Offensive Security Researcher - Server Platform & Secure Computing, SEAR

Apple · Paris

Spotted 2h ago

What you'll need to apply

What this employer's standard application typically asks

NameEmailPhoneLocationRésuméWork authorization answer

Company-specific questions

  • Have you previously worked at Apple?
Job description

About this role

Employer-provided description, formatted for easier reading.

Apple's Security Engineering & Architecture organization keeps the users of over 2. 35 billion active devices around the world safe. That mission is at the heart of everything we do, and our team approaches it from the offensive side by finding and helping eliminate vulnerabilities in one of the most sophisticated ecosystems ever built, before adversaries can exploit them.

You would be joining an extraordinary group of researchers who bring a range of backgrounds and perspectives to the work, and who are driven by curiosity, passion, and genuine engagement with what they do. If you think you can make a difference at this scale, join us in protecting all Apple users.

You will join a team whose work spans vulnerability research, binary exploitation, security tooling development, fuzzing, machine learning, and much more. By harnessing state-of-the-art technologies, and developing new ones where they don't yet exist, we amplify our impact on the security of Apple products.

In this role, your primary focus will be on the infrastructure attack surface of Apple platforms and services. You will conduct end-to-end offensive research against the custom server platforms behind those services, from coprocessor firmware and bootrom, through the operating system and its multiple layers of defense-in-depth and privacy protections, up to the user space applications running on top.

These systems are built to stay trustworthy even against an attacker with privileged access, and represent some of the most security-critical infrastructure we operate. Knowledge of Apple operating systems such as iOS or macOS is a plus, but not required.

This role is for individuals with outstanding technical skills, grit, and a genuine passion for breaking systems in order to make them stronger. You will work alongside other researchers to identify vulnerabilities and partner with cross-functional teams to get fixes deployed quickly.

In-office roles in Paris, Zurich, Cupertino, and other locations. Remote considered for experienced candidates.

Proven track record in full-stack vulnerability research, from low-level platform components such as firmware, secure boot, and hardware roots of trust to kernel and user space attack surfaces.

Strong understanding of vulnerability classes and exploitation techniques relevant to these systems, such as memory corruption, parsing and state-machine flaws in boot and certificate handling, cryptographic-protocol flaws and authentication weaknesses, and rollback or logic attacks. Fluency in applying AI techniques and tools, such as LLMs and Machine Learning, to security research.

Deep knowledge of remote and local attestation protocols, HSM and key management architecture, and platform trust boundaries. Hands-on Linux security experience, from the kernel to user space, and familiarity with server platform internals such as baseboard management controllers (BMC), remote management planes, and confidential computing technologies.

Experience with datacenter and cloud infrastructure, including orchestration, network fabric, and provisioning systems.

Interested in this role?Continue on Apple's careers page.
Apply on Apple