QNX Senior Security Researcher
- Ottawa, ON
- Sur place
- Publié 12 sept. 2026
- 1 poste
108 750 $–152 250 $ / année
Ouvre un site externe
- Type d’emploi
- Temps plein
- Niveau d’expérience
- Expérimenté · 5+ ans
- Postuler avant le
- 25 sept. 2026
- Langue de l’offre
- anglais
- Heures de travail
- 40 heures par semaine
Résumé du poste
The role involves hunting for vulnerabilities across QNX products and embedded software components using offensive security techniques. You will design and execute large-scale fuzzing campaigns, conduct root-cause analysis, and develop automated security testing frameworks.
Détails du poste
Worker Sub-Type: Regular Job Description: QNX enhances the human experience and amplifies technology-driven industries, providing a trusted foundation for software-defined businesses to thrive. The business leads the way in delivering safe and secure operating systems, hypervisors, middleware, solutions, and development tools, along with support and services delivered by trusted embedded software experts. With a focus on reducing hardware dependency and increasing efficiency, QNX empowers organizations to unlock new possibilities in areas like high-performance computing at the edge, standards-based virtualization technologies, and cloud enablement. QNX® technology has been deployed in the world’s most critical embedded systems, including more than 275 million vehicles on the road today. QNX® software is trusted across industries including automotive, medical devices, industrial controls, robotics, commercial vehicles, rail, and aerospace and defense. Are you the person we are looking for? We're expanding our Product Cybersecurity team and looking for passionate security researchers who love understanding how software fails, uncovering hidden vulnerabilities, and pushing offensive security techniques to the next level. If you're the type of person who can't resist digging deeper into a crash dump, writing custom fuzzing harnesses, reversing software to understand its inner workings, or using AI to uncover attack paths others miss, we'd love to talk to you. What You'll Do: Hunt for vulnerabilities across QNX products and embedded software components before attackers find them Perform penetration testing and offensive security assessments against real-world embedded platforms Design, develop, and execute large-scale fuzzing campaigns to uncover memory corruption defects, logic flaws, and emerging vulnerability classes Investigate crashes and software defects to determine exploitability and security impact Conduct root-cause analysis and exploit development to understand and demonstrate real-world attack scenarios Leverage AI/ML-assisted techniques to accelerate vulnerability discovery and improve security analysis workflows Build and evolve automated security testing frameworks, fuzzers, scanners, and exploit validation pipelines Collaborate closely with engineering teams to reproduce, triage, and remediate vulnerabilities Contribute tools, methodologies, and research that strengthen our overall security posture Stay at the forefront of emerging threats and vulnerability research affecting modern embedded operating systems What We're Looking For: Hands-on experience in vulnerability research, penetration testing, exploit development, or offensive security Practical experience with fuzzing frameworks such as AFL, libFuzzer, or similar technologies Strong understanding of low-level software internals including memory management, process isolation, POSIX APIs, concurrency, and embedded systems concepts Familiarity with common vulnerability classes such as: Use-after-free Heap corruption Buffer overflows Race conditions Privilege escalation Logic vulnerabilities Strong programming skills in C, C++, and Python Experience developing automation and tooling for security testing or vulnerability discovery A passion for investigating complex systems and finding weaknesses others overlook The ability to independently drive research initiatives from concept through discovery and validation Bonus Points If You Have: Experience applying AI or machine learning techniques to security research or vulnerability detection Knowledge of automotive cybersecurity, embedded systems, or QNX-based platforms Familiarity with ISO/SAE 21434 or secure software development practices Reverse engineering experience using tools such as IDA Pro, Ghidra, Binary Ninja, or similar frameworks Experience working with operating systems, kernels, drivers, or low-level system software Why You’ll Love This Role: This is an opportunity to spend your time exploring, researching, breaking, and improving the security of software that runs some of the most important systems in the world. You'll