We’re looking for an experienced DevSecOps engineer, with specific expertise in application security or infrastructure security. Your work will be a mix between technical and human centered, as we work to build quality infrastructure and a strong security culture within Apple Health Software. Bring ideas and passion, as you’ll have room to shape this role and our roadmap. Initial responsibilities will include:
-Building security-focused infrastructure and process automations, with a focus on shifting security left in the software development lifecycle
-Reviewing code (primarily Java and Python) for vulnerabilities, and guiding remediation efforts
-Leading security efforts in design reviews, and guiding the creation of a comprehensive threat modeling program
-Engaging with engineers and internal customers to answer questions, respond to concerns, and empower work organization-wide
-Contribute to vulnerability management efforts, to help teams prioritize and remediate known vulnerabilities
-Joining DevOps on-call rotation to support our infrastructure and customers
Beyond that, your journey can take many paths. As we build a culture of security excellence, here are a few ideas we’re excited to work on:
-Build an offensive security program and methodology to conduct security assessments, penetration tests, and red team engagements
-Lead fun security demonstrations, workshops, and exercises for our software engineers, in order to strengthen security awareness and secure software development