January 31, 2025

Senior Staff Security Engineer - Red Team

Senior • On-site

$207,800 - $312,200/yr

New York City, NY

Summary

Posted:
Weekly Hours: 40
Role Number:200589192
Home Office: Yes
Apple Services Engineering (ASE), the team behind Apple Services (iCloud, App and Media) and the infrastructure that powers it, is looking for security engineers to partner with engineering teams working on significant services. You will collaborate with developers, site reliability engineers, and security teams to protect ASE services. Your work will include end-to-end security assurance activities including security architecture, threat modeling and extensive security testing. The ASE Security Red Team focuses on deep technical security review work of critical ASE services and infrastructure. These security reviews will either be scoped and focused on review depth, or objective oriented with exploit chain enumeration. You will be working with partner teams in security engineering, privacy, detection and design review to keep Apple's services secure for our users. If you love diving into complex and important system, and driving the security of that system over time, we want to talk to you!

Description

In this role, you will scope and lead focused security reviews on critical internet scale applications and supporting infrastructure. Within these depth focused engagements, you will learn the services architecture and risk profile to build a scope that enables meaningful security review. Once the review starts, you and the team will review with a high bar for depth and quality. After the review, you will go beyond vulnerabilities, communicating with stakeholders and leadership important observations. You may also lead and scope goal or objective oriented Red Team exercises. Your Red Team exercises will include the standard phases of attacker emulation, like reconnaissance, exploitation, pivoting and stealth. Using insights from these engagements, you will help define, document, and automate security best practices, as well as advocate for platform-wide security enhancements to raise the security bar for all engineering teams at Apple. You will be: * A technical expert responsible for the enumerating risks or exploit chains. * A technical expert capable of identifying engagement scope, planning reviews, then executing those reviews to identify vulnerabilities and improvement opportunities. * Able to identify areas that are ripe for improvement and establishes appropriate security goals * Adept at building relationships with engineering and leadership teams to drive security improvements * Current on new security technologies, vulnerabilities, and methodologies * An excellent verbal and written communicator * Able to develop proof of concept systems to automate security recommendations, vulnerability discovery, and process workflows * Responsible for security decisions impacting hundreds of millions of users This position will involve some travel to other Apple sites.

Minimum Qualifications

  • 6+ years in an information security field or software engineering
  • Four or more of those years conducting security reviews
  • Bachelors degree in Computer Science / Engineering or a related, with emphasis in security related fields (or equivalent experience)
  • Extensive infrastructure, cloud and application security experience
  • Ability to reason about security of a large and complex application or infrastructure
  • Desire to go deep on complex systems for extended engagements

Preferred Qualifications

  • Desire to construct narratives and build exploit chains that relate to the business
  • Ability to reason about and influence software architecture for security
  • Community contributions like public CVEs, bug bounty recognition, open source tools, blogs, talks etc.
  • Threat modeling and communicating risk to engineering and leadership teams

Pay & Benefits

  • Apple is an equal opportunity employer that is committed to inclusion and diversity. We take affirmative action to ensure equal opportunity for all applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, Veteran status, or other legally protected characteristics. Learn more about your EEO rights as an applicant.