Offensive Security Researcher - Server Platform & Secure Computing, SEAR

Apple Inc.

Cupertino (CA)

Hybrid

USD 136,000 - 205,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Apple Inc. is seeking an Offensive Security Researcher to probe the server platform and secure computing stack.

The role focuses on end-to-end offensive research across firmware through user-space components, with emphasis on vulnerability discovery and rapid collaboration to mitigate findings. Ideal candidates bring deep familiarity with exploitation techniques, kernel/user-space interfaces, and applying AI methods to security research, in a fast-paced environment that values curiosity and

Qualifications

  • Proven track record in full-stack vulnerability research across firmware, secure boot, hardware roots of trust, kernel and user space.
  • Strong understanding of vulnerability classes and exploitation techniques including memory corruption, parsing/state-machine flaws, cryptographic flaws and authentication weaknesses.
  • Fluency in applying AI techniques and tools like LLMs and machine learning to security research.

Responsibilities

  • Conduct end-to-end offensive research against Apple server platforms and services.
  • Identify vulnerabilities and work with cross-functional teams to deploy fixes quickly.
  • Explore coprocessor firmware, bootrom, OS layers, and user-space applications for attack surface assessment.

Skills

Vulnerability research
Memory corruption
Boot/firmware analysis
Kernel analysis
AI in security
Exploitation techniques

Tools

Linux security
BMC security

Job description

Offensive Security Researcher - Server Platform & Secure Computing, SEAR

Paris, Ile-de-France, France Machine Learning and AI

Apple's Security Engineering & Architecture organization keeps the users of over 2.35 billion active devices around the world safe. That mission is at the heart of everything we do, and our team approaches it from the offensive side by finding and helping eliminate vulnerabilities in one of the most sophisticated ecosystems ever built, before adversaries can exploit them. You would be joining an extraordinary group of researchers who bring a range of backgrounds and perspectives to the work, and who are driven by curiosity, passion, and genuine engagement with what they do. If you think you can make a difference at this scale, join us in protecting all Apple users.

Description

You will join a team whose work spans vulnerability research, binary exploitation, security tooling development, fuzzing, machine learning, and much more. By harnessing state-of-the-art technologies, and developing new ones where they don't yet exist, we amplify our impact on the security of Apple products. In this role, your primary focus will be on the infrastructure attack surface of Apple platforms and services. You will conduct end-to-end offensive research against the custom server platforms behind those services, from coprocessor firmware and bootrom, through the operating system and its multiple layers of defense-in-depth and privacy protections, up to the user space applications running on top. These systems are built to stay trustworthy even against an attacker with privileged access, and represent some of the most security-critical infrastructure we operate. Knowledge of Apple operating systems such as iOS or macOS is a plus, but not required. This role is for individuals with outstanding technical skills, grit, and a genuine passion for breaking systems in order to make them stronger. You will work alongside other researchers to identify vulnerabilities and partner with cross-functional teams to get fixes deployed quickly. In-office roles in Paris, Zurich, Cupertino, and other locations. Remote considered for experienced candidates.

Minimum Qualifications
  • Proven track record in full-stack vulnerability research, from low-level platform components such as firmware, secure boot, and hardware roots of trust to kernel and user space attack surfaces.
  • Strong understanding of vulnerability classes and exploitation techniques relevant to these systems, such as memory corruption, parsing and state-machine flaws in boot and certificate handling, cryptographic-protocol flaws and authentication weaknesses, and rollback or logic attacks.
  • Fluency in applying AI techniques and tools, such as LLMs and Machine Learning, to security research.
Preferred Qualifications
  • Deep knowledge of remote and local attestation protocols, HSM and key management architecture, and platform trust boundaries.
  • Hands-on Linux security experience, from the kernel to user space, and familiarity with server platform internals such as baseboard management controllers (BMC), remote management planes, and confidential computing technologies.
  • Experience with datacenter and cloud infrastructure, including orchestration, network fabric, and provisioning systems.

At Apple, we're not all the same. And that's our greatest strength. We draw on the differences in who we are, what we've experienced, and how we think. Because to create products that serve everyone, we believe in including everyone. Therefore, we are committed to treating all applicants fairly and equally. We will work with applicants to make any reasonable accommodations.

At Apple, we believe accessibility is a fundamental human right. You will find that idea reflected in everything here - in our culture, our benefits and our digital tools. By welcoming as many perspectives as possible, we help you build a career where you feel like you belong.

Learn about accessibility in Apple's workplace

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Vulnerability Researcher
Vulnerability Researcher

Apple Inc. • Seattle (WA)

On-site
USD 172,000 - 233,000
Stock programs
Medical benefits
Tuition reimbursement
+1
Offensive Security Researcher, SEAR
Offensive Security Researcher, SEAR

Apple Inc. • Cupertino (CA), Northern (KY)

On-site
USD 185,000 - 325,000
Stock programs
relocation potential
Tuition reimbursement
Product Security Engineer, SEAR
Product Security Engineer, SEAR

Apple Inc. • Seattle (WA), Northern (KY)

On-site
USD 123,000 - 214,000
Medical benefits
Employee stock programs
Tuition reimbursement
Software Engineer, Trusted Execution, SEAR
Software Engineer, Trusted Execution, SEAR

Apple Inc. • Cupertino (CA)

On-site
USD 129,000 - 225,000
Medical coverage
Dental coverage
Retirement benefits
+4
Firmware Security Researcher, SEAR
Firmware Security Researcher, SEAR

Apple Inc. • Cupertino (CA)

On-site
USD 129,000 - 225,000
Comprehensive medical and dental
Retirement benefits
Stock program eligibility
+2
Research Scientist, Applied Machine Learning Security (Agent Systems), SEAR
Research Scientist, Applied Machine Learning Security (Agent Systems), SEAR

Apple Inc. • Cupertino (CA), Northern (KY)

On-site
USD 185,000 - 278,000
Secure Systems Engineer - Platform Architecture Security Team
Secure Systems Engineer - Platform Architecture Security Team

Apple Inc. • Beaverton (OR)

On-site
USD 150,000 - 230,000
Senior System Security Software Engineer, Platform Attestation
Senior System Security Software Engineer, Platform Attestation

Apple Inc. • Seattle (WA)

On-site
USD 175,000 - 263,000
Relocation
Stock plans
Education reimbursement
+2
Security Infrastructure Software Engineer, SEAR
Security Infrastructure Software Engineer, SEAR

Apple Inc. • Austin (TX), Northern (KY)

On-site
USD 150,000 - 190,000
Senior Security Software Engineer - Secure Transports
Senior Security Software Engineer - Secure Transports

Apple Inc. • Cupertino (CA)

On-site
USD 180,000 - 260,000