Parallels
Posted 1mo ago

Application Security Engineer

Parallels
Canada
$120k-$145k/yrRemoteFull Time
Responsibilities
  • reproducing vulnerabilities
  • constructing exploits
  • coordinating fixes
Requirements
  • Offensive-minded application security engineer with 3+ years experience
  • Skilled in exploit development
  • C++ and Python debugging
  • Reverse engineering and web exploitation
  • Assists CVE disclosure and secure development
Technical tools mentioned
C++PythonPortSwiggerParallels Remote Application Server

Job description

Application Security Engineer

Parallels is seeking a highly motivated and talented Application Security Engineer to join our team. In this role, you will make security decisions that impact millions of our customers while gaining hands-on experience in exploit development and CVE discovery. The ideal candidate will combine an attacker mindset with the humility and detail-oriented attitude required to coordinate fixes and security architecting with busy engineers.

Your primary responsibility will be to coordinate with more senior members of our team to write exploits and design fixes for existing application vulnerabilities. You will also help search for new critical/high risk vulnerabilities in our codebase. In addition, you will assist in vulnerability disclosure processes and help implement repeatable secure development practices.

As issues are uncovered, you will communicate with the appropriate technical and leadership teams to ensure a focus on risk mitigation – allowing for business continuity, but without negligent risk. Application security engineers are constantly assessing applications for weaknesses and finding resolutions before they can be abused. 

Parallels: anytime, anywhere, any-device productivity.

Why Parallels, why now?

The top creative and technical minds could sell anywhere. So why are so many choosing Parallels? Three reasons:

This is the moment. It's an exciting time at Parallels — strong leadership, a refreshed brand, and a whole new approach to how the world works. The EUC market is shifting fast, and we're at the front of that wave. We want you riding it with us.

We want you to be you. Too many companies tell you about their culture and then expect you to fit it. Ours is built from the people who work here. We want you to feel safe being who you are, taking risks, and showing us what you've got.

It's your world. We know you have a life. We want to be part of it — not all of it. At Parallels, we're serious about empowering people to work when, how, and where they want. Couch? Sweatpants? Cool with us. Happy sellers mean happy customers. That's why we hire amazing people and get out of their way.

Sound good so far? Awesome. Let's talk about the role

What you'll do:

  • Reproduce and triage incoming vulnerabilities from security automation/bug bounty programs, then propose granular fixes to engineers
  • Discover vulnerabilities and construct exploits for core Parallels applications such as Parallels Remote Application Server
  • Assist in the CVE disclosure process
  • Provide threat models and design reviews for teams throughout the company
  • Assist in tuning existing static analysis, dynamic analysis, and dependency management tools


Desired Qualities:

  • An attacker mindset: engineers will often want proof before fixes are implemented
  • Eagerness to learn – you are not expected to know everything coming in, but you should continuously learn new techniques on the job
  • The ability to communicate clearly, acknowledge mistakes, and disagree when necessary
  • Demonstrable passion for offensive security
  • Experience reading, writing and debugging C++ and Python code
  • Basic experience with memory exploitation techniques
  • Demonstrable experience with web exploitation techniques and tools (e.g. PortSwigger lab scoreboards)
  • Excellent written and oral communication skills

Ideal Candidate Will Have:

  • BSc/MS in computer science or a related field
  • Previous CVEs in desktop applications
  • Proficiency with reverse engineering tools
  • Significant experience in memory exploitation techniques (e.g. gaining code execution from memory vulnerabilities in modern operating systems)
  • Familiarity with cloud security best practices
  • 3+ years of industry experience
  • OSCP/OSWE/OSED/RET2 certification

What are you waiting for? Apply now. We can't wait to meet you.

(FYI, we're lucky to get a lot of interest and we appreciate every application — please note we'll only reach out if you've been selected for an interview.)

About Parallels

Parallels is a top VDI/EUC product helping businesses since 1999. Whether it's desktop or cloud, on-prem or hybrid, Parallels delivers speed, security, and affordability for the modern work environment.

It is our policy and practice to offer equal employment opportunities to all qualified applicants and employees without regard to race, color, age, religion, national origin, sex, political affiliation, sexual orientation, marital status, disability, veteran status, genetics, or any other protected characteristic.

Parallels is committed to an inclusive, barrier-free recruitment and selection process and work environment. If you are contacted for a job opportunity, please advise us of any accommodations required. Appropriate accommodation will be provided upon request as required by law.


#LI-Remote



About Parallels

A software delivering virtualization and remote application solutions to enable productivity across devices.

