Senior Security Engineer - Red Team
Apple Seattle, Washington, United States
Computers and Electronics Manufacturing · 10,001+ employees
About the role
You will lead deep security reviews of critical services and infrastructure to identify complex risks and improvement opportunities. You will collaborate with engineering teams to validate security controls, design detection mechanisms, and develop repeatable testing frameworks.
What they look for
Requirements
Candidates must have at least 4 years of experience in information security or software engineering, including 2 years conducting security reviews and manual source code analysis. A bachelor's degree in a related field is preferred, along with extensive experience in cloud and application security.
Full description
We are the Apple Services Engineering (ASE) Security Red Team. We focus on deep technical security review work of critical ASE services and infrastructure. These security reviews will be scoped and focused on review depth and quality. We are growing our team and looking an Security Engineer to lead deep reviews that identify meaningful security improvement opportunities. In this role, you will work closely with the security engineering, InfoSec, privacy, SRE, detection, and design review teams to keep Apple's services secure for our users. You will identify security weaknesses, validate and design detection mechanisms, and provide actionable recommendations to enhance our security posture. You will go beyond simple to find risks and identify obscure and complex risks within complex services. You will collaborate with various architecture and engineering teams to continuously validate and improve our security controls and detection capabilities, with a strong focus on developing repeatable testing frameworks and metrics-driven security improvements. If you love diving into complex and important systems, and driving the security of that system over time, we want to talk to you!
Description
In this role, you will scope and lead focused security reviews on critical internet scale applications and supporting infrastructure. You will learn the services architecture and risk profile to build a scope that enables a meaningful security review.
Minimum Qualifications
4+ years in an information security field or software engineering; 2 or more of those years conducting security reviews 2+ years of manually reviewing source code to assist in finding vulnerabilities Ability to adapt quickly to prioritization shifts and investigate unfamiliar technologies Extensive infrastructure, cloud, and application security experience Experience communicating risk to engineering and leadership teams Ability to reason about security of a large and complex application or infrastructure Experience going deep on complex systems for extended engagements
Preferred Qualifications
8+ years in an information security field; 4 or more of those years conducting security reviews Bachelors degree in Computer Science / Engineering or a related, with emphasis in security related fields (or equivalent experience) Experience constructing threat scenario narratives and building exploit chains Ability to reason about and influence software architecture for security Community contributions like public CVEs, bug bounty recognition, open source tools, blogs, talks etc.
Similar roles
-
IT & Cybersecurity Manager
Jusczak Trucking LLC Forest Lake, Minnesota, United States
-
Senior Cloud Security Engineer
Zions Bancorporation Midvale, Utah, United States
-
Lead Cyber Security Engineer
Capital Bank Rockville, Maryland, United States · $115K–$125K/yr
-
Cyber Security Engineer I
TAMKO Coppell, Texas, United States
-
Cybersecurity Officer (Remote)
CloseKnit MSO Rockville, Maryland, United States · $175K–$205K/yr
-
Engineering, Cybersecurity, Application Security Engineer, Vice President
TPG Careers Page Fort Worth, Texas, United States