About QNX
QNX enhances the human experience and amplifies technology-driven industries, providing a trusted foundation for software-defined businesses to thrive. The business leads the way in delivering safe and secure operating systems, hypervisors, middleware, solutions, and development tools, along with support and services delivered by trusted embedded software experts. With a focus on reducing hardware dependency and increasing efficiency, QNX empowers organizations to unlock new possibilities in areas like high-performance computing at the edge, standards-based virtualization technologies, and cloud enablement.
QNX® technology has been deployed in the world’s most critical embedded systems, including more than 275 million vehicles on the road today. QNX® software is trusted across industries including automotive, medical devices, industrial controls, robotics, commercial vehicles, rail, and aerospace and defense.
- Hunt for vulnerabilities across QNX products and embedded software components before attackers find them
- Perform penetration testing and offensive security assessments against real-world embedded platforms
- Design, develop, and execute large-scale fuzzing campaigns to uncover memory corruption defects, logic flaws, and emerging vulnerability classes
- Investigate crashes and software defects to determine exploitability and security impact
- Conduct root-cause analysis and exploit development to understand and demonstrate real-world attack scenarios
- Leverage AI/ML-assisted techniques to accelerate vulnerability discovery and improve security analysis workflows
- Build and evolve automated security testing frameworks, fuzzers, scanners, and exploit validation pipelines
- Collaborate closely with engineering teams to reproduce, triage, and remediate vulnerabilities
- Contribute tools, methodologies, and research that strengthen our overall security posture
- Stay at the forefront of emerging threats and vulnerability research affecting modern embedded operating systems
- Hands-on experience in vulnerability research, penetration testing, exploit development, or offensive security
- Practical experience with fuzzing frameworks such as AFL, lib Fuzzer, or similar technologies
- Strong understanding of low-level software internals including memory management, process isolation, POSIX APIs, concurrency, and embedded systems concepts
- Familiarity with common vulnerability classes such as:
Use-after-free, Heap corruption, Buffer overflows, Race conditions, Privilege escalation, Logic vulnerabilities - Strong programming skills in C, C++, and Python
- Experience developing automation and tooling for security testing or vulnerability discovery
- A passion for investigating complex systems and finding weaknesses others overlook
- The ability to independently drive research initiatives from concept through discovery and validation
- Experience applying AI or machine learning techniques to security research or vulnerability detection
- Knowledge of automotive cybersecurity, embedded systems, or QNX-based platforms
- Familiarity with ISO/SAE 21434 or secure software development practices
- Reverse engineering experience using tools such as IDA Pro, Ghidra, Binary Ninja, or similar frameworks
- Experience working with operating systems, kernels, drivers, or low-level system software
This is an opportunity to spend your time exploring, researching, breaking, and improving the security of software that runs some of the most important systems in the world. You’ll have the freedom to:
- Pursue challenging security research questions
- Build new tools and automation frameworks
- Experiment with emerging AI-assisted security techniques
- Influence the security of products…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).