Similar jobs

Application Security Engineer roles
1d
Save
Mark Applied
Hide
Staff/Lead Application Security Engineer
San Francisco or New York or Toronto
OnsiteFull Time
SnailWorks
SnailWorks: SnailWorks provides mail tracking and delivery intelligence software for marketers.
Expert web/API security, identity and access design, applied cryptography, cloud and container security; production coding experience and a record of driving security work across engineering organizations.
AI, SAST, DAST, SCA, CI/CD, RBAC, ABAC
1d
Save
Mark Applied
Hide
Senior Application Security Engineer
Ottawa, Ontario, Canada
RemoteFull Time
Barracuda
Barracuda: Sells cybersecurity software for email, network, and data protection.
5+ YOERequires 5–8+ years in product-focused application security, proficiency in at least two listed programming languages, penetration testing and code review experience, and expertise in threat modeling and risk analysis.
TypeScript, JavaScript, Python, Ruby, Java, Go, SAST, SCA, LLM
6d
Save
Mark Applied
Hide
Ingénieur(e) sécurité applicative - Cybersécurité - Toulouse
Colomiers or Toulouse or Toronto or Singapore
HybridFull Time
Sopra Steria
Sopra SteriaEuronext Paris: SOPR: Provides digital transformation consulting and information technology services.
6+ YOEEngineering or university-equivalent degree and at least 6 years in application security; experience with security projects, governance, DevSecOps tools, programming languages, security frameworks, and fluent written and spoken English.
Java, .Net, JavaScript, Angular, GitLab, Jenkins, Checkmarx, Sysdig, HashiCorp Vault, Kubernetes, OWASP, OWASP Top Ten, MITRE ATT&CK, SAMM, ASVS, NIST
1w
Save
Mark Applied
Hide
Senior Application Security Engineer
Toronto or London or New York City or Pune
OnsiteFull Time
TripleLift
TripleLift: Programmatic advertising platform for high-quality digital ad experiences.
5+ YOERequires 5+ years in application security or security engineering, secure coding, SAST/DAST/SCA, CI/CD security, penetration testing, threat modeling, AWS security, and cybersecurity frameworks.
GitHub Advanced Security, SAST, DAST, SCA, CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode, CI/CD, Python, Java, TypeScript, Go, NIST CSF, PCI, SOC2, HITRUST, ISO 27001/2, AWS, IAM, VPC, KMS, GuardDuty, CloudTrail, Claude
1w
Save
Mark Applied
Hide
Senior Application Security Engineer II
Toronto, Ontario, Canada
$180k-$220k/yr HybridFull Time
Relay
Relay: Digital banking and cash flow management for small businesses.
5+ YOERequires 5–6 years of professional security experience, production software development, application security or penetration testing expertise, OWASP Top 10 knowledge, AI tooling experience, communication, ownership, and mentoring skills.
TypeScript, Node.js, Postgres, AWS, Datadog, Burp Suite, Claude Code, Cursor, Hack The Box, Google Meet, OWASP Top 10, SBOM, SCA, Certn
2w
Save
Mark Applied
Hide
Lead Application Security Engineer
San Francisco or New York City or Austin or United States or Canada
$220k-$320k/yr RemoteFull Time
Advatix
Advatix: Provides technology-driven supply chain, fulfillment, and logistics services.
6+ YOE6+ years application security experience, CS/Math/Physics degree, deep knowledge of distributed systems, multi-cloud security, multi-tenant isolation, authorization models, and privacy-adjacent controls.
TypeScript, Go, AWS, Azure, GCP, Okta
3w
Save
Mark Applied
Hide
Staff Application Security Engineer
Ann Arbor or United States or Canada
$172k-$233k/yr RemoteFull Time
Censys
Censys: Maps the internet to discover and manage security risks.
10+ YOE10+ years in security engineering/DevSecOps/SRE; expertise securing Kubernetes, cloud (GCP), IaC, CI/CD AppSec tooling, scripting (Python/Bash), threat frameworks, and on-call participation.
Kubernetes, Google Cloud Platform (GCP), Helm, Crossplane, GitHub Actions, ArgoCD, Terraform, Python, Bash, Orca Security, Aikido Security, TensorFlow, PyTorch, Prometheus, Grafana, OpenTelemetry, MITRE ATT&CK
3w
Save
Mark Applied
Hide
Application Security Engineer - ADR
Quincy or Toronto or Austin or Atlanta
$120k-$203k/yr OnsiteFull Time
State Street
State StreetNYSE: STT: Provides investment servicing and management to institutional investors.
6+ YOEHands-on experience with application security, ADR/RASP/WAAP, SAST/DAST/SCA, cloud (Azure/AWS), DevSecOps, secure SDLC, threat detection, incident response, and relevant security certifications.
Java, .NET, Python, Node.js, Azure, AWS, SAST, DAST, SCA, API Security, Container Security, Runtime Application Self-Protection (RASP), Web Application and API Protection (WAAP), Ansible, Terraform, Kubernetes, Infrastructure as Code (IaC), Agile, DevOps