iOS Vulnerability Researcher (Security Research)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
iOS Vulnerability Researcher (iOS/ARM): Identifying vulnerabilities within Apple’s ecosystem and developing innovative exploit strategies to gain access to iPhones with an accent on bypassing hardware-backed encryption and secure boot chains. Focus on overcoming state-of-the-art exploit mitigations like PAC, KTRR, and PPL to execute native payloads.
Location: Must be based in the offices in Tel Aviv, Israel
Company
provides an AI-powered Digital Investigation Platform that enables public safety organizations and intelligence agencies to lawfully access and analyze digital evidence.
What you will do
- Research unexplored vulnerability territories within the Apple ecosystem.
- Develop unique capabilities to extract evidence from iPhones and other embedded devices.
- Analyze and bypass hardware-backed encryption (SiDP), secure crypto coprocessors (SEP), and secured boot chains (SecureROM).
- Overcome modern exploit mitigations including PAC, KTRR, and PPL.
- Execute native shell code on hardened mobile technology platforms.
- Collaborate with a high-level research team to solve complex digital intelligence challenges.
Requirements
- Proven experience in vulnerability research, specifically with iOS.
- Expertise in advanced exploitation techniques.
- Strong proficiency in ARM reverse engineering.
- Deep understanding of cryptographic primitives and their weaknesses.
- Must be able to work onsite in Tel Aviv.
Nice to have
- Experience with hardware research and board design.
Culture & Benefits
- Opportunity to work in industry-leading Security Research Labs.
- Contribution to global justice by enabling law enforcement to extract crucial evidence.
- Collaboration with a team of passionate researchers working years ahead of industry standards.
- Engagement with cutting-edge mobile technology and high-impact engineering challenges.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →