Senior Security Engineer Security Assurance Scaling
Seattle, OR - USA
Job Summary
In this role you will partner with infrastructure and application teams to identify areas where security standards and where security controls should be applied across the ASE organization. You will work with engineering teams throughout their development lifecycle conduct security reviews and develop threat models and using the insights from these engagements to build standard methodologies. As Apples security risk experts for these services you will help prioritize which security capabilities and controls need to be applied and partner with our security engineering team and other platform teams to get them enforced. You will help define prioritize and advocate for platform-wide security improvements raising the security bar for all engineering teams at a technical lead responsible for the security of Apples internet-facing services and backend infrastructure you will be:nnInnately curious listening for nuances and digging into details to understand systems and their weaknessesnAble to identify areas ripe for improvement and establish appropriate security goalsnExperienced and comfortable establishing relationships with teams to drive security improvementsnCurrent on new security technologies vulnerabilities and methodologiesnAble to identify opportunities for automated enforcement and partner with security and platform engineering teams to implement themnAble to use data to drive security review efficiency and prioritize high-value security team engagementnResponsible for security decisions impacting millions of users
8 or more years conducting security reviews threat modeling tracking findings and communicating risk to engineering and leadershipnHands-on experience in cloud security engineering with demonstrated expertise in securing at least one major cloud platform (AWS GCP or AliCloud) in production environmentsnExperience securing cloud-native applications and workloads including containerized environments (Kubernetes/EKS/GKE) serverless architectures (Lambda/Cloud Functions) and modern CI/CD pipelinesnExperience building evaluating or directing the use of AI/ML-based security tooling to scale secure design review capacity demonstrating the ability to recognize and act on automation opportunitiesnConversant in at least one programming language such as Python Java Go or Swift
Bachelors degree or equivalent experience preferrednExperience identifying and prioritizing security enforcement points within infrastructure-as-code (e.g. Terraform CloudFormation Pulumi) and CI/CD pipelines and partnering with platform/security engineering teams to embed controls that apply consistently across many teams rather than relying on manual one-off reviewsnFamiliarity with policy-as-code approaches (e.g. Open Policy Agent Sentinel Checkov) sufficient to define control requirements and evaluate proposed implementations for coverage and risk reduction even if not personally authoring the policy code
Required Experience:
Senior IC
About Company
Ask Siri to name the most successful company in the world and it might respond: Apple. And it's not just out of familial pride. Apple consistently ranks highly in profit, revenue, market capitalization, and consumer cachet. In 2018, the company became the first reach a trillion dollar ... View more