have the freedom to: Pursue challenging security research questions Build new tools and automation frameworks Experiment with emerging AI-assisted security techniques Influence the security of products deployed at massive scale Collaborate with world-class embedded engineers and security researchers Turn curiosity into real-world impact #LI-KH1 Scheduled Weekly Hours: 40 Compensation Hiring Base Salary Range: $108,750.00 - $152,250.00 Please be advised that the compensation hiring range indicated herein is provided solely as a good-faith estimate of expected base compensation for the position. The actual compensation offered will be determined at the time of hire and is contingent upon multiple factors, including but not limited to the candidate’s qualifications, relevant experience, demonstrated skills, and results of assessments conducted during the hiring process. Bonus: The BlackBerry Variable Incentive Pay (VIP) program is an organization-wide bonus incentive program which aims to reward full-time eligible employees for their contribution to BlackBerry’s success. VIP payments are made in addition to base salary and factor in company’s performance as a way for employees to share in BlackBerry’s achievements. Benefits: The BlackBerry Employee Benefits programs offer a wide range of benefits that support your physical, financial and personal well-being. BlackBerry remains committed to offering affordable benefits including coverage for medical, dental, vision, life, disability insurance, retirement, employee share purchase program and paid-time-off to those that meet the eligibility requirements. Disclosure of Position Status: This is an active opening. We are seeking to fill this position immediately Disclosure of Artificial Intelligence: We do not use artificial intelligence (AI) to screen, assess, or select applicants at any stage of our recruitment process. All applications are reviewed and evaluated by our hiring team.
Ce que vous ferez
The role involves hunting for vulnerabilities across QNX products and embedded software components using offensive security techniques. You will design and execute large-scale fuzzing campaigns, conduct root-cause analysis, and develop automated security testing frameworks.
Exigences
Candidates must have hands-on experience in vulnerability research, penetration testing, and exploit development. Strong programming skills in C, C++, and Python, along with a deep understanding of low-level software internals and embedded systems, are required.
Avantages
• Medical insurance • Dental insurance • Vision insurance • Life insurance • Disability insurance • Retirement program • Employee share purchase program • Paid time off
Compétences indiquées
- C++ · Souhaitée
- Python · Souhaitée
- Embedded Systems · Souhaitée
Autres compétences pertinentes
Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.
- Vulnerability research
- Penetration testing
- Exploit development
- Fuzzing
- C
- C++
- Python
- Embedded systems
- Memory management
- Reverse engineering
- Automation
- Security assessment
- POSIX APIs
- Concurrency
- AI/ML security techniques
- Process Isolation
- Influencing Skills
- Pipelines
- Influencing Without Authority
- Exploit Development
- Workflow Management
- Curiosity
- Time Off Management
- Ghidra (Reverse Engineering Software)
- Medical Devices
- Binary Ninja (Reverse Engineering Software)
- IDA Pro
- C (Programming Language)
- Research
- Application Programming Interface (API)
- Artificial Intelligence
- Penetration Testing
- Software Development
- Blackberry
- Buffer Overflow
- C++ (Programming Language)
- Cyber Security
- Operating Systems
- Programming Tools
- Memory Management
- Embedded Systems
- Middleware
- Embedded Operating Systems
- Embedded Software
- Experimentation
- Fuzz Testing
- Hypervisor
- Python (Programming Language)
- Machine Learning
- Memory Corruption
Domaines d’emploi
- Security & Safety
- Software
- Technology
- Engineering
- Science & Research
- Security Researcher
- Vulnerability Analyst / Penetration Tester
- Database and Network Professionals Not Elsewhere Classified
- Penetration Testers
- Computer Occupations, All Other
D’autres postes auxquels postuler directement
Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.
Bédard Ressources Humaines
ITAD Services Representative #1265
CommanditéEmployeur directCandidature simplifiée- Sur place
- Mississauga, ON
- Publié 16 sept. 2026
BC Public Schools
Manager, Financial Planning and Analysis
CommanditéEmployeur directCandidature simplifiée- Sur place
- Victoria, BC
- Publié 18 sept. 2026
Bédard Ressources Humaines
Responsable d’expédition
CommanditéEmployeur directCandidature simplifiée- Sur place
- Mascouche, QC
- Publié 16 sept. 2026