应用安全工程师
Application Security Engineer
应用安全工程师
Parallels 正在寻找一位积极主动且才华横溢的应用安全工程师加入我们的团队。在这个职位中,你将做出影响数百万客户的安全决策,同时获得在漏洞开发和 CVE 发现方面的实战经验。理想的候选人应具备攻击者思维,同时拥有谦逊和注重细节的态度,以便与忙碌的工程师协调修复方案和安全架构设计。
你的主要职责是与团队中更资深的成员合作,编写漏洞利用代码并为现有应用漏洞设计修复方案。你还将帮助在我们的代码库中发现新的关键/高风险漏洞。此外,你将协助进行漏洞披露流程,并帮助实施可重复的安全开发实践。
当发现问题时,你需要与相应的技术及管理层沟通,确保关注风险缓解——在保障业务连续性的同时,避免疏忽的风险。应用安全工程师持续评估应用程序的弱点,并在它们被滥用之前找到解决方案。
Parallels:随时随地、跨设备的生产力。为什么选择 Parallels,为什么现在?
顶尖的创意和技术人才可以去任何地方工作。那么为什么这么多优秀的人选择了 Parallels?三个原因:
这是关键时刻。Parallels 正处于激动人心的时刻——强有力的领导、焕新的品牌,以及全新的工作方式。EUC 市场正在快速变化,而我们正处于浪潮之巅。我们希望你与我们一同前行。
做真实的自己。太多公司告诉你他们的文化,然后期望你适应它。我们的文化由在这里工作的人们构建而成。我们希望你感到安全地做自己,敢于冒险,并向我们展示你的能力。
这是你的世界。我们知道你有生活。我们希望成为其中的一部分,而不是全部。在 Parallels,我们认真对待让人们能够按自己想要的时间、方式和地点工作。沙发?睡衣?我们完全接受。满意的销售员意味着满意的客户。这就是我们雇佣优秀人才并让他们自由发挥的原因。
听起来不错吗?太好了。让我们来谈谈这个职位
你会做什么:
- 重现并分类来自安全自动化/漏洞赏金计划的漏洞,然后向工程师提出具体的修复方案
- 发现漏洞并为核心 Parallels 应用程序(如 Parallels Remote Application Server)构造漏洞利用代码
·
查看英文原文
Application Security Engineer
Parallels is seeking a highly motivated and talented Application Security Engineer to join our team. In this role, you will make security decisions that impact millions of our customers while gaining hands-on experience in exploit development and CVE discovery. The ideal candidate will combine an attacker mindset with the humility and detail-oriented attitude required to coordinate fixes and security architecting with busy engineers.
Your primary responsibility will be to coordinate with more senior members of our team to write exploits and design fixes for existing application vulnerabilities. You will also help search for new critical/high risk vulnerabilities in our codebase. In addition, you will assist in vulnerability disclosure processes and help implement repeatable secure development practices.
As issues are uncovered, you will communicate with the appropriate technical and leadership teams to ensure a focus on risk mitigation – allowing for business continuity, but without negligent risk. Application security engineers are constantly assessing applications for weaknesses and finding resolutions before they can be abused.
Parallels: anytime, anywhere, any-device productivity.Why Parallels, why now?
The top creative and technical minds could sell anywhere. So why are so many choosing Parallels? Three reasons:
This is the moment.It's an exciting time at Parallels — strong leadership, a refreshed brand, and a whole new approach to how the world works. The EUC market is shifting fast, and we're at the front of that wave. We want you riding it with us.
We want you to be you.Too many companies tell you about their culture and then expect you to fit it. Ours is built from the people who work here. We want you to feel safe being who you are, taking risks, and showing us what you've got.
It's your world.We know you have a life. We want to be part of it — not all of it. At Parallels, we're serious about empowering people to work when, how, and where they want. Couch? Sweatpants? Cool with us. Happy sellers mean happy customers. That's why we hire amazing people and get out of their way.
Sound good so far? Awesome. Let's talk about the role
What you'll do:
- Reproduce and triage incoming vulnerabilities from security automation/bug bounty programs, then propose granular fixes to engineers
- Discover vulnerabilities and construct exploits for core Parallels applications such as Parallels Remote Application Server
- Assist in the CVE disclosure process
- Provide threat models and design reviews for teams throughout the company
- Assist in tuning existing static analysis, dynamic analysis, and dependency management tools
Desired Qualities:
- An attacker mindset: engineers will often want proof before fixes are implemented
- Eagerness to learn – you are not expected to know everything coming in, but you should continuously learn new techniques on the job
- The ability to communicate clearly, acknowledge mistakes, and disagree when necessary
- Demonstrable passion for offensive security
- Experience reading, writing and debugging C++ and Python code
- Basic experience with memory exploitation techniques
- Demonstrable experience with web exploitation techniques and tools (e.g. PortSwigger lab scoreboards)
- Excellent written and oral communication skills
Ideal Candidate Will Have:
- BSc/MS in computer science or a related field
- Previous CVEs in desktop applications
- Proficiency with reverse engineering tools
- Significant experience in memory exploitation techniques (e.g. gaining code execution from memory vulnerabilities in modern operating systems)
- Familiarity with cloud security best practices
- 3+ years of industry experience
- OSCP/OSWE/OSED/RET2 certification
What are you waiting for? Apply now. We can't wait to meet you.
(FYI, we're lucky to get a lot of interest and we appreciate every application — please note we'll only reach out if you've been selected for an interview.)
About Parallels
Parallels is a top VDI/EUC product helping businesses since 1999. Whether it's desktop or cloud, on-prem or hybrid, Parallels delivers speed, security, and affordability for the modern work environment.
It is our policy and practice to offer equal employment opportunities to all qualified applicants and employees without regard to race, color, age, religion, national origin, sex, political affiliation, sexual orientation, marital status, disability, veteran status, genetics, or any other protected characteristic.
Parallels is committed to an inclusive, barrier-free recruitment and selection process and work environment. If you are contacted for a job opportunity, please advise us of any accommodations required. Appropriate accommodation will be provided upon request as required by law.
Originally posted on Himalayas