Software Engineer, External API Security

GoogleNew York, NY
$147,000 - $211,000

About The Position

The Information Security Engineering, Authorization (ISE Auth) team strives to eliminate product authorization vulnerabilities at Google, through a combination of designing and rolling out safe-by-default developer surfaces, agentic security scanning and targeted remediation projects. Our API Security pillar focuses specifically on the risk of externally exploitable authorization weaknesses in internet-facing APIs. As a Software Engineer in ISE Auth, you will protect user data and secure Google's public-facing API boundaries from authorization vulnerabilities. In this role, you will design secure-by-default frameworks, build advanced AI-assisted security scanning systems, and run central remediation campaigns like changes to eliminate risk at scale. You will access control capabilities across all Google products.

Requirements

  • Bachelor's degree or equivalent practical experience.
  • 2 years of experience with software development in one or more programming languages, or 1 year of experience with an advanced degree.
  • 2 years of experience building software for security (e.g., vulnerability analysis, identity and access management).

Nice To Haves

  • Experience with agent-based artificial intelligence systems.
  • Experience in software security domains including secure coding practices, vulnerability analysis, or security architecture.
  • Experience designing, building, or securing web APIs and microservices.
  • Experience developing software with one or more general-purpose programming language including Go, Java, or Python.
  • Experience running automated code refactoring or programmatic remediation campaigns across systems.

Responsibilities

  • Develop and improve AI-assisted API vulnerability scanning systems, framework improvements, and automated launch checkers to proactively identify authorization bypasses.
  • Drive central remediation campaigns to remediate systemic vulnerability classes without putting undue churn onto product teams.
  • Collaborate with core infrastructure and product teams to establish secure-by-default API deployment architectures and to pragmatically reduce risk.
  • Build and maintain infrastructure and automation for security policy enforcement, monitoring, and regression prevention.
  • Analyze emerging authorization bypass patterns and evaluate agent-based AI systems to proactively harden API access controls.

Benefits

  • 15% bonus target
  • equity
  • benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service