← Back to all jobs

Group Product Manager, AI Agent Security and Authorization

Google · United States · Posted 2026-08-13

Apply on the company site →

Job description

Define and progress the strategic plans for Google's agent authorization model, balancing high operational velocity with zero-trust security controls across all development and production environments. Influence holistic and long-term strategy for agent access control, partnering with identity platform PMs and token specification owners to define how Google restricts agent access using cryptographic tokens and scopes across all services. Solve challenges in authorization across service meshes, designing original approaches for routing and inspecting agent-initiated credentials. Serve as the domain expert for agentic access security, advising executive directors and Vice President's across AI Research, Cloud, Productivity, and Core Infrastructure on secure agent architectures. Drive innovation in security models by replacing manual compliance exceptions with policy frameworks and standardized agent integration software development kits (SDKs), empowering product teams to innovate at AI speed while maintaining company-level security commitments. Minimum Qualifications: Bachelor's degree or equivalent practical experience. 10 years of product management experience in security, cloud infrastructure, identity and access management (IAM), enterprise platforms, or AI/ML systems. 5 years of experience taking technical products from conception to launch (e.g., ideation to execution, end-to-end, 0 to 1, etc.). Experience in enterprise security architecture, including zero-trust models, OAuth, service mesh authorization (RPC/HTTP), and capability-based tokens (e.g., Macaroons). Experience designing secure AI agent systems, including tool-calling, prompt safety, and exfiltration prevention. Experience leading distributed engineering organizations. Preferred Qualifications: Master's degree in a technology or business related field. Experience with large-scale enterprise security and authorization infrastructure (e.g., zero-trust proxies, identity-aware access controls, distributed databases, RPC frameworks, and sandboxed developer/agent runtimes). Experience building or securing LLM-driven agents, verifiable cryptographic credentials, or automated vulnerability detection platforms. Experience designing intuitive, low-toil developer tools and SDKs that make agent security the default, easiest path for engineers. Proficiency in SQL and distributed databases with the ability to analyze massive-scale remote procedure call (RPC) log streams to establish quantitative risk metrics and clear product requirements.