Looking for something else?
Find a vacancy that works for you. Send us your CV to receive a personalized offer.
Find me a jobChoose an option
We are seeking a Lead C++ Developer to join our team.
This position is ideal for someone who thrives on solving complex security challenges within large-scale, open-source infrastructure environments. You will operate at the crossroads of systems programming and security engineering, making direct contributions to widely adopted networking technology.
Responsibilities
- Resolve security vulnerabilities within the open-source Envoy Proxy codebase (C++) drawn from a Google-triaged Buganizer backlog
- Submit patches to Envoy's private security repository (envoy-setec) for evaluation by Envoy maintainers
- Back-port validated fixes to supported Envoy release branches
- Incorporate approved fixes into Google3 through the designated patching workflow, including Google FTE review, without relying on AI tooling within Google3
- Place all behavior-affecting fixes behind Envoy runtime flags to reduce potential risk
- Raise complex or unclear cases to Google technical leads for further direction
Requirements
- At least 5 years of relevant professional experience
- A minimum of one year of experience leading and managing teams
- Solid production-level C++ development expertise
- Experience in network programming using C++, covering sockets, TCP/UDP, TLS termination, and HTTP protocol handling such as parsing, framing, and connection lifecycle management
- Experience developing asynchronous, event-driven server architectures, including epoll/libevent-style event loops and non-blocking I/O
- Demonstrated ability to identify and resolve security vulnerabilities
- Experience leveraging LLM/AI-agent-assisted tools to generate fixes for vulnerabilities
- Experience with GitHub, including pull requests, contributing to upstream open-source projects, and conducting code reviews
- Strong written and spoken proficiency in English at a B2 level or higher
Nice to have
- Familiarity with Envoy internals or proxy/networking code, including HTTP/1.1, HTTP/2, HTTP/3, and TLS
- Background working within large monorepo codebases
