You will conduct end-to-end offensive security research on Apple's server platforms, ranging from firmware and bootrom to operating systems and user space applications. The role involves identifying vulnerabilities, developing security tooling, and partnering with cross-functional teams to deploy fixes.
Apple's Security Engineering & Architecture organization keeps the users of over 2.35 billion active devices around the world safe. That mission is at the heart of everything we do, and our team approaches it from the offensive side by finding and helping eliminate vulnerabilities in one of the most sophisticated ecosystems ever built, before adversaries can exploit them.
You would be joining an extraordinary group of researchers who bring a range of backgrounds and perspectives to the work, and who are driven by curiosity, passion, and genuine engagement with what they do. If you think you can make a difference at this scale, join us in protecting all Apple users.
Description
You will join a team whose work spans vulnerability research, binary exploitation, security tooling development, fuzzing, machine learning, and much more. By harnessing state-of-the-art technologies, and developing new ones where they don't yet exist, we amplify our impact on the security of Apple products.
In this role, your primary focus will be on the infrastructure attack surface of Apple platforms and services. You will conduct end-to-end offensive research against the custom server platforms behind those services, from coprocessor firmware and bootrom, through the operating system and its multiple layers of defense-in-depth and privacy protections, up to the user space applications running on top. These systems are built to stay trustworthy even against an attacker with privileged access, and represent some of the most security-critical infrastructure we operate. Knowledge of Apple operating systems such as iOS or macOS is a plus, but not required.
This role is for individuals with outstanding technical skills, grit, and a genuine passion for breaking systems in order to make them stronger. You will work alongside other researchers to identify vulnerabilities and partner with cross-functional teams to get fixes deployed quickly.
In-office roles in Paris, Zurich, Cupertino, and other locations. Remote considered for experienced candidates.
Minimum Qualifications
Proven track record in full-stack vulnerability research, from low-level platform components such as firmware, secure boot, and hardware roots of trust to kernel and user space attack surfaces.
Strong understanding of vulnerability classes and exploitation techniques relevant to these systems, such as memory corruption, parsing and state-machine flaws in boot and certificate handling, cryptographic-protocol flaws and authentication weaknesses, and rollback or logic attacks.
Fluency in applying AI techniques and tools, such as LLMs and Machine Learning, to security research.
Preferred Qualifications
Deep knowledge of remote and local attestation protocols, HSM and key management architecture, and platform trust boundaries.
Hands-on Linux security experience, from the kernel to user space, and familiarity with server platform internals such as baseboard management controllers (BMC), remote management planes, and confidential computing technologies.
Experience with datacenter and cloud infrastructure, including orchestration, network fabric, and provisioning systems.
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”