Apple

Platform Security Engineer

Apple London, England, United Kingdom

Computers and Electronics Manufacturing · 10,001+ employees

4 d ago
security Senior (5-10 yrs) Full-time United Kingdom
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

You will design, build, and operate security application frameworks for a Kubernetes-based developer platform across multiple cloud providers. You will also collaborate with engineering teams to embed security guardrails into the development lifecycle and elevate the overall security profile of Apple Services.

What they look for

Platform Security Kubernetes Go Kotlin Java Spring Framework Identity and Access Management Cloud Security Container Security Supply Chain Security Vulnerability Management OAuth2 OIDC JWT PKI Cryptography

Requirements

The role requires experience in platform security or infrastructure software engineering, along with proficiency in Go, Kotlin, or Java. Candidates should possess strong communication skills and a passion for developer enablement and secure-by-default practices.

Full description

The Wallet & Payments Security Solutions team sits at the intersection of developer experience and customer trust, building the foundational security layer that every product in the Apple Pay portfolio depends on. We are a group of security engineers passionate about enabling fast, safe engineering at scale across a modern, Kubernetes-based multi-cloud platform. This role is an opportunity to shape secure-by-default practices across Apple Pay engineering organizations working on Payments, Transit, Access, & Identity products. If you're passionate about security and customer safety, we may have the job for you.

Description

As a Platform Security Engineer on the Wallet & Payments Security Solutions team, you will design, build, and operate security application frameworks and solutions for a Kubernetes-based developer platform spanning multiple cloud providers. You will partner closely with platform and product engineering teams to embed security into every stage of the development lifecycle, ensuring guardrails never become friction. Your work will directly protect Apple customers and the engineers who build the products they rely on every day. Further, as part of this role, you will frequently collaborate with other security engineers and architects across Apple to identify, define and design security solutions which elevate overall security profile of Apple Services.

Minimum Qualifications

Experience in platform security and/or software engineering experience in infrastructure and application development, or a closely related security engineering discipline Experience in Go, Kotlin/Java and Spring Framework. Ability to communicate thoughtfully and clearly, both verbally and in writing, to discuss complex technical concepts with diverse audiences, including global teams. Passion for developer enablement and building "security as a product" The tenacity and perseverance to drive a complex project all the way from conception to production.

Preferred Qualifications

BS in Computer Science or equivalent experience/skills in application development and security. Prior experience contributing to or driving a secure-by-default platform initiative across a large engineering organization Experience with Identity and Access management frameworks Deep expertise in Kubernetes security, including RBAC, admission control, pod security standards, network policy, and workload identity Experience designing and implementing security controls across at least two major cloud providers and not just defining policies. Experience hardening containers and orchestration: image provenance, admission control, runtime and network policy, service mesh configuration, and clean isolation across micro services Experience with Supply Chain Security and optimizing Vulnerability management loop. Identity protocols and applied cryptography in practice: OAuth2, OIDC, JWT, SAML, mutual TLS, PKI, encryption and signing primitives. Fluency with coding agents and LLM-based development tooling, and judgment about when to trust their output.

Similar roles