cat ~/cv
Lukas Weichselbaum
Chronological record: roles, levels, and what shipped in each.
The narrative
version lives on the main page.
google · zürich
2023 – nowSenior Staff (L7) · Manager
AI Agent Security & Web Security
- Anticipated the security implications of LLMs touching sensitive data and privileged actions; bootstrapped Google's first AI Agent Security team, focused on securing AI agents against prompt injection, rogue actions and sensitive-data exfiltration.
- The team's work is a core part of Google's public Secure AI Framework: launched the company-wide Agent Security Policy; helps secure Gemini and Search AI Mode in practice. Team published "Google's Approach for Secure AI Agents", among the most-cited papers in agent security.
- In parallel, set the three-part Agentic Web Security strategy — using agents to change how classical security gets done: find agents (built-in validation, zero false positives), patching agents upstreamed into DeepMind's CodeMender, and safe-coding training for the underlying models.
2018 – 2023Staff → Senior Staff (L6 → L7)
Lead, Google's web security org
- Built and led the organization securing Google's flagship web apps — Gmail, Photos, Drive among them — and grew the team to ~25 engineers across Zürich, New York, Sunnyvale and Seattle.
- Drove strict CSP, Trusted Types, Fetch Metadata, COOP and CORP across hundreds of Google's most sensitive domains. Today they cover the majority of its sensitive Front End traffic.
- Bootstrapped Product Security Measurability; co-authored Security Signals (8,000+ services, ~1,000 domains, trillions of requests; used by 60+ teams); defined Long-Lived Stable Metrics for Web Security, Memory Safety and Crypto Hygiene. Synthetic-signals approach patent-pending (US 2026/0119646 A1, with Spagnuolo and Janc).
2016 – 2018Senior → Staff (L5 → L6)
Web platform security & standards
- W3C WebAppSec WG: CSP Level 3. Introduced strict-dynamic, moving CSP from domain allowlists to deployable nonces and hashes.
- Architected the strict CSP rollout across Gmail, Docs, Drive, Cloud Console, Accounts and hundreds more.
- Built the CSP violation-report telemetry pipeline (billions of reports/day) to scale and automate rollouts.
2015 – 2016SWE → Senior (L4 → L5)
Web security research
- Internet-scale CSP study: ~100B pages, 1.68M hosts, 26k unique policies → "CSP Is Dead, Long Live CSP!" (ACM CCS 2016).
- Built and open-sourced CSP Evaluator, now in Chrome DevTools and Lighthouse. 200,000+ users a year.
2013 – 2015SWE (L3 → L4)
Vendor Security
- Security audits and red teaming across Google's third-party supply chain.
- Built the vendor assessment remediation platforms and open-sourced Google's vendor assessment questionnaire: VSAQ.
2012
Software engineering intern — Google, Mountain ViewJul – Oct 2012
before google
2012
secLab, Technical University of Vienna — researchCo-built Andrubis: dynamic analysis of Android
malware at scale,
1,000,000+ apps analysed.
2009 – 2013
SEC Consult, Vienna — security consultant60+ audits and forensic engagements for national and
international clients; multi-day security trainings; trained new staff.
education
2012 – 2015
MSc Software Engineering & Internet Computing — Technical University of ViennaCompleted from
Zürich alongside
full-time work. Thesis: Andrubis — Dynamic Behavior Monitoring of Android Malware.
2009 – 2012
BSc Software & Information Engineering — Technical University of Vienna2× merit
scholarship.
2003 – 2008
HTL St. Pölten — EDP & OrganisationMatura, 1.0 grade average.
recognition & service
- 4× Senior-Vice-President-level Google Impact Awards
- Programme committees / peer review: NDSS MADWeb, USENIX WOOT (×2)
- gMentors (Alphabet-wide mentoring) · promotion & hiring committees
- Mentored several engineers to Staff and Senior Staff
- Certifications: CompTIA Security+, SCJP, CCNA, MCP, Cambridge BEC