Enter a job title or keyword

Senior Security Software Engineer, Software Supply Chain Security

Apple


Job Location:

Seattle, OR - USA

Monthly Salary: Not provided by the employer
Posted: 28 August 2026 (8 hours ago)
Application Deadline: 25 November 2026
Vacancies: 1 Vacancy

Job Summary

We are the Dependency Risk u0026 Automation Team in Apple Services Engineering (ASE) Security. Were responsible for understanding what software Apple runs where it came from and how exposed it is across the internal and open-source projects behind iCloud Music Siri the App Store and the rest of Apples and vulnerability signal reach us from build systems package registries vulnerability feeds and SBOMs generated across a large heterogeneous estate of projects and languages and increasingly from dependency choices made by AI coding assistants and agents rather than the engineers who own the code. Turning that into one prioritized trustworthy picture of risk that engineering teams can act on and security leadership can rely on takes real architectural judgment not just looking for a senior engineer to take technical ownership of significant parts of this problem: shaping how software inventory and vulnerability data are modeled and correlated setting the engineering quality bar the rest of the platform is held to and mentoring engineers across the team and adjacent teams on how to reason about supply chain risk. Youll make the architectural calls that determine whether the rest of the company can trust and act on that data and youll play a meaningful role in ensuring the highest standard of security for one of the most-watched companies in the world.n

This role owns technical depth across software composition analysis vulnerability intelligence and the automation that keeps both operating reliably at Apples scale. Youll work across a diverse set of tools and codebases and youll be one of the people other engineers and adjacent security teams turn to when supply chain risk questions get hard from how we track whats in our software to how we correlate that against emerging vulnerabilities and end-of-life risk to how we make that information actionable rather than just will confront a new class of problem as AI coding assistants and agents generate a growing share of Apples code and a growing share of its dependency choices youll help define what secure software development means when dependencies increasingly get pulled in with minimal human review.n

8 years of experience in security software engineering with demonstrated end-to-end ownership of a system or platform and hands-on experience in the software supply chain security dependency management and OSS risknDeep proficiency in Go and strong proficiency in Java including both languages dependency ecosystems (Go Modules Maven/Gradle) plus solid software engineering fundamentalsnExperience with SBOM standards software composition analysis (SCA) tooling and vulnerability data sources (e.g. NVD OSV GitHub Advisories) turning raw feeds into prioritized signalnTrack record of technical leadership driving architecture decisions setting technical direction for a team or platform mentoring other engineers and communicating technical tradeoffs clearly to both engineers and security leadershipnExperience with software delivery pipelines (CI/CD build systems release engineering) and cloud/container infrastructure (Kubernetes AWS or equivalent)nPractical hands-on experience with AI coding assistants or agentic development tools and an understanding of emerging AI-specific supply chain risks

Familiarity with specific SBOM formats and tooling (CycloneDX SPDX cdxgen syft) and the Package URL (purl) standardnKnowledge of Open Container Initiative (OCI) image conceptsnExperience with SLSA (Supply-chain Levels for Software Artifacts) and build/artifact attestationsnExperience with graph-based data modeling for dependency or risk relationshipsnExperience designing or operating automated dependency curation or allow-listing systems that can keep pace with AI-accelerated developmentnFamiliarity with spec-driven development workflows and how they change the security review surface

Required Experience:

Senior IC


About Company

Company Logo

Ask Siri to name the most successful company in the world and it might respond: Apple. And it's not just out of familial pride. Apple consistently ranks highly in profit, revenue, market capitalization, and consumer cachet. In 2018, the company became the first reach a trillion dollar ... View more

View Profile View Profile