About The Position

Apple Services Engineering (ASE) is seeking a Senior Security Engineer to collaborate with engineering teams on new products and features. This role involves partnering with developers, site reliability engineers, and security teams to protect ASE services and establish a secure foundation for services at Apple. Responsibilities include end-to-end security assurance, encompassing security architecture, threat modeling, security testing, and risk management. The engineer will work with partner teams in security engineering, privacy, and offensive security to ensure the security of Apple's services for users. The ideal candidate is passionate about exploring complex technical systems, sharing security improvements, and enhancing overall security posture.

Requirements

  • 5 or more years conducting security reviews, threat modeling, tracking findings, and communicating risk to engineering and leadership.
  • Hands-on experience in cloud security engineering with demonstrated expertise in securing at least one major cloud platform (AWS, GCP, or AliCloud) in production environments.
  • Deep technical knowledge of cloud-native security controls including identity and access management (IAM), network security (VPCs, security groups, firewall rules), encryption (KMS, data protection), and logging/monitoring services native to major cloud platforms.
  • Proven experience working with and using policy-as-code frameworks such as AWS Service Control Policies (SCPs), GCP Organization Policy Constraints, or AliCloud Control Policies to enforce security guardrails at scale.
  • Strong background in third-party risk assessment and vendor security reviews, including the ability to evaluate cloud service architectures, identify security gaps, and provide actionable remediation guidance.
  • Demonstrated ability to develop security requirements and design documentation for complex cloud environments, translating technical controls into clear, implementable guidance for engineering teams.
  • Conversant in at least one programming language such as Python, Java, Go, or Swift.

Nice To Haves

  • Bachelor's Degree or equivalent experience preferred.
  • Experience securing cloud-native applications and workloads including containerized environments (Kubernetes/EKS/GKE), serverless architectures (Lambda/Cloud Functions), and modern CI/CD pipelines.
  • Experience with multiple cloud platforms (AWS, GCP, Azure, AliCloud) and the ability to perform comparative security analysis across different cloud providers' security models and controls.

Responsibilities

  • Serve as the primary security team point of contact for several large engineering efforts.
  • Collaborate with engineering teams throughout their development lifecycle.
  • Conduct security reviews and develop threat models.
  • Utilize insights from engagements to build standard methodologies.
  • Define, automate, and advocate for platform-wide security improvements.
  • Partner with colleagues to elevate the security bar for all engineering teams at Apple.
  • Act as a technical lead responsible for the security of Apple's internet-facing services and backend infrastructure.
  • Develop proof of concept systems to automate security recommendations, vulnerability discovery, and process workflows.
  • Use data to drive security review efficiency and prioritize high-value security team engagement.
  • Make security decisions impacting millions of users.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service