Senior Security Researcher – Red Team
Referral available at Apple
An employee here can refer you. The referrer stays anonymous and reaches out to you directly if interested.
Help Apple secure the world’s most advanced consumer devices, which people trust to store their personal and professional data. We believe that the best defense is a good offense, and that means finding vulnerabilities before attackers do. We're looking for talented and inspired individuals to join our team and attack Apple's products with the goal of better safeguarding our users.
We are looking for a Senior Security Researcher to join our specialized Red Team. In this role, you will focus on the complex boundary where hardware meets software. You will hunt for vulnerabilities in the microarchitecture, memory management, and execution pipelines of modern CPUs and GPUs, as well as in the low-level code which runs on it. If you enjoy bridging the gap between hardware primitives and kernel-level exploits, and have a passion for uncovering side-channels or architectural logic flaws, this is the team for you.
Minimum Qualifications
- Deep Architectural Knowledge: Strong understanding of modern CPU architectures (pipeline stages, caching mechanisms, MMU, speculative execution). Extensive familiarity with ARM v8/v9 or x86 instruction sets.
- GPU/Compute Expertise: Proven understanding of GPU architectures (execution pipelines, memory hierarchies) and how software interfaces with them (e.g., driver vulnerability research, compute batching, memory isolation).
- Low-Level Software Mastery: Proficiency in C, C++, and Assembly. Deep understanding of operating system internals, kernel architecture, and memory management.
- Proven Track Record: Demonstrable experience in discovering vulnerabilities or developing exploits at the OS/Hypervisor level, or in hardware-software interfaces (CVEs, bug bounties, conference talks, or whitepapers).
Preferred Qualifications
- Experience with hardware description languages (Verilog/VHDL) or pre-silicon security validation.
- Experience with confidential computing environments.
- Familiarity with the security implications of AI/ML hardware accelerators and complex GPU workloads (e.g., memory handling in PagedAttention or Mixture of Experts).
- Familiarity with reverse engineering tools (IDA Pro, Ghidra) and dynamic analysis/debugging tools.