Senior Security Software Engineer, Software Supply Chain Security
We are the Dependency Risk & Automation Team in Apple Services Engineering (ASE) Security. We're responsible for understanding what software Apple runs, where it came from, and how exposed it is, across the internal and open-source projects behind iCloud, Music, Siri, the App Store, and the rest of Apple's services.
Composition and vulnerability signal reach us from build systems, package registries, vulnerability feeds, and SBOMs generated across a large, heterogeneous estate of projects and languages, and increasingly from dependency choices made by AI coding assistants and agents rather than the engineers who own the code. Turning that into one prioritized, trustworthy picture of risk that engineering teams can act on and security leadership can rely on takes real architectural judgment, not just tooling.
We're looking for a senior engineer to take technical ownership of significant parts of this problem: shaping how software inventory and vulnerability data are modeled and correlated, setting the engineering quality bar the rest of the platform is held to, and mentoring engineers across the team and adjacent teams on how to reason about supply chain risk. You'll make the architectural calls that determine whether the rest of the company can trust and act on that data, and you'll play a meaningful role in ensuring the highest standard of security for one of the most-watched companies in the world.
Description
This role owns technical depth across software composition analysis, vulnerability intelligence, and the automation that keeps both operating reliably at Apple's scale. You'll work across a diverse set of tools and codebases, and you'll be one of the people other engineers and adjacent security teams turn to when supply chain risk questions get hard, from how we track what's in our software, to how we correlate that against emerging vulnerabilities and end-of-life risk, to how we make that information actionable rather than just available.
You will confront a new class of problem, as AI coding assistants and agents generate a growing share of Apple's code and a growing share of its dependency choices you'll help define what secure software development means when dependencies increasingly get pulled in with minimal human review.
Preferred Qualifications
Familiarity with specific SBOM formats and tooling (CycloneDX, SPDX, cdxgen, syft) and the Package URL (purl) standard
Knowledge of Open Container Initiative (OCI) image concepts
Experience with SLSA (Supply-chain Levels for Software Artifacts) and build/artifact attestations
Experience with graph-based data modeling for dependency or risk relationships
Experience designing or operating automated dependency curation or allow-listing systems that can keep pace with AI-accelerated development
Familiarity with spec-driven development workflows and how they change the security review surface
Minimum Qualifications
8+ years of experience in security software engineering, with demonstrated end-to-end ownership of a system or platform, and hands-on experience in the software supply chain security, dependency management and OSS risk
Want more jobs like this?
Get jobs in Seattle, WA delivered to your inbox every week.

Deep proficiency in Go and strong proficiency in Java, including both languages' dependency ecosystems (Go Modules, Maven/Gradle), plus solid software engineering fundamentals
Experience with SBOM standards, software composition analysis (SCA) tooling and vulnerability data sources (e.g., NVD, OSV, GitHub Advisories), turning raw feeds into prioritized signal
Track record of technical leadership - driving architecture decisions, setting technical direction for a team or platform, mentoring other engineers, and communicating technical tradeoffs clearly to both engineers and security leadership
Experience with software delivery pipelines (CI/CD, build systems, release engineering) and cloud/container infrastructure (Kubernetes, AWS or equivalent)
Practical, hands-on experience with AI coding assistants or agentic development tools, and an understanding of emerging AI-specific supply chain risks
Pay & Benefits
At Apple, base pay is one part of our total compensation package and is determined within a range. This provides the opportunity to progress as you grow and develop within a role. The base pay range for this role is between $175,000 and $308,500, and your base pay will depend on your skills, qualifications, experience, and location.
Apple employees also have the opportunity to become an Apple shareholder through participation in Apple's discretionary employee stock programs. Apple employees are eligible for discretionary restricted stock unit awards, and can purchase Apple stock at a discount if voluntarily participating in Apple's Employee Stock Purchase Plan. You'll also receive benefits including: Comprehensive medical and dental coverage, retirement benefits, a range of discounted products and free services, and for formal education related to advancing your career at Apple, reimbursement for certain educational expenses - including tuition. Additionally, this role might be eligible for discretionary bonuses or commission payments as well as relocation. Learn more about Apple Benefits
Note: Apple benefit, compensation and employee stock programs are subject to eligibility requirements and other terms of the applicable plan or program.
Perks and Benefits
Health and Wellness
Parental Benefits
Work Flexibility
Office Life and Perks
Vacation and Time Off
Financial and Retirement
Professional Development
Diversity and Inclusion
Company Videos
Hear directly from employees about what it is like to work at Apple.