About this role
Within the Cloud AI organization, we focus on building highly differentiated, highly scalable, and easy-to-use products and services that enable our customers to transform their business with AI. Products such as Vertex AI and Gemini Enterprise comprise a portfolio that spans the needs of Developers, Data Scientists, Operation specialists in a broad range of industries. We not only provide customers with state-of-the-art models, such as Gemini, but also full Agent platforms and applications with strong security and governance.
The Principal Engineer, Cloud AI Safeguards is a senior individual contributor and the technical authority for safety and security across the Cloud AI product portfolio, with a primary focus on agentic safety. Reporting to the Senior Director of Cloud AI Safeguards Engineering, this role sets technical direction without managing people: defining architecture, raising the engineering bar, and personally designing and building defenses that meaningfully reduce risk as model capabilities, product surfaces, and adversaries evolve. Agentic systems make the safety problem substantially harder — autonomous tool use, long-horizon planning, and untrusted inputs expand the attack surface — and this role exists to get ahead of that complexity rather than react to it.
The ideal applicant looks deeply into hard problems, approaches them with curiosity and objectivity, works across teams and individuals to recommend solutions, and makes complexity legible by explaining it clearly and designing it away.
Google Cloud accelerates every organization’s ability to digitally transform its business and industry. We deliver enterprise-grade solutions that leverage Google’s cutting-edge technology, and tools that help developers build more sustainably. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.
US: $307000 - $427000 (USD) + 30% bonus target + equity + benefits
Learn more about benefits at Google (https://www.google.com/about/careers/applications/benefits/).
Minimum qualifications:
- Bachelor’s degree in Computer Science or equivalent practical experience.
- 15 years of professional experience in engineering leadership or related technical roles.
- Experience in AI and machine learning, including building and deploying classifiers and ML systems in production.
Preferred qualifications:
- Experience with command of threat modeling, particularly for complex, evolving, and adversarial systems.
- Experience securing agentic or autonomous AI systems (tool use, planning, multi-agent).
- Experience with agent platform technologies such as Vertex AI or Gemini Enterprise.
- Demonstrated ability to make risk-based trade-offs and to reduce complexity in hard problem spaces.
- Proven track record of building defenses that have meaningfully and measurably reduced risk.
- Depth in adversarial ML, red-teaming, or abuse/fraud detection, and a strong track record of influencing without authority and working effectively across teams.
- Design, prototype, and ship safety for AI driven threats across CBRN, Cyber, Agentic, Fraud risks with classifiers, runtime policy enforcement, and ML systems. Own the technical vision and reference architecture for safeguarding agentic systems across tool use, planning, memory, and multi-agent interactions, etc.
- Lead threat modeling for increasingly complex attack surfaces, anticipating adversary behavior and translating it into concrete engineering requirements and defenses.
- Shape the shared safety and security infrastructure that AI workloads depend on, ensuring defenses are reusable across products.
- Work objectively across teams and team members to diagnose problems, recommend solutions, align on standards, and raise the engineering bar through design reviews, mentorship, etc.
- Build data analysis, detection, and response capabilities needed to observe safety-relevant behavior at scale, measure efficacy, and close the loop quickly when threats emerge.