Description
This is a highly collaborative, hands-on role where you will partner with infrastructure, platform, and product security teams to build the tooling and services that other engineers across Apple depend on to develop, ship, and operate services securely at scale. You will be accountable for producing quality software that meets service-level objectives. Your everyday activities will include designing, implementing, testing, and operating security services and features, including scanning and assurance tooling, agentic and LLM-integrated components, backends and APIs, and the integrations that make security work show up in developers’ existing workflows. You will participate in code and security reviews to help your peers meet a high bar for the software they ship. You will do research, prototyping, and present ideas, designs, and results to your team, management, and internal customers. You are expected to own significant components end to end and to remain close to the code as those components evolve.
Minimum Qualifications
13+ years of hands-on software engineering experience, including production ownership of non-trivial systems Strong software engineering fundamentals with proficiency in at least two: Python, Go, Java and comfort working across additional languages as the work requires Solid working knowledge of software supply chain security concepts, including package and dependency risk, build and release integrity, artifact signing and verification, attestation infrastructure and policy-based admission of software into runtime environments Experience designing, building, and operating agentic systems and LLM-integrated applications in production including prompt engineering, orchestration, and evaluation of model outputs Familiarity with application security assurance methodologies, including static and dynamic analysis approaches and their operational trade-offs Experience designing and operating distributed backends: APIs, data pipelines, and services with meaningful uptime and performance requirements Experience building and maintaining CI/CD pipelines and integrating security controls into them Comfortable operating in Linux and macOS environments, with proficiency in a shell scripting language such as Bash Working understanding of the full software development lifecycle building, testing, deploying, and monitoring production software
Preferred Qualifications
Experience building policy admission systems that enforce security controls at deployment or runtime Experience with threat modeling, taint analysis, or other program-analysis techniques Working knowledge of common web and service-level vulnerabilities (injection, IDOR, input validation, authentication and authorization flaws) Experience evaluating and integrating new models and services to extend product capabilities Full-stack engineering experience, including building user-facing surfaces that expose complex data to internal customers Experience with containerization, container orchestration, and cloud infrastructure at scale Experience with gRPC and other high-performance service interfaces Bachelor’s degree in Computer Science or equivalent work experience in a related field
Learn more about this Employer on their Career Site
