Apple
Posted 3d ago

Senior Security Software Engineer, Software Supply Chain Security

Apple
Seattle or Washington or United States or West
OnsiteFull Time
Responsibilities
  • modeling inventory
  • correlating vulnerabilities
  • mentoring engineers
Requirements
  • Requires 8+ years in security software engineering
  • Deep Go and strong Java proficiency
  • Supply chain security expertise
  • SBOM/SCA knowledge
  • CI/CD and cloud infrastructure experience, and technical leadership
Technical tools mentioned
GoJavaGo ModulesMavenGradleSBOMsoftware composition analysis (SCA)NVDOSVGitHub AdvisoriesCI/CDKubernetesAWSCycloneDXSPDXcdxgensyftPackage URL (purl)Open Container Initiative (OCI)SLSA

Job description

We are the Dependency Risk & Automation Team in Apple Services Engineering (ASE) Security. We're responsible for understanding what software Apple runs, where it came from, and how exposed it is, across the internal and open-source projects behind iCloud, Music, Siri, the App Store, and the rest of Apple's services.

Composition and vulnerability signal reach us from build systems, package registries, vulnerability feeds, and SBOMs generated across a large, heterogeneous estate of projects and languages, and increasingly from dependency choices made by AI coding assistants and agents rather than the engineers who own the code. Turning that into one prioritized, trustworthy picture of risk that engineering teams can act on and security leadership can rely on takes real architectural judgment, not just tooling.

We're looking for a senior engineer to take technical ownership of significant parts of this problem: shaping how software inventory and vulnerability data are modeled and correlated, setting the engineering quality bar the rest of the platform is held to, and mentoring engineers across the team and adjacent teams on how to reason about supply chain risk. You'll make the architectural calls that determine whether the rest of the company can trust and act on that data, and you'll play a meaningful role in ensuring the highest standard of security for one of the most-watched companies in the world.

Description

This role owns technical depth across software composition analysis, vulnerability intelligence, and the automation that keeps both operating reliably at Apple's scale. You'll work across a diverse set of tools and codebases, and you'll be one of the people other engineers and adjacent security teams turn to when supply chain risk questions get hard, from how we track what's in our software, to how we correlate that against emerging vulnerabilities and end-of-life risk, to how we make that information actionable rather than just available.

You will confront a new class of problem, as AI coding assistants and agents generate a growing share of Apple's code and a growing share of its dependency choices you'll help define what secure software development means when dependencies increasingly get pulled in with minimal human review.

Minimum Qualifications

  • 8+ years of experience in security software engineering, with demonstrated end-to-end ownership of a system or platform, and hands-on experience in the software supply chain security, dependency management and OSS risk
  • Deep proficiency in Go and strong proficiency in Java, including both languages' dependency ecosystems (Go Modules, Maven/Gradle), plus solid software engineering fundamentals
  • Experience with SBOM standards, software composition analysis (SCA) tooling and vulnerability data sources (e.g., NVD, OSV, GitHub Advisories), turning raw feeds into prioritized signal
  • Track record of technical leadership — driving architecture decisions, setting technical direction for a team or platform, mentoring other engineers, and communicating technical tradeoffs clearly to both engineers and security leadership
  • Experience with software delivery pipelines (CI/CD, build systems, release engineering) and cloud/container infrastructure (Kubernetes, AWS or equivalent)
  • Practical, hands-on experience with AI coding assistants or agentic development tools, and an understanding of emerging AI-specific supply chain risks

Preferred Qualifications

  • Familiarity with specific SBOM formats and tooling (CycloneDX, SPDX, cdxgen, syft) and the Package URL (purl) standard
  • Knowledge of Open Container Initiative (OCI) image concepts
  • Experience with SLSA (Supply-chain Levels for Software Artifacts) and build/artifact attestations
  • Experience with graph-based data modeling for dependency or risk relationships
  • Experience designing or operating automated dependency curation or allow-listing systems that can keep pace with AI-accelerated development
  • Familiarity with spec-driven development workflows and how they change the security review surface

About Apple

Designing and manufacturing consumer electronics, software, and digital services.

