Apple

Security Platform Automation Engineer

Apple Seattle, Washington, United States

Computers and Electronics Manufacturing · 10,001+ employees

16 h ago
Principal (10+ yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will lead the software architecture and engineering of a next-generation AI-assisted security automation platform to scale security reviews across thousands of services. This involves building agentic workflows, evaluation harnesses, and integrating security standards directly into core data systems.

What they look for

Python Go Java LLM Agentic workflows Automation Data pipelines Cloud security Threat modeling Software supply chain Risk management SAST SCA SBOM API integration Backend services

Requirements

Candidates must have 8+ years of experience in production automation or backend services, including at least 1 year of experience with production-grade LLM or agent-based systems. Proficiency in Python, Go, or Java and a strong background in cloud security and software supply chain management are required.

Full description

We are the Assurance Automation & Risk Management team within Apple Services Engineering (ASE) Security org. We are responsible for securing the platforms, infrastructure, and distributed systems behind Apple’s global services, including iCloud, App Store, Apple Music, TV+, Maps, and Commerce.

Apple operates thousands of critical backend services across a rapidly expanding global footprint. We have a transformative opportunity to amplify security experts reach by building the next-generation AI-assisted Security Automation Platform. Rather than building isolated tooling, we turn expert security standards into robust, running software by combining agentic workflows, deterministic scaffolding, and rigorous evaluation gates integrated directly into Apple’s core security data systems (Security Findings, Bill of Materials, and Risk Governance).

We are hiring Tech Lead to lead the software architecture and agentic engineering of this platform. Your effort will help build solutions to a variety of outstanding security challenges in software supply chain, security posture, and risk management. Join us, and you’ll play a meaningful role in ensuring the highest standard of security for one of the most-watched companies in the world.

Description

We’re looking for an exceptional automation engineer to build the pipeline that scales security review across Apple’s 1000s+ services. You will turn security expertise into running software, designing and operating AI agentic review system, skills, tool layer, evaluation harness on top of Apple's existing security tooling, and giving reviewers a reliable, high-throughput pipeline to execute against. You’ll partner closely with the security engineers who define the review standards and the analysts who validate the output, and build automation that reduces toil.

Minimum Qualifications

1 year of building LLM- or agent-based systems that ran in production, with a measured quality bar 8+ years building and operating production automation, data pipelines, or backend services Highly proficient in at least one of Python, Go, or Java Experience integrating third-party and first-party APIs, tooling, and services into reliable end-to-end workflows and AI agent workflows Working knowledge of application and cloud security concepts (threat modeling, vulnerabilities, secure configuration) MS or BS or equivalent experience in Computer Science, Engineering, or a related field OR equivalent practical experience in Software or Security Engineering

Preferred Qualifications

Experience with Agent engineering: retrieval, grounding, citation, reasoning Experience with Agentic workflow design with bounded autonomy, building LLM- or agent-based automation and evaluating output quality (precision/recall, human-in-the-loop feedback loops), AI agent evaluation harness as CI Familiar with AWS cloud resources (S3, EC2, Lambda, Step Functions, etc.) Experience with security tooling such as SAST/SCA scanners, SBOM tooling, or vulnerability intelligence platforms Background in security review, threat modeling, or supply-chain security Experience delivering tooling used by non-engineer reviewers or contractors at scale Awareness of AI-specific threats in systems that ingest untrusted input