Application Security Engineer

Parallels Inc.
United States
about 2 months ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$120,000.0 - $130,000.0
Working hours
Regular working hours
Job source

Tech stack

Server Applications Software Applications C++ (Programming Language) Static Program Analysis Software Debugging Dynamic Program Analysis Python (Programming Language) Reverse Engineering Software Security Information Technology

Job description

Parallels is seeking a highly motivated and talented Application Security Engineer to join our team. In this role, you will make security decisions that impact millions of our customers while gaining hands-on experience in exploit development and CVE discovery. The ideal candidate will combine an attacker mindset with the humility and detail-oriented attitude required to coordinate fixes and security architecting with busy engineers. Your primary responsibility will be to coordinate with more senior members of our team to write exploits and design fixes for existing application vulnerabilities. You will also help search for new critical/high risk vulnerabilities in our codebase. In addition, you will assist in vulnerability disclosure processes and help implement repeatable secure development practices. As issues are uncovered, you will communicate with the appropriate technical and leadership teams to ensure a focus on risk mitigation - allowing for business continuity, but without negligent risk. Application security engineers are constantly assessing applications for weaknesses and finding resolutions before they can be abused., * Reproduce and triage incoming vulnerabilities from security automation/bug bounty programs, then propose granular fixes to engineers

  • Discover vulnerabilities and construct exploits for core Parallels applications such as Parallels Remote Application Server
  • Assist in the CVE disclosure process
  • Provide threat models and design reviews for teams throughout the company
  • Assist in tuning existing static analysis, dynamic analysis, and dependency management tools

Requirements

  • An attacker mindset: engineers will often want proof before fixes are implemented
  • Eagerness to learn - you are not expected to know everything coming in, but you should continuously learn new techniques on the job
  • The ability to communicate clearly, acknowledge mistakes, and disagree when necessary
  • Demonstrable passion for offensive security
  • Experience reading, writing and debugging C++ and Python code
  • Basic experience with memory exploitation techniques
  • Demonstrable experience with web exploitation techniques and tools (e.g. PortSwigger lab scoreboards)
  • Excellent written and oral communication skills

Ideal Candidate Will Have:

  • BSc/MS in computer science or a related field
  • Previous CVEs in desktop applications
  • Proficiency with reverse engineering tools
  • Significant experience in memory exploitation techniques (e.g. gaining code execution from memory vulnerabilities in modern operating systems)
  • Familiarity with cloud security best practices
  • 3+ years of industry experience
  • OSCP/OSWE/OSED/RET2 certification

Benefits & conditions

4.04.0 out of 5 stars Remote $120,000 - $130,000 a year - Full-time

About the company

Why Parallels, why now? The top creative and technical minds could sell anywhere. So why are so many choosing Parallels? Three reasons: This is the moment. It’s an exciting time at Parallels - strong leadership, a refreshed brand, and a whole new approach to how the world works. The EUC market is shifting fast, and we’re at the front of that wave. We want you riding it with us. We want you to be you. Too many companies tell you about their culture and then expect you to fit it. Ours is built from the people who work here. We want you to feel safe being who you are, taking risks, and showing us what you’ve got. It’s your world. We know you have a life. We want to be part of it - not all of it. At Parallels, we’re serious about empowering people to work when, how, and where they want. Couch? Sweatpants? Cool with us. Happy sellers mean happy customers. That’s why we hire amazing people and get out of their way. Sound good so far? Awesome. Let’s talk about the role, Parallels is a top VDI/EUC product helping businesses since 1999. Whether it’s desktop or cloud, on-prem or hybrid, Parallels delivers speed, security, and affordability for the modern work environment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · World Congress 2025

2:08 min

The vending machine trap in software debugging

Jen Callou Jen Callou · Europe 2026 Virtual

4:25 min

Evolution of deployment models from application servers

Adam Bien · World Congress 2021

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

3:55 min

Establishing blameless dialogue surrounding critical software security vulnerabilities

Chris Heilmann +2 · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all