About The Position

Join Apple’s Information Systems and Technology (IS&T) organization as a Senior Network Security Engineer. IS&T is responsible for Apple's global technology systems, supporting billions of devices and transactions. Infrastructure Services, a part of IS&T, manages data center equipment and systems, providing compute, storage, and networking services. This is a hands-on engineering role focused on designing, deploying, automating, and troubleshooting resilient enterprise network services. You will collaborate with various teams to design, engineer, and improve network services, focusing on Zero Trust and modern secure access architectures. The role involves designing multi-profile VPN services, scaling connectivity, and building automation and AI-driven workflows to evolve from reactive support to predictive, self-healing engineering. The goal is to continuously improve service reliability, security posture, and user/partner experience at a global scale. We seek engineers who are curious, take end-to-end ownership, and solve complex problems through engineering. Successful candidates thrive in collaborative environments, embrace continuous learning, challenge conventional approaches, and leverage software, automation, observability, and AI.

Requirements

  • 8+ years of enterprise experience designing, deploying, and operating global network security, routing, Switching, remote access VPN, and WAN/SD-WAN architectures.
  • Deep firewall & edge platform expertise: Hands-on mastery of Cisco ASA / Firepower, Palo Alto Networks Firewalls, and Fortinet (FortiGate / FortiOS), including security policy architecture, NAT, NAT64 and platform lifecycle management.
  • Large-scale Remote Access & Zero Trust: Proven track record engineering multi-profile SSL and IPsec remote access services (split/full tunnel, device posture, per-app VPN) and integrating with modern ZTNA/SSE architectures.
  • Advanced IPsec & Site-to-Site Connectivity: Deep expertise in IKEv1/IKEv2, PKI/certificate authentication, crypto suites, VTI, DMVPN/FlexVPN, and resilient tunnel architecture for Client to site VPN, partners, 3PLs, and remote sites.
  • Complex Routing & WAN Edge: Advanced BGP and OSPF routing design across hybrid WAN/SD-WAN environments, including carrier peering, traffic engineering (communities, AS-path manipulation), VRF route-leaking, and L2/L3 segmentation.
  • Identity & Access Management Integration: Strong experience integrating network access with enterprise IAM systems—RADIUS, TACACS+, SAML/SSO, MFA, PKI certificate lifecycle, 802.1X, and NAC.
  • End-to-End Troubleshooting & Telemetry: Exceptional packet-level diagnostic skills (pcap, flow analysis, debugs, MTU/path latency issues) across security policies, overlay/underlay networks, and application layers.
  • Infrastructure Automation & Modern Tooling: Demonstrated proficiency automating network security provisioning and validation using Python, REST APIs, Ansible, or Terraform, with bonus experience leveraging AI/LLM-assisted workflows for operations and triage.

Nice To Haves

  • Bachelor's degree in Computer Science, Information Technology, Computer Engineering, Electrical Engineering, or a related technical discipline, or equivalent practical experience
  • Professional-level network security certifications, such as CCNP Security, PCNSE (Palo Alto Networks), JNCIP-SEC (Juniper), or equivalent demonstrated expertise.
  • Experience leading large-scale network migrations, such as transitioning legacy VPN and MPLS footprints toward modern Zero Trust (ZTNA), SASE, or SD-WAN architectures.
  • Background in hybrid cloud networking (AWS, Azure, or GCP), including cloud edge firewalls, transit architectures, and dedicated interconnects (Direct Connect / ExpressRoute).
  • Track record of applying software engineering and emerging AI/agentic workflows (Python, CI/CD, IaC, GenAI, Claude) to automate security provisioning and eliminate operational toil.
  • History of cross-functional technical leadership, with experience driving SLO-based reliability, security standards, and operational excellence beyond your immediate team.

Responsibilities

  • Design, engineer, and continuously improve resilient enterprise network services.
  • Design multi-profile VPN services.
  • Scale partner and remote site connectivity.
  • Build automation and agentic AI-driven workflows.
  • Engineer, Reliability and operation resilient network security services across Cisco, Palo Alto Networks, and Fortinet platforms.
  • Advance Zero Trust journey by engineering scalable multi-profile VPN services.
  • Design resilient hybrid SD-WAN fabrics.
  • Establish secure connectivity for remote facilities, 3PL logistics sites, and third-party partners.
  • Eliminate operational toil by applying software engineering, infrastructure as code, and agentic AI workflows.
  • Evolve systems from reactive troubleshooting into predictive, self-healing platforms.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service