Principal Security Engineering Program Manager - China Security & Infrastructure, Apple Services Engineering
Apple Seattle, Washington, United States
Computers and Electronics Manufacturing · 10,001+ employees
About the role
You will define and drive the overarching security and compliance strategy for Apple services operating in mainland China. This involves collaborating with engineering, legal, and government affairs teams to ensure infrastructure meets stringent regulatory and security objectives.
What they look for
Requirements
Candidates must have 10+ years of experience in program management with a focus on infrastructure security and compliance. Deep expertise in China's cybersecurity and data privacy regulatory landscape is essential for this role.
Full description
Apple Services Engineering (ASE) team is one of the most exciting examples of Apple's long-held passion for combining art and technology! We enable Apple's apps and services, and we do it on an extensive scale, to hundreds of millions of customers in over 35 languages to more than 150 countries.
The ASE Security team is seeking a highly experienced Security Engineering Program Manager to lead our China Security and Infrastructure compliance initiatives. Within ASE, you will work with and influence colleagues across Apple, interface with Chinese regulators, and advise Apple leadership to ensure our services meet stringent security and regulatory objectives in mainland China. As our work is integral through the entire software and infrastructure stack, you will have the opportunity to work with a wide variety of engineering, legal, privacy, and government affairs teams across Apple. We cultivate strong relationships, build trust, and influence without direct authority. We communicate openly and clearly, collaborate enthusiastically, and value a diverse culture of healthy debate. Do these points resonate with you? If so, we want to talk!
Description
As the Security Engineering Program Manager for China Security & Infrastructure in ASE, you are a strategic leader and functional expert in the intersection of enterprise security, cloud infrastructure, and regulatory compliance at scale. While working directly with ASE engineering teams, legal counsel, and cross-functional partners, you will define and drive the overarching security and compliance strategy for all Apple services operating in mainland China. This will include navigating complex regulatory landscapes, driving large-scale infrastructure security improvements, and representing Apple's technical security posture to Chinese regulators and internal executives. You will be responsible for identifying, planning, and delivering critical security outcomes by autonomously engaging a broad set of internal and external stakeholders, balancing rigorous compliance requirements with Apple's high standards for privacy and user experience.
Minimum Qualifications
10+ years of experience in program management, with a significant focus on infrastructure security and compliance OR a combination of 5+ years program management with an additional 5+ years in a related field such as engineering leadership, security engineering or technical architecture. Regulatory Expertise: Deep expertise in China's regulatory landscape, specifically regarding cybersecurity, data localization, and privacy laws. External Representation: Proven track record of successfully interfacing with government regulators, auditors, and legal teams on complex technical security matters. Executive Presence: Exceptional communication skills with the ability to convey complex technical and regulatory information to both technical audiences and executive leadership with clarity, confidence, and alignment. Strategic Leadership: Experience leading large-scale, highly matrixed, cross-functional programs across global time zones, driving alignment from kick-off to successful deployment. Technical Proficiency: A solid understanding of cloud-native infrastructure, distributed systems, network architecture, and enterprise security controls to credibly partner with and challenge senior engineering teams. Risk Management Skills: Advanced ability to identify, assess, and prioritize systemic security and compliance risks, and drive the execution across multiple organizations to remediate them.
Preferred Qualifications
Advanced degree in Computer Science, Information Security, Law, or a related field or equivalent professional experience Prior experience operating autonomously as an TPM or EPM in a massive-scale enterprise technology company partnering with Sr. Executives to deliver time-critical work. Experience with cloud security architectures and joint venture/partner-operated infrastructure models in China. Industry certifications in security, privacy, or compliance (e.g., CISSP, CISM, CIPP/A).