Security Platform Automation Engineer

Apple
Apple

Software Engineering

Ontario, Canada · Seattle, WA, USA

USD 175k-308,500 / year + Equity

Posted on Aug 26, 2026
We are the Assurance Automation & Risk Management team within Apple Services Engineering (ASE) Security org. We are responsible for securing the platforms, infrastructure, and distributed systems behind Apple’s global services, including iCloud, App Store, Apple Music, TV+, Maps, and Commerce. Apple operates thousands of critical backend services across a rapidly expanding global footprint. We have a transformative opportunity to amplify security experts reach by building the next-generation AI-assisted Security Automation Platform. Rather than building isolated tooling, we turn expert security standards into robust, running software by combining agentic workflows, deterministic scaffolding, and rigorous evaluation gates integrated directly into Apple’s core security data systems (Security Findings, Bill of Materials, and Risk Governance). We are hiring Tech Lead to lead the software architecture and agentic engineering of this platform. Your effort will help build solutions to a variety of outstanding security challenges in software supply chain, security posture, and risk management. Join us, and you’ll play a meaningful role in ensuring the highest standard of security for one of the most-watched companies in the world.
We’re looking for an exceptional automation engineer to build the pipeline that scales security review across Apple’s 1000s+ services. You will turn security expertise into running software, designing and operating AI agentic review system, skills, tool layer, evaluation harness on top of Apple's existing security tooling, and giving reviewers a reliable, high-throughput pipeline to execute against. You’ll partner closely with the security engineers who define the review standards and the analysts who validate the output, and build automation that reduces toil.
  • Design system and interfaces that make Apple's existing security systems agent-consumable
  • Build and maintain the review automation pipeline that ingests a service, runs AI-assisted threat modeling and triage, and produces structured, reviewable output at scale
  • Implement the AI skills and routing criteria defined by our security standards engineers, meeting quality targets for precision, recall, and false positives
  • Integrate the pipeline with existing security engineering tooling (findings, vulnerability intelligence, SBOM, scanning, and risk-acceptance systems) rather than standing up parallel foundations
  • Build the quality feedback loop so signals from reviewer validation continuously improve the automation
  • Be accountable for quality software that meets service level objectives, with runbooks, tests, and observability so no system depends on a single person
  • Own prompt, skill, and model versioning as code, with the eval gates
  • Research, prototype, and present ideas and designs to your team, management, and internal customers
  • 1 year of building LLM- or agent-based systems that ran in production, with a measured quality bar
  • 8+ years building and operating production automation, data pipelines, or backend services
  • Highly proficient in at least one of Python, Go, or Java
  • Experience integrating third-party and first-party APIs, tooling, and services into reliable end-to-end workflows and AI agent workflows
  • Working knowledge of application and cloud security concepts (threat modeling, vulnerabilities, secure configuration)
  • MS or BS or equivalent experience in Computer Science, Engineering, or a related field OR equivalent practical experience in Software or Security Engineering
  • Experience with Agent engineering: retrieval, grounding, citation, reasoning
  • Experience with Agentic workflow design with bounded autonomy, building LLM- or agent-based automation and evaluating output quality (precision/recall, human-in-the-loop feedback loops), AI agent evaluation harness as CI
  • Familiar with AWS cloud resources (S3, EC2, Lambda, Step Functions, etc.)
  • Experience with security tooling such as SAST/SCA scanners, SBOM tooling, or vulnerability intelligence platforms
  • Background in security review, threat modeling, or supply-chain security
  • Experience delivering tooling used by non-engineer reviewers or contractors at scale
  • Awareness of AI-specific threats in systems that ingest untrusted input