Cookies & analytics consent
We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.
Read how we use data in our Privacy Policy and Terms of Service.
🤖 15+ AI Agents working for you. Find jobs, score and update resumes, cover letter, interview questions, missing keywords, and lots more.

Apple • Cork, Munster, Ireland
Role & seniority
Stack/tools
SAP ecosystem: SAP S/4HANA, ECC, BTP, Ariba, Commerce Cloud, Signavio, LeanIX; ABAP, Java, JavaScript
Web/API/mobile security, infrastructure/cloud security
Scripting/programming: Python, PowerShell, Bash, Go, Ruby, Node.js
Custom scripts, PoCs, security automation, vulnerability discovery tools
Top 3 responsibilities
Perform advanced offensive security testing across SAP/hybrid landscape (manual pen testing of ABAP/Java apps, SAP Fiori, web APIs, mobile interfaces)
Conduct vulnerability research, code reviews, develop exploit scripts/tools, and automate findings; synthesize findings into actionable reports
Communicate risk and remediation to engineering, drive secure development practices, and contribute to shift-left security and development standards
Must-have skills
Experience in offensive security, penetration testing, vulnerability research
Knowledge of web/API/infrastructure security; ability to identify vulnerabilities in complex codebases (ABAP, Java, JavaScript, Go)
Proficiency in at least one scripting/programming language (e.g., Python, PowerShell, Bash, Go, Ruby, JavaScript)
Strong analytical/problem-solving skills and ability to present technical findings clearly
Nice-to-haves
Offensive security certifications (OSCP, OSWE, OSWP, eJPT); CTF/bug bounty/public CVE experience
Cloud security knowledge (AWS/Azure/GCP, SAP BTP); familiarity with AI/ML in security
In a fast-evolving digital world, our team seeks a Security Researcher with an offensive security mindset to tackle emerging cyber threats within Apple’s critical ERP environment. You will play a pivotal role in safeguarding our dynamic, hybrid enterprise systems, which underpin Apple’s supply chain, treasury, and customer experiences. This unique opportunity focuses on shifting security left by relentlessly pursuing and identifying vulnerabilities early and often within the development lifecycle. You will apply cutting-edge offensive security techniques, code analysis, and penetration testing to generate meaningful data that drives the evolution of secure development standards. If you possess the necessary offensive security skills, an insatiable desire to find vulnerabilities in sophisticated systems, a passion for ethical hacking, and a strong curiosity for how enterprise systems function, we would love to meet you!
DESCRIPTION
Conduct advanced offensive security testing across Apple’s hybrid SAP landscape,
including: Manual penetration testing of custom ABAP & Java applications, SAP Fiori apps, web applications, APIs, and mobile interfaces. Vulnerability research and testing within SAP S/4HANA, ECC, BTP services, Ariba, Commerce Cloud, Signavio, LeanIX, and other integrated cloud-native systems. Security assessments of underlying infrastructure and cloud environments supporting SAP. Perform deep-dive source code reviews of sophisticated applications to identify security flaws and architectural weaknesses. Develop custom scripts, tools, and proof-of-concept exploits to augment penetration testing activities, automate vulnerability discovery, and demonstrate impact. Proactively identify and research emerging threats and attack vectors relevant to enterprise systems and the SAP ecosystem. Document findings in high-quality, actionable reports and presentations, clearly communicating technical vulnerabilities, their business impact, and recommended remediations to engineering teams across the organization. Collaborate closely with engineering and development teams to provide security advice, improve secure coding practices, and integrate security early into the development lifecycle (shift-left). Assemble and analyze threat & vulnerability data to highlight issues and trends, and author enhanced development standards and security requirements. Contribute to the team’s security knowledge base, sharing expertise, developing technical documentation, and shaping testing methodologies. Continuously learn and develop expertise in offensive security techniques and the intricacies of the SAP ecosystem.
MINIMUM QUALIFICATIONS
Experience in offensive security, penetration testing, vulnerability research, or a related field (internships, research projects, open-source contributions, CTF participation, or bug bounty success are highly valued). In-depth knowledge of web application security, API security, system and infrastructure security, and common attack techniques. Ability to read, understand, and find vulnerabilities in sophisticated codebases (e.g., ABAP, Java, JavaScript, Go). Proficiency in at least one scripting or programming language (e.g., Python, PowerShell, Bash, Go, Ruby, JavaScript (Node.js)) for security automation and tool development. Strong analytical, problem-solving, and critical thinking skills, with the ability to analyze complex challenges and produce creative solutions.
PREFERRED QUALIFICATIONS
Relevant offensive security certifications (e.g., OSCP, OSWE, OSWP, eJPT) are highly regarded. Experience with CTFs, hacking labs, bug bounty programs, or public security research/CVEs. Knowledge of cloud architecture and security principles (e.g., AWS, Azure, GCP, SAP BTP). Familiarity with modern cybersecurity concepts including AI/ML applications in security, cryptography, and prompt engineering for security tasks. An insatiable curiosity for how complex enterprise systems work, with a mandatory desire to learn and understand the SAP ecosystem. (No prior SAP expertise required, but a strong aptitude and willingness to dive deep into this domain is essential). Proficiency in MacOS and other Unix-based systems. Experience with or a strong interest in learning ABAP is a significant plus.