QNX

QNX Senior Security Researcher

QNX

Ottawa, Ontario, Canada · Full Time

Be the first to apply

Experience
Any
Salary
USD 108,750 – USD 158,750 / year
Openings
1
Posted
1 day ago
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About QNX and the Role

QNX plays a pivotal role in advancing technology-driven sectors by providing reliable and secure software foundations that enable software-defined businesses to excel. Their offerings include secure operating systems, hypervisors, middleware, development tools, and expert support, primarily for embedded software in industries such as automotive, medical devices, robotics, aerospace, and more. QNX technologies power over 275 million vehicles worldwide.

The Product Cybersecurity team seeks an enthusiastic security researcher passionate about probing software vulnerabilities, enhancing offensive security strategies, and utilizing advanced methods such as AI to discover potential threats. This role offers a unique opportunity to delve into complex technical challenges and strengthen security in critical embedded systems.

Key Responsibilities

  • Identify vulnerabilities within QNX products and embedded software before exploitation occurs.
  • Carry out penetration testing and offensive security assessments on practical embedded platforms.
  • Design and implement extensive fuzzing initiatives to detect varied vulnerability types including memory corruption and logic errors.
  • Analyze crashes and software defects to evaluate potential exploit risks.
  • Perform root-cause investigations and develop exploits to simulate real-world attack scenarios.
  • Utilize AI and machine learning to accelerate vulnerability discovery and enhance security analysis procedures.
  • Develop and maintain automated security testing frameworks and exploit validation tools.
  • Work collaboratively with engineering teams to reproduce, investigate, and remediate identified vulnerabilities.
  • Contribute innovations in tooling, methodology, and research to strengthen overall cybersecurity defenses.
  • Keep updated on emerging threats and vulnerability research relevant to embedded operating systems.

Candidate Profile and Requirements

  • Practical experience in vulnerability research, penetration testing, or offensive security roles.
  • Proficiency with fuzzing tools such as AFL, libFuzzer, or equivalent.
  • Comprehensive understanding of low-level software mechanics including memory management, process isolation, POSIX APIs, concurrency, and embedded systems concepts.
  • Knowledge of common vulnerability types, including use-after-free, heap corruption, buffer overflows, race conditions, privilege escalation, and logic flaws.
  • Strong programming expertise in C, C++, and Python.
  • Experience creating automation and tools to support security testing and vulnerability discovery.
  • Keen interest in analyzing intricate systems to reveal subtle weaknesses.
  • Capability to independently lead research projects from inception to validation.

Additional Bonuses

  • Experience integrating AI or machine learning techniques in security research.
  • Familiarity with automotive cybersecurity, embedded platforms, or specifically QNX-based systems.
  • Understanding of ISO/SAE 21434 standards or secure software development methodologies.
  • Reverse engineering skills using tools like IDA Pro, Ghidra, or Binary Ninja.
  • Experience with operating systems, kernels, drivers, or low-level system software.

Why This Role is Exciting

  • Engage in in-depth research and development focused on securing some of the world’s most critical software systems.
  • Enjoy flexibility to pursue challenging security questions and develop innovative tools.
  • Work with AI-assisted techniques to advance vulnerability detection.
  • Influence security in products deployed on a global scale.
  • Collaborate with top-tier embedded engineers and security researchers.
  • Transform curiosity into impactful security improvements.

Additional Information

Weekly Hours: 40 hours per week.

Salary Range: $108,750 to $158,750 annually, with the exact offer depending on qualifications, experience, and assessment results.

Bonus Program: Eligible for the BlackBerry Variable Incentive Pay (VIP) bonus, rewarding employees based on company performance.

Benefits: Comprehensive plans covering medical, dental, vision, life and disability insurance, retirement options, employee share programs, and paid time off.

Hiring Status: This is a current opening with immediate hiring intent.

Recruitment Process: No artificial intelligence is used during applicant screening or selection; all evaluations are conducted by hiring personnel.

Level

Senior

How they work

Teamwork & Collaboration Problem Solving Independence Learning Agility
🤖
Online · instant AI help
Broxer