Logo
Google Inc.

Senior Penetration Tester, Kubernetes, Google Public Sector

Google Inc., Reston, Virginia, United States, 22090

Save Job

Overview

Senior Penetration Tester, Kubernetes, Google Public Sector. This role focuses on emulating real-world attack scenarios, identifying vulnerabilities in containerized and cloud-native environments, and improving overall security posture. Responsibilities

Perform black box, grey box, and white box penetration tests against Kubernetes clusters, containerized applications, and the underlying cloud infrastructure. Simulate realistic attack scenarios, target containerized and cloud environments, including initial access and lateral movement across environments. Identify and exploit vulnerabilities in containerized components, including escape techniques, privilege escalation, runtime vulnerabilities, and insecure configurations in the control plane or network policies. Automate tasks, analyze data, and develop exploits specifically for cloud-native and containerized targets. Share knowledge and findings with defensive teams to improve their detection and response capabilities within containerized and cloud environments. Apply purple team methodologies for hardening networks. Required qualifications

Bachelor’s degree or equivalent practical experience. 5 years of experience in security engineering, with a focus on container security. Experience with security assessments, design reviews, or threat modeling for containerized applications. Ability to travel up to 25% of the time to engage with customers. Active US Government Top Secret/Sensitive Compartmentalized Information (TS/SCI) security clearance. Preferred qualifications

Certifications in Certified Kubernetes Security Specialist (CKS), Offensive Security Certified Professional (OSCP), GIAC Cloud Penetration Tester (GCPN), or GIAC Web Application Tester (GWAPT). Experience with securing cloud-native CI/CD pipelines. Experience with container security tools such as Falco, Trivy, Twistlock, Kube-Hunter, Burp Suite, and Nmap. Experience in scripting languages such as Python, Go, or Bash. Understanding of the control plane (API server, etc.), worker nodes (kubelet, container runtime), pod security, networking (CNI), and IAM/RBAC mechanisms. Ability to contribute to the security community (e.g., open-source projects, public research, conference presentations) related to containerization. About the job

Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities. In this role, you will be responsible for emulating real-world attack scenarios, identifying vulnerabilities in the AI environments and cloud-native ecosystems, and helping to improve the overall security posture. You will have an understanding of containerization internals, common attack vectors, and pen-testing methodologies. Google Public Sector brings the magic of Google to the mission of government and education with solutions purpose-built for enterprises. We focus on helping United States public sector institutions accelerate their digital transformations, and we continue to grow our team to meet the complex needs of local, state and federal government and educational institutions. Base salary range for this full-time position in the US is $166,000-$244,000 plus bonus, equity, and benefits. Salary ranges are determined by role, level, and location, with individual pay influenced by location and job-related skills, experience, and training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process. Compensation details listed reflect base salary only and do not include bonus, equity, or benefits. Learn more about benefits at Google. Compensation and benefits

We offer a comprehensive compensation package with bonuses, equity, and benefits. Specifics vary by location and role. Equal employment opportunity

Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a diverse workforce and providing equal employment opportunities regardless of race, creed, color, religion, gender, sexual orientation, gender identity or expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, criminal histories (as permitted by law). See Google’s EEO Policy and related resources for more information. Google is a global company and English proficiency is a requirement for all roles unless stated otherwise in the job posting. To all recruitment agencies: Google does not accept agency resumes. Do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes.

#J-18808-Ljbffr