Vulnerability Response Engineer

Lex

Greater London

On-site

GBP 75,000 - 110,000

Full time

9 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Apple is seeking an exceptional Information Security Engineer to support our vulnerability response program. This hands-on role focuses on scanning, analyzing, and remediating vulnerabilities across Apple’s external perimeter, coordinating with owners and external researchers to drive remediation at scale.

You will replicate vulnerabilities, perform large-scale assessments, communicate risk clearly, and contribute to tooling and processes while participating in on-call rotation.

Qualifications

  • Familiarity with common security vulnerabilities and ability to judge risk and convey impact clearly to engineers and stakeholders.
  • Strong hands-on security testing experience, with focus on web applications and security research.
  • Experience using large-scale security solutions and vulnerability scanning tools (commercial or open-source).
  • Proficient scripting in Python, Go, Rust, or Bash to build security tooling and automation.

Responsibilities

  • Technically replicate reported vulnerabilities and scale variant analysis across the external perimeter to remediate all related instances.
  • Conduct security assessments and large-scale scanning of external properties to discover vulnerabilities.
  • Author clear, authoritative responses to vulnerability inquiries, including direct communication with external researchers.
  • Triage automated alerting and emerging threats, coordinate rapid mitigation with partner teams.
  • Build and improve security tooling, automation, and detection capabilities; work with management to drive issues from discovery to closure.
  • On-call rotation, including weekends, as part of a tiered escalation model.

Skills

Penetration testing
Vulnerability assessment
Security tooling
Scripting (Python/Go/Rust/Bash)
Communication

Education

Bachelor's degree in CS or related field

Tools

Nessus
Burp Suite
Qualys

Job description

Summary
Apple is seeking an exceptional Information Security Engineer to support our vulnerability response program. This is a technical, hands-on role in a dynamic and fast-paced environment. Apple's external perimeter spans thousands of internet-facing services relied upon by customers worldwide, and this team is responsible for continuously discovering, analyzing, and remediating vulnerabilities across that infrastructure. You will work with application and system owners to report vulnerabilities, drive remediation, determine associated risks, engage directly with external security researchers, and improve the tooling and processes that allow our response to scale.
Description
You will join a team that passionately stays up to date on emerging security vulnerabilities and threats, keeps a cool head in crisis, and advocates every single day for improving the security of Apple products and services. You will need to have a good technical background, superb communication skills, and a strong interest in network, system, and web security. The role also requires a demonstrable ability to work with incomplete information and to adapt to changing priorities.
Responsibilities
  • Technically replicate reported vulnerabilities and scale variant analysis across Apple's external perimeter to identify and remediate every related instance of an issue
  • Conduct security assessments and large-scale scanning of external properties to discover vulnerabilities before they are reported or exploited
  • Author clear, authoritative responses to vulnerability inquiries, including direct communication with external security researchers
  • Triage automated alerting and emerging threats, including zero-day assessment, and coordinate rapid mitigation with partner teams
  • Build and improve security tooling, automation, and detection capabilities that increase team efficiency and coverage, and work closely with project management to drive security issues from discovery through verified closure
  • Requirement for on-call rotation, which includes weekends, as part of a tiered escalation model supporting continuous coverage
Minimum Qualifications
  • Familiarity with common security vulnerabilities and the ability to judge their severity and impact to the business, and to articulate that risk clearly to both engineers and senior stakeholders
  • Strong penetration testing skills, primarily focusing on web application penetration testing experience and security research, including the ability to identify logic flaws, chained vulnerabilities, and access control weaknesses that automated tooling does not surface
  • Excellent knowledge of large-scale security solutions and vulnerability scanning tools, both commercial and open source
  • Software development experience with either Python, Go, Rust, and/or Bash scripting, sufficient to build and maintain production security tooling and automation
Preferred Qualifications
  • Knowledge of the security research community, coordinated disclosure, and bug bounty processes is a strong plus
  • Experience in Information Security or a related field, with demonstrable hands‑on work in vulnerability assessment, penetration testing, or security engineering.
At Apple, we’re not all the same. And that’s our greatest strength. We draw on the differences in who we are, what we’ve experienced and how we think. Because to create products that serve everyone, we believe in including everyone. Therefore, we are committed to treating all applicants fairly and equally. As a registered Disability Confident employer, we will work with applicants to make any reasonable accommodations. Apple will consider for employment all qualified applicants with criminal backgrounds in a manner consistent with applicable law. Learn more
At Apple, we believe accessibility is a fundamental human right. You’ll find that idea reflected in everything here — in our culture, our benefits and our digital tools. By welcoming as many perspectives as possible, we help you build a career where you feel like you belong.
Learn about accessibility in Apple’s workplace
Role Number: 200683092-2114
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Vulnerability Response Engineer
Vulnerability Response Engineer

Apple • Greater London

On-site
GBP 85,000 - 120,000
Vulnerability Response Engineer
Vulnerability Response Engineer

Apple Inc. • Greater London

On-site
GBP 90,000 - 150,000
Vulnerability Response Engineer: Security Automation & Remediation
Vulnerability Response Engineer: Security Automation & Remediation

Apple • Greater London

On-site
GBP 85,000 - 120,000
Security Response Engineer: Vulnerability & Remediation
Security Response Engineer: Vulnerability & Remediation

Lex • Greater London

On-site
GBP 75,000 - 110,000
Vulnerability Response Engineer — Security Automation
Vulnerability Response Engineer — Security Automation

Apple Inc. • Greater London

On-site
GBP 90,000 - 150,000
iOS Software Engineer (Security)
iOS Software Engineer (Security)

Apple Inc. • Greater London

On-site
GBP 90,000 - 130,000
Senior Software Engineer, Customer Data Protection
Senior Software Engineer, Customer Data Protection

Apple • Greater London

On-site
GBP 110,000 - 140,000
Accessibility Engineer (Web Accessibility SME)
Accessibility Engineer (Web Accessibility SME)

Apple • Greater London

On-site
GBP 70,000 - 100,000
Site Reliability Engineer - Private Cloud Compute
Site Reliability Engineer - Private Cloud Compute

Apple • Greater London

On-site
GBP 90,000 - 130,000
Senior Software Engineer, Customer Data Protection
Senior Software Engineer, Customer Data Protection

Lex • Greater London

On-site
GBP 100,000 - 150,000