Vulnerability Response Engineer

London Posted 9/14/2026 Leaves the board in 7 days
ATS Keyword Match See which key terms from this posting your resume already has. Free.

You will join a team that passionately stays up to date on emerging security vulnerabilities and threats, keeps a cool head in crisis, and advocates every single day for improving the security of Apple products and services. You will need to have a good technical background, superb communication skills, and a strong interest in network, system, and web security. The role also requires a demonstrable ability to work with incomplete information and to adapt to changing priorities.
This is a globally distributed team operating in a continuous response environment. You will collaborate with engineers and around-the-clock support resources across multiple time zones, and you will be trusted to exercise independent judgment on risk, set direction on how we approach entire classes of problem, and see your findings translate into shipped change.

Minimum Qualifications
Familiarity with common security vulnerabilities and the ability to judge their severity and impact to the business, and to articulate that risk clearly to both engineers and senior stakeholders
Strong penetration testing skills, primarily focusing on web application penetration testing experience and security research, including the ability to identify logic flaws, chained vulnerabilities, and access control weaknesses that automated tooling does not surface
Excellent knowledge of large-scale security solutions and vulnerability scanning tools, both commercial and open source
Software development experience with either Python, Go, Rust, and/or Bash scripting, sufficient to build and maintain production security tooling and automation

Preferred Qualifications
Knowledge of the security research community, coordinated disclosure, and bug bounty processes is a strong plus
Experience in Information Security or a related field, with demonstrable hands-on work in vulnerability assessment, penetration testing, or security engineering.

Share your thoughts