Application Security Engineer
Job Description
Responsibilities
- Reproduce and triage vulnerabilities reported by security automation and bug bounty programs, then propose precise fixes to engineering teams
- Identify vulnerabilities and craft exploits for core Parallels applications, including Parallels Remote Application Server
- Support the CVE disclosure process
- Provide threat models and perform design reviews for teams across the company
- Assist in tuning existing static analysis, dynamic analysis, and dependency management tools
Requirements
- Strong offensive security mindset with a preference for proof-based validation before fixes
- Commitment to ongoing learning; not required to know everything upfront, but must continually acquire new techniques on the job
- Clear communication, accountability, and the ability to disagree constructively when necessary
- Demonstrated passion for offensive security
- Experience reading, writing, and debugging C++ and Python code
- Foundational experience with memory exploitation techniques
- Proven experience with web exploitation techniques and tools, including PortSwigger lab scoreboards
- Excellent written and verbal communication skills
- BSc or MSc in computer science or a related field
- Track record of CVEs in desktop applications
- Proficiency with reverse engineering tools
- Extensive experience in memory exploitation techniques, including achieving code execution from memory vulnerabilities in modern operating systems
- Familiarity with cloud security best practices
- Three or more years of professional industry experience
- Certifications such as OSCP, OSWE, OSED, or RET2
Technologies
- C++
- Python
- PortSwigger lab scoreboards
Location: Remote
Salary: USD 120,000 - 130,000 per year
About Parallels
Parallels offers VDI and EUC solutions that support desktop and cloud deployments, delivering speed, security, and affordability for modern work environments across on-premises and hybrid setups since 1999.
Parallels is an equal opportunity employer, providing opportunities to all qualified applicants without regard to race, color, age, religion, national origin, sex, political affiliation, sexual orientation, marital status, disability, veteran status, genetics, or any other protected characteristic.
The company is committed to an inclusive, barrier-free recruitment and work environment. If accommodations are required during the hiring process, please request them; appropriate accommodations will be provided as required by law.