Bb

QNX Senior Security Researcher

OttawaFull timeSenior$108,750 - $158,750 / yearPosted 21 days ago
Apply on Bb →

Sign into see who you know at Bb.

 Worker Sub-Type:Regular Job Description: QNX enhances the human experience and amplifies technology-driven industries, providing a trusted foundation for software-defined businesses to thrive. The business leads the way in delivering safe and secure operating systems, hypervisors, middleware, solutions, and development tools, along with support and services delivered by trusted embedded software experts. With a focus on reducing hardware dependency and increasing efficiency, QNX empowers organizations to unlock new possibilities in areas like high-performance computing at the edge, standards-based virtualization technologies, and cloud enablement. QNX® technology has been deployed in the world’s most critical embedded systems, including more than 275 million vehicles on the road today. QNX® software is trusted across industries including automotive, medical devices, industrial controls, robotics, commercial vehicles, rail, and aerospace and defense.Are you the person we are looking for?We're expanding our Product Cybersecurity team and looking for passionate security researchers who love understanding how software fails, uncovering hidden vulnerabilities, and pushing offensive security techniques to the next level. If you're the type of person who can't resist digging deeper into a crash dump, writing custom fuzzing harnesses, reversing software to understand its inner workings, or using AI to uncover attack paths others miss, we'd love to talk to you.What You'll Do:Hunt for vulnerabilities across QNX products and embedded software components before attackers find themPerform penetration testing and offensive security assessments against real-world embedded platformsDesign, develop, and execute large-scale fuzzing campaigns to uncover memory corruption defects, logic flaws, and emerging vulnerability classesInvestigate crashes and software defects to determine exploitability and security impactConduct root-cause analysis and exploit development to understand and demonstrate real-world attack scenariosLeverage AI/ML-assisted techniques to accelerate vulnerability discovery and improve security analysis workflowsBuild and evolve automated security testing frameworks, fuzzers, scanners, and exploit validation pipelinesCollaborate closely with engineering teams to reproduce, triage, and remediate vulnerabilitiesContribute tools, methodologies, and research that strengthen our overall security postureStay at the forefront of emerging threats and vulnerability research affecting modern embedded operating systemsWhat We're Looking For:Hands-on experience in vulnerability research, penetration testing, exploit development, or offensive securityPractical experience with fuzzing frameworks such as AFL, libFuzzer, or similar technologiesStrong understanding of low-level software internals including memory management, process isolation, POSIX APIs, concurrency, and embedded systems conceptsFamiliarity with common vulnerability classes such...

Also hiring in