Senior Software Engineer - Security
We are the software supply chain security team, part of Apple Services Engineering (ASE) Security org. We work on the software behind iCloud, App Store, Apple Music, TV+, and Commerce. Our job is to make software Apple can trust: know what goes into it, catch the security problems in it before they ship, and keep unsafe code out of production. Engineering teams across Apple Services build against the tooling we provide.
The near-term work is assurance signal. Scanners, design reviews, and code analysis produce findings faster than anyone can judge them, so engineers hand-triage noise and stop trusting the output. That triage step sets the ceiling on how much assurance we can run and on how much of it our partner teams act on. We are building automated security assurance that produces findings engineers trust: agentic and LLM-driven analysis, wrapped in the evaluation harnesses and guardrails that keep non-deterministic components honest as inputs, targets, and models change.
The longer-term agenda is the supply chain itself. Today nobody can answer questions about a running service without a person spending a day chasing registries, build systems, and scanners: what went into this build, where each dependency came from, who owns fixing it when it goes bad. We are building the paved path that answers those questions by construction, through dependency risk management, build and release integrity, artifact signing and verification, and policy-based admission of software into runtime.
We are looking for a Senior Software Engineer to design, write, and ship production software. Success here takes strong distributed systems engineering, real judgment about where agentic components belong and where they don’t, and the ability to make security controls show up in other teams’ existing workflows without becoming a tax.