Apple conçoit des appareils électroniques, des systèmes d'exploitation et des services numériques, dont l'iPhone, le Mac et l'App Store.
Vulnerability Response Engineer
Am I a fit — voir ma compatibilitéApple recherche un ingénieur en sécurité de l’information pour renforcer son programme de réponse aux vulnérabilités sur son périmètre externe. Le poste couvre l’analyse et la remédiation des vulnérabilités, les tests d’intrusion web, la coordination avec les chercheurs en sécurité et le développement d’outils en Python, Go, Rust ou Bash. Une rotation d’astreinte, incluant certains week-ends, est prévue pour assurer une couverture continue.
Repères sur Apple
- Domaine officiel
- apple.com
- Offres ouvertes
- 61
Détails de l’offre
La description complète publiée par Apple.
Apple is seeking an exceptional Information Security Engineer to support our vulnerability response program. This is a technical, hands-on role in a dynamic and fast-paced environment. Apple's external perimeter spans thousands of internet-facing services relied upon by customers worldwide, and this team is responsible for continuously discovering, analyzing, and remediating vulnerabilities across that infrastructure.
You will work with application and system owners to report vulnerabilities, drive remediation, determine associated risks, engage directly with external security researchers, and improve the tooling and processes that allow our response to scale. You will join a team that passionately stays up to date on emerging security vulnerabilities and threats, keeps a cool head in crisis, and advocates every single day for improving the security of Apple products and services.
You will need to have a good technical background, superb communication skills, and a strong interest in network, system, and web security. The role also requires a demonstrable ability to work with incomplete information and to adapt to changing priorities. This is a globally distributed team operating in a continuous response environment. You will collaborate with engineers and around-the-clock support resources across multiple time zones, and you will be trusted to exercise independent judgment on risk, set direction on how we approach entire classes of problem, and see your findings translate into shipped change.
Technically replicate reported vulnerabilities and scale variant analysis across Apple's external perimeter to identify and remediate every related instance of an issue Conduct security assessments and large-scale scanning of external properties to discover vulnerabilities before they are reported or exploited Author clear, authoritative responses to vulnerability inquiries, including direct communication with external security researchers Triage automated alerting and emerging threats, including zero-day assessment, and coordinate rapid mitigation with partner teams
Build and improve security tooling, automation, and detection capabilities that increase team efficiency and coverage, and work closely with project management to drive security issues from discovery through verified closure Requirement for on-call rotation, which includes weekends, as part of a tiered escalation model supporting continuous coverage Familiarity with common security vulnerabilities and the ability to judge their severity and impact to the business, and to articulate that risk clearly to both engineers and senior stakeholders Strong penetration testing skills, primarily focusing
on web application penetration testing experience and security research, including the ability to identify logic flaws, chained vulnerabilities, and access control weaknesses that automated tooling does not surface Excellent knowledge of large-scale security solutions and vulnerability scanning tools, both commercial and open source Software development experience with either Python, Go, Rust, and/or Bash scripting, sufficient to build and maintain production security tooling and automation Knowledge of the security research community, coordinated disclosure, and bug bounty processes is a
strong plus Experience in Information Security or a related field, with demonstrable hands-on work in vulnerability assessment, penetration testing, or security engineering.
Prérequis
- web application penetration testing
- security research
- vulnerability assessment
- vulnerability scanning
- coordinated disclosure
- bug bounty processes