Build Security Engineer
Austin, TX - USA
Job Summary
The Build Security Engineer is a key contributor to the security of Apples software supply chain. This role requires deep technical security expertise applied across threat modeling offensive security assessments and the development of security controls all in close collaboration with the engineering teams who build and maintain Apples most critical software infrastructure. The role also involves creating documentation mentoring teammates and staying current with the evolving threat landscape to proactively address risk.
Conducts threat modeling and security assessments of critical build infrastructure regularly updating models to reflect evolving threats and changes in the with engineering teams to ensure adherence to defined security standards and requirements providing guidance on the implementation of security implements and maintains technical solutions to mitigate identified security risks within the software build and maintains test cases to validate the effectiveness and resilience of security penetration tests and red team exercises with a focus on the software build path and related critical vulnerabilities in critical software components used across the environment and recommends proactive and maintains documentation outlining security guidelines and best practices for engineering teams.
3 years of experience in cybersecurity with hands-on experience in threat modeling security assessments or penetration testingnExperience in a software engineering or security operations rolenExperience with scripting or programming languages such as Python or BashnExperience working cross-functionally with engineering teams on security requirements or controls
Experience conducting penetration testing or red team exercises particularly targeting build pipelines or software supply chain componentsnExperience leveraging LLMs safely to accelerate various security workflowsnExperience with container orchestration platforms such as KubernetesnProficiency in additional programming languages such as Go (Golang) or PerlnFamiliarity with cybersecurity frameworks and standards (e.g. NIST CIS SLSA)nExperience mentoring engineers or junior security team members on security concepts and best practicesnTrack record of identifying and driving remediation of vulnerabilities in complex software environmentsnStrong written and verbal communication skills with the ability to present technical findings to varied audiencesnSecurity certifications such as OSCP or CISSP
Required Experience:
IC
About Company
Ask Siri to name the most successful company in the world and it might respond: Apple. And it's not just out of familial pride. Apple consistently ranks highly in profit, revenue, market capitalization, and consumer cachet. In 2018, the company became the first reach a trillion dollar ... View more