Offensive Security Researcher - Userland & Kernel Security
Apple · Paris
Apple's Security Engineering & Architecture organization keeps the users of over 2.35 billion active devices around the world safe. That mission is at the heart of everything we do, and our team approaches it from the offensive side by finding and helping eliminate vulnerabilities in one of the most sophisticated ecosystems ever built, before adversaries can exploit them.
You would be joining an extraordinary group of researchers who bring a range of backgrounds and perspectives to the work, and who are driven by curiosity, passion, and genuine engagement with what they do. If you think you can make a difference at this scale, join us in protecting all Apple users.
You will join a team whose work spans vulnerability research, binary exploitation, security tooling development, fuzzing, machine learning, and much more. By harnessing state-of-the-art technologies, and developing new ones where they don't yet exist, we amplify our impact on the security of Apple products.
In this role, your primary focus will be on the userland software stack and the kernels of Apple platforms. You will conduct offensive security research across system services, apps, the kernel and drivers, hypervisors, or other components essential to the security of Apple users. You will work in cross-functional teams alongside other researchers and engineering teams to evaluate and strengthen every layer of our products.
This job is for individuals with outstanding technical skills, grit, and a genuine passion for breaking systems — so we can build them stronger.
If this is you, we'd love to hear from you.
In-office roles in Paris and other locations. Remote considered for experienced candidates.
Minimum Qualifications
- Proven track record in vulnerability research targeting operating systems for local privilege escalation (LPE), across both kernel and userland attack surfaces
- Strong understanding of vulnerability classes and exploitation techniques, such as memory corruption, race conditions, and use-after-free
- Fluency in applying AI techniques and tools, such as LLMs and Machine Learning, to security research.
Preferred Qualifications
- Deep knowledge of kernel internals, including virtual memory management, system call interfaces, and driver frameworks
- Understanding of state-of-the-art userland vulnerabilities and exploitation techniques
- Familiarity with recent mitigations such as PAC or MTE
- Fluency with tool development, using programming languages such as C, C++, Python, Swift, or Objective-C
- Knowledge of Apple operating systems like iOS or macOS is nice-to-have, but not required