About the role
What will you do at Google?
MINIMUM QUALIFICATIONS:
* Bachelor’s degree in Computer Science, Computer Engineering, or equivalent
practical experience.
* 15 years of professional software development experience, or 13 years with an
advanced degree.
* Experience architecting, developing, and securing low-level systems software
across the virtualization and operating systems stack (e.g., hypervisors such
as KVM/Cloud Hypervisor/QEMU, Linux kernel internals, VMMs, firmware, or
hardware-assisted virtualization).
PREFERRED QUALIFICATIONS:
* Advanced degree (Master’s or PhD) in Computer Science, Computer Engineering,
Cybersecurity, or a related technical field.
* 20 years of software engineering experience, with experience with industry
leadership in cloud platform security, hypervisor security, hardware/CPU
security, or operating system defense.
* Experience anticipating and defending against emerging adversarial
capabilities, including AI/LLM-accelerated vulnerability discovery, automated
exploit synthesis, and autonomous agentic threat vectors.
* Experience in cross-organizational technical leadership, executive
communication, and building consensus across large, multi-disciplinary
engineering organizations (Hardware/Silicon).
* Expertise in hardware-software security co-design, including CPU
microarchitectural vulnerability mitigation (speculative execution,
side-channel analysis), hardware root-of-trust, vTPM, and Confidential
Computing.
ABOUT THE JOB:
As Principal Engineer for GCE Platform Security, you will serve as the premier
technical authority, executive architect, and overall owner for the end-to-end
security posture of Google Compute Engine (GCE) - protecting the foundational
global infrastructure that powers Google Cloud, Core Google services, and
advanced AI research labs and mission-critical enterprise workloads.
In this high-impact strategic role, your leadership spans the complete
architectural continuum between the distributed Control Plane and the
foundational Data Plane. Across the control plane, you will architect robust,
scalable defenses for multi-tenant orchestration, resource lifecycle management,
zero-trust identity and access boundaries, supply-chain integrity, and
high-assurance compliance for regulated and public-sector cloud environments.
Across the node data plane, you will lead deep systems security architecture
across hypervisors, virtual machine monitors (VMMs), host operating systems,
kernel subsystems, and hardware-level isolation mechanisms.
Crucially, you will navigate a rapidly transforming threat landscape shaped by
the emergence of agentic threat vectors enabled through advanced LLMs, where
automated, AI-driven vulnerability discovery and exploit generation compress
attacker timelines to machine speed. You will lead proactive defense-in-depth
across the platform - mitigating hardware and microarchitectural CPU
vulnerabilities (e.g., speculative execution, transient execution side-channels,
and address space isolation), eliminating memory safety exploitation risks
across the virtualization stack, and advancing host deprivileging and zero-trust
host architectures.
Furthermore, you will advocate for next-generation virtualization security
designs - leveraging custom silicon for isolation, establishing multi-domain
security boundaries, and architecting secure runtime substrates for
next-generation AI workloads, high-density sandboxed execution environments, and
massive accelerator clusters.
Google Cloud accelerates every organization’s ability to digitally transform its
business and industry. We deliver enterprise-grade solutions that leverage
Google’s cutting-edge technology, and tools that help developers build more
sustainably. Customers in more than 200 countries and territories turn to Google
Cloud as their trusted partner to enable growth and solve their most critical
business problems.
Individual pay is determined by factors including job-related skills,
experience, and relevant education or training.
US: $307000 - $427000 (USD) + 30% bonus target + equity + benefits
Learn more about benefits at Google
[https://www.google.com/about/careers/applications/benefits/].
RESPONSIBILITIES:
* Serve as the overall technical authority and executive owner for GCE Platform
Security, defining and driving the multi-year security strategy across
distributed global control planes and low-level node data planes.
* Formulate architectural and operational defenses to counter the rapid
emergence of autonomous agentic threat vectors and LLM-assisted exploitation
tools, establishing automated vulnerability discovery, proactive mitigation
frameworks, and rapid incident response capabilities across the fleet.
* Architect robust, hardware-level defenses and isolation boundaries to
eliminate and mitigate hardware CPU vulnerabilities, speculative execution
side-channels, transient execution threats, and cross-tenant leakage
* Lead security defenses and privilege reduction across hypervisor
technologies, virtual machine monitors (VMMs), host kernels, and low-level
runtimes, implementing sandboxing and defense against virtualization escapes.
* Drive the architectural outlook for host security and isolation, advancing
host deprivileging, zero-trust host architectures, hardware-assisted
offloading of security and lifecycle functions.
Which skills does this role require?
Make your next move
Build a shortlist and prepare
Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.
- Build a focused shortlist before you applyCompare role requirements with your experience and give each application a clear reason.
- Practice explaining your experience in an interviewRehearse your answers before meeting the hiring team.
Other roles to compare
Review the responsibilities and requirements before adding an opening to your shortlist.
Staff/Principal AI Transformation Engineer
DiDi Autonomous Driving · San Jose, California, United States
Principal Engineer, Content and Generative AI Exploration, Search Platforms
Google · Mountain View, California, United States
Principal Electrical Engineer, AI Hardware
Microsoft · Redmond, Washington, United States
AI Outcome Customer Engineer, Forward Deployed Engineering
Google · Atlanta, Georgia, United States
Senior Principal Engineer, Enterprise Networking Architecture, Automation and AI
Equinix · Toronto, Ontario, Canada
VP – Distinguished Engineer of Generative AI Engineering
Slate Auto · United States
Role information can change. Confirm current details on the original application page.
