
Remote opportunity at
HuntressPrincipal macOS Security Researcher
Huntress is hiring a remote Principal macOS Security Researcher to spearhead product research initiatives and evaluate macOS security strategies and technologies. Founded in 2015 by former…
Career Tools
About This Role
Huntress is hiring a remote Principal macOS Security Researcher to spearhead product research initiatives and evaluate macOS security strategies and technologies. Founded in 2015 by former NSA cyber operators, Huntress operates as a remote-first organization delivering enterprise-grade cybersecurity protection to small and medium-sized businesses worldwide through in-house technology backed by a 24/7 human-led security operations center. This role reports directly to the Manager of Product Research and involves investigating macOS…
Job Description
Huntress is hiring a remote Principal macOS Security Researcher to spearhead product research initiatives and evaluate macOS security strategies and technologies. Founded in 2015 by former NSA cyber operators, Huntress operates as a remote-first organization delivering enterprise-grade cybersecurity protection to small and medium-sized businesses worldwide through in-house technology backed by a 24/7 human-led security operations center.
This role reports directly to the Manager of Product Research and involves investigating macOS security threats, developing prototypes from Apple’s Endpoint Security API, and reversing macOS malware alongside Apple security frameworks such as Gatekeeper, TCC, and XProtect. The ideal professional brings deep knowledge of macOS system internals, experience with red teaming or attack emulation, and the ability to mentor teammates while guiding product direction.
Team members enjoy a fully remote work model supported by extensive health benefits, a 401(k) plan featuring a 5% employer contribution, and generous paid time off. Additional offerings include professional development stipends, digital allowances, home office setup reimbursement, and access to coaching through the BetterUp platform.
Responsibilities
- Lead product research initiatives focused on evaluating and developing macOS security product strategies and technologies.
- Identify and prototype new telemetry sources from Apple’s Endpoint Security API and other subsystems to improve hardening, prevention, and detection.
- Reproduce and analyze macOS attacks via hands-on malware detonation, vulnerability exploitation, and attacker technique execution.
- Reverse engineer Apple security frameworks and macOS malware to discover coverage gaps and guide product roadmaps.
- Prototype and test offensive methodologies against macOS endpoints, including research into EDR bypass and evasion.
- Build proof-of-concept implementations and collaborate with Detection Engineering to write and tune detectors.
- Coordinate with Engineering and Product groups to operationalize and integrate security solutions.
- Deploy ephemeral research environments and attacker infrastructure utilizing cloud, container, and VM tools.
- Monitor Apple platform release and beta cycles to evaluate their effect on telemetry, agent capabilities, and detection coverage.
- Investigate false positives and negatives to resolve gaps in macOS product coverage.
- Draft internal and external technical documentation to educate adjacent teams and customers regarding macOS security risks.
- Mentor team members on research methodologies, malware analysis, and macOS internals.
- Represent the company through public speaking engagements, blog posts, CFPs, and media interactions.
Requirements
- Deep expertise in macOS system internals, including code signing and notarization, the security model, TCC, SIP, persistence mechanisms, and the Mach-O file format.
- Hands-on experience developing system extensions and working with Apple’s Endpoint Security API.
- Extensive familiarity with macOS security threats, the current malware landscape, and common attack techniques.
- Experience with macOS fleet management tools including MDM, mobileconfig deployment, and configuration profiles.
- Background in red teaming and attack emulation to bypass EDR on macOS platforms.
- Proficiency in Swift.
- Working knowledge of Elasticsearch/Kibana, Sigma, YARA, and the MITRE ATT&CK framework.
- Proven track record of developing proof-of-concepts and steering research from initial concept to shipped product capabilities.
- Experience defining data requirements and balancing collection and storage costs against telemetry value.
Qualifications
- Familiarity with Go, Python, and/or Ruby.
- Understanding of how SMBs use IT automation tools such as RMMs and PSAs.
- Experience reverse engineering scripted payloads and Mach-O binaries using debuggers and disassembler suites like Hopper, IDA Pro, Binary Ninja, or Ghidra.
Core Skills
Benefits
- 100% remote work environment
- Paid time off covering vacation, sick time, and paid holidays
- 12 weeks of paid parental leave
- Comprehensive medical, dental, and vision insurance plans
- 401(k) with a 5% contribution regardless of employee contribution
- Life and Disability insurance plans
- Stock options for all full-time employees
- One-time $500 home office building or upgrading reimbursement
- Annual allowance for education and professional development assistance
- $75 USD per month digital reimbursement
- Access to the BetterUp platform for personal and professional growth
Frequently Asked Questions
Answers are based only on the employer’s listing; where it doesn’t say, neither do we.
Is this position remote?
Yes, this is a 100% remote position located within the United States.
What is the compensation for this role?
The base salary range is between $215,000.00 and $225,000.00, plus bonus and equity.
Who does this role report to?
The Principal macOS Security Researcher reports to the Manager of Product Research.
What programming languages are required or preferred?
Proficiency in Swift is required, while understanding of Go, Python, and/or Ruby is preferred.
Sample Interview Questions
AI-generated questions tailored to this specific role — a preview of the full practice set.