Vulnerability Response Engineer
London, KY - USA
Job Summary
You will join a team that passionately stays up to date on emerging security vulnerabilities and threats keeps a cool head in crisis and advocates every single day for improving the security of Apple products and services. You will need to have a good technical background superb communication skills and a strong interest in network system and web security. The role also requires a demonstrable ability to work with incomplete information and to adapt to changing is a globally distributed team operating in a continuous response environment. You will collaborate with engineers and around-the-clock support resources across multiple time zones and you will be trusted to exercise independent judgment on risk set direction on how we approach entire classes of problem and see your findings translate into shipped change.
Technically replicate reported vulnerabilities and scale variant analysis across Apples external perimeter to identify and remediate every related instance of an issuenConduct security assessments and large-scale scanning of external properties to discover vulnerabilities before they are reported or exploitednAuthor clear authoritative responses to vulnerability inquiries including direct communication with external security researchersnTriage automated alerting and emerging threats including zero-day assessment and coordinate rapid mitigation with partner teamsnBuild and improve security tooling automation and detection capabilities that increase team efficiency and coverage and work closely with project management to drive security issues from discovery through verified closurenRequirement for on-call rotation which includes weekends as part of a tiered escalation model supporting continuous coveragen
Familiarity with common security vulnerabilities and the ability to judge their severity and impact to the business and to articulate that risk clearly to both engineers and senior stakeholdersnStrong penetration testing skills primarily focusing on web application penetration testing experience and security research including the ability to identify logic flaws chained vulnerabilities and access control weaknesses that automated tooling does not surfacenExcellent knowledge of large-scale security solutions and vulnerability scanning tools both commercial and open sourcenSoftware development experience with either Python Go Rust and/or Bash scripting sufficient to build and maintain production security tooling and automationn
Knowledge of the security research community coordinated disclosure and bug bounty processes is a strong plusnExperience in Information Security or a related field with demonstrable hands-on work in vulnerability assessment penetration testing or security engineering.
Required Experience:
IC
About Company
Ask Siri to name the most successful company in the world and it might respond: Apple. And it's not just out of familial pride. Apple consistently ranks highly in profit, revenue, market capitalization, and consumer cachet. In 2018, the company became the first reach a trillion dollar ... View more