Senior Security Software Engineer, Software Supply Chain Security

Socket.dev

Seattle (WA)

On-site

USD 190,000 - 270,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Apple is seeking a senior security software engineer to own architecture for software inventory, SBOMs, and vulnerability data across our vast ecosystem. You will shape data models, drive engineering quality, and mentor teams while collaborating with security leadership to ensure trusted, actionable signals for product and platform teams at scale.

The role requires deep experience in Go and Java security pipelines, SCA tooling, and CI/CD, with cloud/container familiarity (Kubernetes, AWS).

Qualifications

  • 8+ years of experience in security software engineering.
  • End-to-end ownership of a system or platform.
  • Hands-on experience in software supply chain security, dependency management and OSS risk.
  • Proficiency in Go and Java ecosystems (Go Modules, Maven/Gradle).
  • SBOM standards, SCA tooling and vulnerability data sources (NVD, OSV, GitHub Advisories).
  • Track record of technical leadership and architecture decisions.
  • Experience with CI/CD, build systems, release engineering; Kubernetes and AWS.
  • AI coding assistants and agentic development tools experience.

Responsibilities

  • Own technical depth across software composition analysis and vulnerability intelligence.
  • Define how software inventory and vulnerability data are modeled and correlated.
  • Mentor engineers and set engineering quality standards for the team.
  • Collaborate with security leadership to ensure trusted data for engineering teams.

Skills

Security software engineering
End-to-end ownership
OSS risk
Go
Java
Go Modules
Maven/Gradle
SBOM standards
SCA tooling
Vulnerability data sources
NVD
OSV
GitHub Advisories
Architecture decisions
Technical leadership
CI/CD
Build systems
Release engineering
Kubernetes
AWS
AI coding assistants

Tools

CI/CD tooling
Kubernetes

Job description

We are the Dependency Risk & Automation Team in Apple Services Engineering (ASE) Security. We're responsible for understanding what software Apple runs, where it came from, and how exposed it is, across the internal and open-source projects behind iCloud, Music, Siri, the App Store, and the rest of Apple's services. Composition and vulnerability signal reach us from build systems, package registries, vulnerability feeds, and SBOMs generated across a large, heterogeneous estate of projects and languages, and increasingly from dependency choices made by AI coding assistants and agents rather than the engineers who own the code. Turning that into one prioritized, trustworthy picture of risk that engineering teams can act on and security leadership can rely on takes real architectural judgment, not just tooling. We're looking for a senior engineer to take technical ownership of significant parts of this problem: shaping how software inventory and vulnerability data are modeled and correlated, setting the engineering quality bar the rest of the platform is held to, and mentoring engineers across the team and adjacent teams on how to reason about supply chain risk. You'll make the architectural calls that determine whether the rest of the company can trust and act on that data, and you'll play a meaningful role in ensuring the highest standard of security for one of the most-watched companies in the world.

Description

This role owns technical depth across software composition analysis, vulnerability intelligence, and the automation that keeps both operating reliably at Apple's scale. You'll work across a diverse set of tools and codebases, and you'll be one of the people other engineers and adjacent security teams turn to when supply chain risk questions get hard, from how we track what's in our software, to how we correlate that against emerging vulnerabilities and end-of-life risk, to how we make that information actionable rather than just available. You will confront a new class of problem, as AI coding assistants and agents generate a growing share of Apple's code and a growing share of its dependency choices you'll help define what secure software development means when dependencies increasingly get pulled in with minimal human review.

Minimum Qualifications

8+ years of experience in security software engineering, with demonstrated end-to-end ownership of a system or platform, and hands-on experience in the software supply chain security, dependency management and OSS riskDeep proficiency in Go and strong proficiency in Java, including both languages' dependency ecosystems (Go Modules, Maven/Gradle), plus solid software engineering fundamentalsExperience with SBOM standards, software composition analysis (SCA) tooling and vulnerability data sources (e.g., NVD, OSV, GitHub Advisories), turning raw feeds into prioritized signalTrack record of technical leadership — driving architecture decisions, setting technical direction for a team or platform, mentoring other engineers, and communicating technical tradeoffs clearly to both engineers and security leadershipExperience with software delivery pipelines (CI/CD, build systems, release engineering) and cloud/container infrastructure (Kubernetes, AWS or equivalent)Practical, hands-on experience with AI coding assistants or agentic development tools, and an understanding of emerging AI-specific supply chain risks

Preferred Qualifications

Familiarity with specific SBOM formats and tooling (CycloneDX, SPDX, cdxgen, syft) and the Package URL (purl) standardKnowledge of Open Container Initiative (OCI) image conceptsExperience with SLSA (Supply-chain Levels for Software Artifacts) and build/artifact attestationsExperience with graph-based data modeling for dependency or risk relationshipsExperience designing or operating automated dependency curation or allow-listing systems that can keep pace with AI-accelerated developmentFamiliarity with spec-driven development workflows and how they change the security review surface

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Software Engineer, Software Supply Chain Security
Senior Security Software Engineer, Software Supply Chain Security

Apple Inc. • Seattle (WA)

On-site
USD 175,000 - 309,000
Employee stock programs
Health & dental coverage
Tuition reimbursement
+1
Senior Security Software Engineer - AI Supply Chain Risk
Senior Security Software Engineer - AI Supply Chain Risk

Socket.dev • Seattle (WA)

On-site
USD 190,000 - 270,000
Senior Software Engineer - Security
Senior Software Engineer - Security

Socket.dev • Seattle (WA)

On-site
USD 150,000 - 230,000
Health insurance
401(k) with company match
Senior Security Software Engineer - Supply Chain Security
Senior Security Software Engineer - Supply Chain Security

Apple Inc. • Seattle (WA)

On-site
USD 175,000 - 309,000
Employee stock programs
Health & dental coverage
Tuition reimbursement
+1
Senior Strategic Risk Manager - Account Security
Senior Strategic Risk Manager - Account Security

Socket.dev • Cupertino (CA)

On-site
USD 140,000 - 190,000
Security Software Engineer, Enterprise Technology Services
Security Software Engineer, Enterprise Technology Services

Socket.dev • Sunnyvale (CA)

On-site
USD 150,000 - 210,000
Security Platform Automation Engineer
Security Platform Automation Engineer

Socket.dev • Seattle (WA)

On-site
USD 180,000 - 240,000
Software Supply Chain Security Specialist
Software Supply Chain Security Specialist

Vanguard • Malvern

On-site
USD 150,000 - 210,000
Sr Automation & Intelligence Tools Engineer, SEAR
Sr Automation & Intelligence Tools Engineer, SEAR

Socket.dev • Cupertino (CA)

On-site
USD 180,000 - 240,000
Systems Software Engineer, Information Security
Systems Software Engineer, Information Security

Apple Inc. • Austin (TX)

On-site
USD 100,000 - 130,000