info_outline
X In accordance with Washington state law, we are highlighting our comprehensive benefits package, which is available to all eligible US based employees. Benefits for this role include:
- Health, dental, vision, life, disability insurance
- Retirement Benefits: 401(k) with company match
- Paid Time Off: 20 days of vacation per year, accruing at a rate of 6.15 hours per pay period for the first five years of employment
- Sick Time: 40 hours/year (increased to 69 hours/year for Seattle) including 5 discretionary sick days per instance
- Maternity Leave (Short-Term Disability Baby Bonding): 28-30 weeks
- Baby Bonding Leave: 18 weeks
- Holidays: 13 paid days per year
Note: By applying to this position you will have an opportunity to share your preferred working location from the following:
Kirkland, WA, USA; Sunnyvale, CA, USA.
Minimum qualifications: - Bachelor's degree or equivalent practical experience.
- 8 years of experience programming in C .
- 5 years of experience with design and architecture; and testing/launching software products.
Preferred qualifications: - Experience setting multi-team technical strategy or acting as a Lead Architect/Tech Lead for mission-critical, and large-scale systems.
- Deep technical expertise in Public Key Infrastructure (PKI), applied cryptography (X.509, cryptographic key lifecycles, asymmetric/symmetric algorithms), and identity/token architectures.
- Demonstrated ability to navigate cross-functional organizational dynamics, build consensus among senior leadership stakeholders, and lead geographically distributed engineering teams.
About the jobProd Public Key Infrastructure (PKI) builds and operates the foundational cryptographic and identity infrastructure that secures Google's planetary-scale production environments and sovereign cloud deployments. Every service, machine, workload, and administrative action across Google relies on our platform for cryptographically verified identity, scoped authorization, and high-assurance trust boundaries.
Our organization is structured around three sub-teams to enable our core user journeys:
- Identity: Empowers production entities to prove identity and associated security attributes, owning root-of-trust management, full-lifecycle credential issuance, and revocation infrastructure.
- Platform: Enables Google engineering teams and PKI operators to deploy and operate automated, self-service PKI stacks with minimal operational toil and sustaining cost.
- Delegation: Enables authenticated principals, distributed workloads, and autonomous AI agents to delegate scoped subsets of permissions dynamically, safely, and transparently.
Google Cloud accelerates every organization's ability to digitally transform its business and industry. We deliver enterprise-grade solutions that leverage Google's cutting-edge technology, and tools that help developers build more sustainably. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.
US: $262000 - $364000 (USD) 25% bonus target equity benefits
Learn more about benefits at Google .
Responsibilities - Define the overarching multi-year architectural blueprint across the domains to prevent technical fragmentation. Lead cross-domain design reviews, establish unified cryptographic and API design standards, and resolve complex architectural trade-offs across sub-teams.
- Author and drive the 3-5 year technical goal for production identity, anticipating industry shifts in post-quantum readiness, confidential computing, and agentic workflows. Translate enterprise-wide security mandates including Regional Security Isolation (RSI) and Cryptographic Hygiene programs into actionable, sequenced engineering roadmaps.
- Align stakeholders on priorities, shared dependencies, and architectural best practices. Guide specialized working groups to drive cross-cutting technical consistency across sub-teams.
- Partner closely with Security Leadership, Cloud Foundations, Infrasec SRE, CorpEng, and Hardware Security teams to align security boundaries and platform roadmaps.
- Lead operational excellence, multi-region fault tolerance, automated key rotations, and disaster recovery readiness across all production services.