Join Parallels to make security decisions impacting millions of customers through exploit development and CVE discovery. You'll combine an attacker mindset with collaborative skills to coordinate fixes and architect secure solutions with engineering teams.
3+ years of industry experience in application security or related field
Experience reading, writing and debugging C++ and Python code
Basic experience with memory exploitation techniques
Demonstrable experience with web exploitation techniques and tools
Excellent written and oral communication skills
BSc/MS in computer science or related field preferred
OSCP/OSWE/OSED/RET2 certification preferred
Previous CVEs in desktop applications preferred
Proficiency with reverse engineering tools preferred
Reproduce and triage incoming vulnerabilities from security automation and bug bounty programs
Propose granular fixes to engineers for validated security issues
Discover vulnerabilities and construct exploits for core Parallels applications
Assist in the CVE disclosure process
Provide threat models and design reviews for teams throughout the company
Assist in tuning static analysis, dynamic analysis, and dependency management tools
Role combines attacker mindset with humility to coordinate fixes with busy engineers
Opportunity to gain hands-on experience in exploit development and CVE discovery
Security decisions impact millions of Parallels customers
Parallels is a top VDI/EUC product helping businesses since 1999
Company offers equal employment opportunities to all qualified applicants