QNX

Senior Security Researcher - Embedded Systems

QNX

Ottawa, Ontario, Canada · Full Time

Be the first to apply

Experience
Any
Salary
USD 108,750 – USD 158,750 / year
Openings
1
Posted
4 hours ago
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Company Overview

QNX is a global leader in enabling technology-enhanced industries by providing highly trusted operating systems, hypervisors, middleware, and development tools. Powering over 275 million vehicles worldwide, QNX software supports critical embedded systems within automotive, medical, industrial, robotics, rail, aerospace, and defense sectors. The company focuses on reducing hardware reliance while enhancing efficiency through innovations like edge computing, virtualization standards, and cloud integration.

Position Summary

We are seeking passionate and dedicated Senior Security Researchers to join our expanding Product Cybersecurity team. Ideal candidates enjoy dissecting software failures, identifying covert vulnerabilities, and advancing offensive security techniques. Key activities include crash analysis, custom fuzz harness development, software reverse engineering, and applying AI to discover unique attack vectors.

Key Responsibilities

  • Proactively identify vulnerabilities in QNX products and embedded components before exploitation.
  • Conduct penetration tests and offensive security evaluations on embedded platforms.
  • Create and execute extensive fuzzing campaigns targeting memory corruption, logic errors, and new vulnerability types.
  • Analyze software crashes and defects to assess exploit potential and security implications.
  • Perform root cause investigations and develop exploits to demonstrate realistic attack scenarios.
  • Utilize AI/ML technologies to expedite vulnerability identification and enhance security analysis processes.
  • Develop and maintain automated testing frameworks, fuzzers, scanners, and exploit validation pipelines.
  • Collaborate closely with engineering teams to reproduce, assess, and facilitate remediation of vulnerabilities.
  • Contribute innovative tools, methodologies, and research to fortify overall security posture.
  • Maintain awareness of emerging threats and vulnerability trends affecting modern embedded operating systems.

Candidate Requirements

  • Proven experience in vulnerability research, penetration testing, exploit creation, or other offensive security disciplines.
  • Hands-on knowledge with fuzzing tools such as AFL, libFuzzer, or equivalent frameworks.
  • Deep understanding of low-level software internals including memory handling, process isolation, POSIX APIs, concurrency, and embedded system concepts.
  • Familiarity with common vulnerability categories including use-after-free, heap corruption, buffer overflows, race conditions, privilege escalation, and logic flaws.
  • Proficiency in programming languages C, C++, and Python.
  • Experience in developing automation and tooling aimed at security testing and vulnerability discovery.
  • Strong investigative enthusiasm for complex system analysis and discovering overlooked weaknesses.
  • Capability to lead independent research projects from initial concept through validation stages.

Additional Desired Skills

  • Experience applying AI or machine learning in security research or vulnerability detection contexts.
  • Knowledge of automotive cybersecurity standards, embedded platforms, or QNX environments.
  • Familiarity with ISO/SAE 21434 or secure software development lifecycle practices.
  • Reverse engineering proficiency with tools such as IDA Pro, Ghidra, Binary Ninja, or similar.
  • Background in working with operating systems, kernels, drivers, or low-level system software components.

Why Join Us?

  • Engage in deep security research affecting critical software running global embedded systems.
  • Opportunity to pursue challenging research questions and build cutting-edge tools and automation.
  • Work with pioneering AI-assisted security techniques.
  • Influence security practices and products deployed at massive scale.
  • Collaborate with elite embedded engineers and security professionals.
  • Convert curiosity into impactful outcomes.

Work Hours and Compensation

  • Standard workweek: 40 hours.
  • Salary range: $108,750 to $158,750 (base annual compensation). Actual pay depends on qualifications, experience, and performance assessments.
  • Bonus: Eligible employees participate in a Variable Incentive Pay program rewarding company success contributions.
  • Benefits: Comprehensive coverage including medical, dental, vision, life, disability insurance, retirement plans, employee share purchase program, and paid time off, subject to eligibility.

Additional Information

This is a regular, full-time onsite position based in Ottawa, Canada, with immediate hiring intent. Despite leveraging AI in our research, we do not employ AI for recruitment screening or applicant evaluation; all assessments are conducted by our hiring team.

Level

Senior

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer