Product Security Engineer, Senior Staff
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+8 more
Job description
Job function includes participation in product security incident response, security research on Qualcomm products in detecting and mitigating security vulnerabilities, customer communications on product security related issues. Specific responsibilities may include binary analysis to identify vulnerabilities being used in active exploits; review of resolutions as part of the incident response; assisting customers to adopt security patches; internal vulnerability detection and risk assessment using both manual methods and automated tools; evaluating new technologies/tools to help detect, triage, and mitigate security vulnerabilities; reaching out to security research community and fostering coordinated vulnerability disclosure.
Requirements
- Bachelor’s degree in Engineering, Computer Science, or related field and 6+ years of Security Engineering or related work experience., Master’s degree in Engineering, Computer Science, or related field and 5+ years of Security Engineering or related work experience. OR PhD in Engineering, Computer Science, or related field and 4+ years of Security Engineering or related work experience.
Applicants should possess at least five years of experience (work or academic) in the field of software security and, specifically, with experience of performing software security audits. Ability to work independently with minimal supervision is a must. Applicants should have expertise or experience in two or more of the following areas:
-
Binary analysis and malware/exploit reverse engineering using tools like Ghidra, IDA or Binary Ninja
-
Product security incident response in Mobile, IOT or automotive industry
-
Secure code review, analysis and vulnerability assessment
- Security testing, e.g. fuzzing and pen-testing
-
Operating system security
-
Mobile platform security such as Linux Android
-
Embedded security on embedded firmware
-
Automotive Security
-
Exploit mitigation techniques
- Threat modeling
The following skills/experience will be considered a plus.
-
Experience in product security incident response and working with external security researchers
-
LLVM experience
-
Experience in fuzzing (Custom fuzzers/harnesses, custom bug detection LLVM passes or runtime detection) to large code base for vulnerability detection
-
Knowledge of hypervisors, containers, and secure execution environments
-
Familiarity in the internals for Linux, Windows, Zephyr and QNX
-
Familiarity of wireless communication systems and protocols (CDMA/GSM/UMTS/LTE, WLAN, Bluetooth, NFC, etc)
Soft Skills:
-
Teamwork across various teams and geolocations
-
Able to communicate in English, both verbal and written
Benefits & conditions
The above pay scale reflects the broad, minimum to maximum, pay scale for this job code for the location for which it has been posted. Even more importantly, please note that salary is only one component of total compensation at Qualcomm. We also offer a competitive annual discretionary bonus program and opportunity for annual RSU grants (employees on sales-incentive plans are not eligible for our annual bonus). In addition, our highly competitive benefits package is designed to support your success at work, at home, and at play. Your recruiter will be happy to discuss all that Qualcomm has to offer - and you can review more details about our US benefits at this link .
About the company
Qualcomm Technologies, Inc.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Where to Find Entry-Level Software Engineering Jobs
The 12 Best Jobs for Software Engineers
Is Software Engineering Over-Saturated?
What’s the Difference between a Junior, Mid, and Senior Developer?