- Location
- Shanghai, Shanghai,CN, CN
- Type
- Full-time
- Department
- Engineering
- Education
- PhD
- Source
- Eightfold
Description
##
Company:
Qualcomm China
## Job Area:
Engineering Group, Engineering Group > Software Engineering
General Summary:
Participation in product security incident response, security research on Qualcomm products in detecting and mitigating security vulnerabilities, customer communications on product security related issues.
Skills/experience:
Applicants should possess at least two years of experience (work or academic) in the field of software security and, specifically, with experience of performing software security audits. Ability to work independently with minimal supervision is a must. Applicants should have expertise or experience in two or more of the following areas:
\- Binary analysis and malware/exploit reverse engineering
\- Product security incident response
\- Secure code review, analysis and vulnerability assessment
\- Security testing, e.g. fuzzing and pen-testing
\- Operating system security
\- Mobile platform security such as Android
\- Exploit mitigation techniques
\- Threat modeling
The following skills/experience will be considered a plus.
\- Experience of working with security researchers
\- Incident response in mobile industry
\- Experience of applying software static or dynamic analysis tools (such as Klocwork, Coverity, LLVM sanitizers and popular fuzzing tools) for vulnerability detection
\- Knowledge of the internals of mobile or embedded operating systems
\- Knowledge of wireless communication systems and protocols (CDMA/GSM/UMTS/LTE, WLAN, Bluetooth, NFC, etc)
\- Mobile device development experience including software, hardware and system
\- Knowledge of secure protocols/standards (such as SSL/TLS, PKI, PKCS)
Soft skills:
\- Teamwork across various teams and geolocations
\- Able to communicate in English, both verbal and written
Responsibilities:
Specific responsibilities may include binary analysis to identify vulnerabilities being used in active exploits; review of resolutions as part of the incident response; assisting customers to adopt security patches; internal vulnerability detection and risk assessment using both manual methods and automated tools; evaluating new technologies/tools to help detect, triage, and mitigate security vulnerabilities; establishing and maintaining relationships with local (China) security research community and fostering coordinated vulnerability disclosure.
Education requirements:
Bachelor degree and above; graduate degree in a security related field of Computer Science, Electrical Engineering or Mathematics is a plus.
Minimum Qualifications:
- Bachelor's degree in Engineering, Information Systems, Computer Science, or related field and 6+ years of Software Engineering or related work experience.
OR
Master's degree in Engineering, Information Systems, Computer Science, or related field and 5+ years of Software Engineering or related work experience.
OR
PhD in Engineering, Information Systems, Computer Science, or related field and 4+ years of Software Engineering or related work experience.
- 3+ years of work experience with Programming Language such as C, C++, Java, Python, etc.
Qualcomm is an equal opportunity employer. If you are an individual with a disability and need an accommodation during the application/hiring process, rest assured that Qualcomm is committed to providing an accessible process. You may e-mail [email protected] or call Qualcomm's toll-free number found here. Upon request, Qualcomm will provide reasonable accommodations to support individuals with disabilities to be able participate in the hiring process. Qualcomm is also committed to making our workplace accessible for individuals with disabilities. (Keep in mind that this email address is used to provide reasonable accommodations for individuals with disabilities. We will not respond here to requests for updates on applications or resume inquiries).
Qualcomm expects its employees to abide by all applicable policies and procedures, including but not limited to security and other requirements regarding protection of Company confidential information and other confidential and/or proprietary information, to the extent those requirements are permissible under applicable law.
To all Staffing and Recruiting Agencies: Our Careers Site is only for individuals seeking a job at Qualcomm. Staffing and recruiting agencies and individuals being represented by an agency are not authorized to use this site or to submit profiles, applications or resumes, and any such submissions will be considered unsolicited. Qualcomm does not accept unsolicited resumes or applications from agencies. Please do not forward resumes to our jobs alias, Qualcomm employees or any other company location. Qualcomm is not responsible for any fees related to unsolicited resumes/applications.
If you would like more information about this role, please contact Qualcomm Careers.