Similar jobs

Security Software Engineer roles near Seattle, Washington
1w
Save
Mark Applied
Hide
New Graduate Engineer, Software Security - '26/'27 (Starlink)
Hawthorne or Redmond
$140k-$210k/yr OnsiteFull Time
SpaceX
SpaceXNasdaq: SPCX: Designing, manufacturing, and launching advanced rockets and spacecraft.
Bachelor's degree in computer science or STEM, software development experience in Python, C++, or Golang, security solution implementation experience, and graduation in 2026 or 2027.
Python, C++, Golang, Trusted Platform Modules (TPMs), Hardware Security Modules (HSMs)
3w
Save
Mark Applied
Hide
Senior Security Software Engineer, IAM - Moveworks
Kirkland, Washington, United States
HybridFull Time
Moveworks
Moveworks: Enterprise AI assistant platform that helps organizations automate employee support, search, and workflows.
5+ YOE5+ years developing IAM products or tools; production software, infrastructure as code, automation, and IAM expertise required. BS+ in computer science or related field or equivalent experience.
AWS, Azure, Kubernetes, Teleport, Terraform, Security Information and Event Management (SIEM)
3w
Save
Mark Applied
Hide
Senior Security Software Engineer, IAM - Moveworks
Kirkland or Mountain View
OnsiteFull Time
Moveworks
Moveworks: Enterprise AI assistant platform that helps organizations automate employee support, search, and workflows.
5+ YOE5+ years developing and maintaining IAM products or tools; production software, Infrastructure as Code, IAM best practices, secure access modeling, and automation experience; BS in computer science or related field or equivalent experience.
AWS, Azure, Kubernetes, Teleport, Terraform, Security Information and Event Management (SIEM)
2mo
Save
Mark Applied
Hide
Mid-Level Software Security Engineer
Seattle or Everett
$138k-$186k/yr OnsiteFull Time
Boeing
BoeingNYSE: BA: Global aerospace manufacturer of commercial and defense aircraft.
5+ YOEBachelor's in a related field, 5+ years related experience, 1+ year applying confidentiality/integrity/availability in SDLC, experience with SDLC and software security engineering practices.
Software Development Lifecycle (SDLC), DevSecOps, CI/CD, Common Vulnerabilities and Exploits (CVE), Public Key Infrastructure, hardware security modules, certificate authorities
2mo
Save
Mark Applied
Hide
Mid-Level Software Security Engineer
Seattle or Everett
$138k-$186k/yr OnsiteFull Time
Boeing
BoeingNYSE: BA: Global aerospace manufacturer of commercial and defense aircraft.
5+ YOEBachelor's degree or equivalent; 5+ years related experience; 1+ years applying CIA within SDLC; experience with SDLC, secure coding, software security, and DevSecOps/CI/CD practices.
Secure Coding, Software Development Lifecycle (SDLC), DevSecOps, Continuous Integration and Continuous Deployment (CI/CD), Public Key Infrastructure (PKI), hardware security module, Common Vulnerabilities and Exploits (CVE)
4mo
Save
Mark Applied
Hide
Senior Software Engineer, Security
Seattle or San Francisco
$165k-$230k/yr OnsiteFull Time
NexHealth
NexHealth: Patient experience platform helping doctors and developers streamline EHR-integrated scheduling, communications, and digital paperwork.
5+ YOE5+ years software engineering; 1–3+ years in application or product security; backend experience (Python/Go/Java); OAuth/JWT/RBAC; cloud (AWS/GCP); SAST/DAST; HIPAA/SOC 2 knowledge; bachelor’s in CS/Engineering or equivalent.
OAuth 2.0, JWT, RBAC, SAST, DAST, cloud (AWS, Google Cloud), security tooling, CI/CD
1y
Save
Mark Applied
Hide
Senior Software Security Engineer
San Francisco or New York City or Seattle
$320k-$405k/yr HybridFull Time
Anthropic
Anthropic: AI research developing safe and steerable AI systems.
5+ YOE5+ years building and maintaining security-relevant systems; Bachelor's degree or equivalent; strong programming in Python, Go, or Rust; cloud and Kubernetes security experience; ownership and strong communication skills.
Python, Go, Rust, Kubernetes, SAST, eBPF, OAuth 2.0, OIDC, SAML, SPIFFE, SPIRE, RBAC, VPC, CI/CD
1mo
Save
Mark Applied
Hide
Security Software Dev Engineer II, AWS Security Corporate Response
Seattle, Washington, United States
$144k-$194k/yr OnsiteFull Time
Amazon
AmazonNASDAQ: AMZN: Multinational technology focused on e-commerce and cloud computing.
3+ YOE3+ years professional software development, 2+ years system design/architecture, experience with at least one programming language and Amazon Bedrock/Gen AI, EM lifecycle familiarity; Bachelor's in CS preferred.
Amazon Bedrock, AWS