About the role
What will you do at Apple?
We are the Dependency Risk & Automation Team in Apple Services Engineering (ASE)
Security. We're responsible for understanding what software Apple runs, where it
came from, and how exposed it is, across the internal and open-source projects
behind iCloud, Music, Siri, the App Store, and the rest of Apple's services.
Composition and vulnerability signal reach us from build systems, package
registries, vulnerability feeds, and SBOMs generated across a large,
heterogeneous estate of projects and languages, and increasingly from dependency
choices made by AI coding assistants and agents rather than the engineers who
own the code. Turning that into one prioritized, trustworthy picture of risk
that engineering teams can act on and security leadership can rely on takes real
architectural judgment, not just tooling. We're looking for a senior engineer to
take technical ownership of significant parts of this problem: shaping how
software inventory and vulnerability data are modeled and correlated, setting
the engineering quality bar the rest of the platform is held to, and mentoring
engineers across the team and adjacent teams on how to reason about supply chain
risk. You'll make the architectural calls that determine whether the rest of the
company can trust and act on that data, and you'll play a meaningful role in
ensuring the highest standard of security for one of the most-watched companies
in the world.
DESCRIPTION
This role owns technical depth across software composition analysis,
vulnerability intelligence, and the automation that keeps both operating
reliably at Apple's scale. You'll work across a diverse set of tools and
codebases, and you'll be one of the people other engineers and adjacent security
teams turn to when supply chain risk questions get hard, from how we track
what's in our software, to how we correlate that against emerging
vulnerabilities and end-of-life risk, to how we make that information actionable
rather than just available. You will confront a new class of problem, as AI
coding assistants and agents generate a growing share of Apple's code and a
growing share of its dependency choices you'll help define what secure software
development means when dependencies increasingly get pulled in with minimal
human review.
MINIMUM QUALIFICATIONS
8+ years of experience in security software engineering, with demonstrated
end-to-end ownership of a system or platform, and hands-on experience in the
software supply chain security, dependency management and OSS risk Deep
proficiency in Go and strong proficiency in Java, including both languages'
dependency ecosystems (Go Modules, Maven/Gradle), plus solid software
engineering fundamentals Experience with SBOM standards, software composition
analysis (SCA) tooling and vulnerability data sources (e.g., NVD, OSV, GitHub
Advisories), turning raw feeds into prioritized signal Track record of technical
leadership — driving architecture decisions, setting technical direction for a
team or platform, mentoring other engineers, and communicating technical
tradeoffs clearly to both engineers and security leadership Experience with
software delivery pipelines (CI/CD, build systems, release engineering) and
cloud/container infrastructure (Kubernetes, AWS or equivalent) Practical,
hands-on experience with AI coding assistants or agentic development tools, and
an understanding of emerging AI-specific supply chain risks
PREFERRED QUALIFICATIONS
Familiarity with specific SBOM formats and tooling (CycloneDX, SPDX, cdxgen,
syft) and the Package URL (purl) standard Knowledge of Open Container Initiative
(OCI) image concepts Experience with SLSA (Supply-chain Levels for Software
Artifacts) and build/artifact attestations Experience with graph-based data
modeling for dependency or risk relationships Experience designing or operating
automated dependency curation or allow-listing systems that can keep pace with
AI-accelerated development Familiarity with spec-driven development workflows
and how they change the security review surface
Which skills does this role require?
Make your next move
Build a shortlist and prepare
Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.
- Build a focused shortlist before you applyCompare role requirements with your experience and give each application a clear reason.
- Practice explaining your experience in an interviewRehearse your answers before meeting the hiring team.
Other roles to compare
Review the responsibilities and requirements before adding an opening to your shortlist.
AI Outcome Customer Engineer, Forward Deployed Engineering
Google · Atlanta, Georgia, United States
AI Evaluations Engineer, US Decision Intelligence
Apple · Cupertino, California, United States
Research Engineer, Responsible Frontier AI Research, DeepMind
Google · New York, New York, United States
AI Risk Engineer
Bright Vision Technologies · Columbus, Ohio, United States
Analytics Sr Software Engineer (US Federal)
Workday · Reston, Virginia, United States
AI Solutions Engineer
Superior Essex · Sandy Springs, Georgia, United States
Role information can change. Confirm current details on the original application page.
