprises. We focus on helping United States public sector institutions accelerate their digital transformations, and we continue to make significant investments and grow our team to meet the complex needs of local, state and federal government and educational institutions.

The US base salary range for this full-time position is $166,000-$244,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.

Responsibilities

  • Perform black box, grey box, and white box penetration tests against Kubernetes clusters, containerized applications, and the underlying cloud infrastructure.
  • Simulate realistic attack scenarios, target containerized and cloud environments, including initial access, exploitation, lateral movement across various environments.
  • Identify and exploit vulnerabilities in containerized components, including escape techniques, privilege escalation, runtime vulnerabilities, and insecure configurations in the control plane or network policies.
  • Automate tasks, analyze data, and develop exploits specifically for cloud-native and containerized targets.
  • Share knowledge and findings with defensive teams to improve their detection and response capabilities within containerized and cloud environments. Understand and apply purple team methodology for hardening of networks.

Information collected and processed as part of your Google Careers profile, and any job applications you choose to submit is subject to Google's Applicant and Candidate Privacy Policy.

Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See also Google's EEO Policy, Know your rights: workplace discrimination is illegal, Belonging at Google, and How we hire.

If you have a need that requires accommodation, please let us know by completing our Accommodations for Applicants form.

Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.

To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes.

Google apps
Main menu