Security Software Engineer - Software Supply Chain Security
Seattle, Washington, United States
Software and Services
Summary
Posted: Jun 04, 2025
Weekly Hours: 40
Role Number: 200607648
The Apple Services Engineering Security team is looking for a passionate and skilled Security Software Engineer that will focus on securing the software supply chain across the organization. In this role, you will help build and scale automated security tooling to identify and remediate critical software vulnerabilities at scale. You will partner closely with engineering teams to ensure secure development practices are embedded throughout the lifecycle.
This role is ideal for someone with a strong background in application security, code analysis, and a deep understanding of modern software development ecosystems, particularly GitHub and GitHub Advanced Security (GHAS). You will play a key role in developing and deploying custom CodeQL queries to detect vulnerabilities and reduce risk across Apple Services codebases.
Description
As a Security Software Engineer in Apple Services Engineering, you will:
Develop, deploy, and maintain automated tools to detect and help developers fix critical security vulnerabilities across our services.
Drive the adoption and scaling of GitHub Advanced Security across engineering teams, ensuring broad coverage and impact.
Write and maintain custom CodeQL queries tailored to Apple's codebases and threat model.
Partner with engineering teams to integrate secure development tooling into their CI/CD pipelines and developer workflows.
Contribute to internal tooling and frameworks that support scalable, automated supply chain risk reduction.
Continuously evaluate and improve the effectiveness of our vulnerability detection and remediation capabilities.
Stay current with the latest supply chain security threats and techniques and help Apple proactively respond to them.
Minimum Qualifications
Over five years of experience in software security, with a focus on software supply chain risk.
Programming skills in Go, Java and Python
Deep understanding of secure software development practices and static code analysis.
Experience building scalable security tools or automation for large developer organizations.
Excellent collaboration and communication skills; ability to work cross-functionally with security and engineering teams.
Preferred Qualifications
Hands-on experience with GitHub Advanced Security (GHAS), including enabling and managing security features at scale.
Proficiency with CodeQL and experience writing or customizing CodeQL queries to identify application vulnerabilities.
Knowledge of vulnerability management, SBOMs, and dependency analysis is a plus.
Pay & Benefits
At Apple, base pay is one part of our total compensation package and is determined within a range. This provides the opportunity to progress as you grow and develop within a role. The base pay range for this role is between $166,600 and $296,300, and your base pay will depend on your skills, qualifications, experience, and location.
Apple employees also have the opportunity to become an Apple shareholder through participation in Apple's discretionary employee stock programs. Apple employees are eligible for discretionary restricted stock unit awards, and can purchase Apple stock at a discount if voluntarily participating in Apple's Employee Stock Purchase Plan. You'll also receive benefits including: Comprehensive medical and dental coverage, retirement benefits, a range of discounted products and free services, and for formal education related to advancing your career at Apple, reimbursement for certain educational expenses - including tuition. Additionally, this role might be eligible for discretionary bonuses or commission payments as well as relocation.Learn more about Apple Benefits. (https://www.apple.com/careers/us/benefits.html)
Note: Apple benefit, compensation and employee stock programs are subject to eligibility requirements and other terms of the applicable plan or program.
Apple is an equal opportunity employer that is committed to inclusion and diversity. We seek to promote equal opportunity for all applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, Veteran status, or other legally protected characteristics.Learn more about your EEO rights as an applicant (https://www.eeoc.gov/sites/default/files/2023-06/22-088\EEOC\KnowYourRights6.12ScreenRdr.pdf) .
Apple is an equal opportunity employer that is committed to inclusion and diversity. We seek to promote equal opportunity for all applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, Veteran status, or other legally protected characteristics.Learn more about your EEO rights as an applicant (https://www.eeoc.gov/sites/default/files/2023-06/22-088\EEOC\KnowYourRights6.12ScreenRdr.pdf) .
Apple will not discriminate or retaliate against applicants who inquire about, disclose, or discuss their compensation.
Apple participates in the E-Verify program in certain locations as required by law.Learn more about the E-Verify program (https://www.apple.com/jobs/pdf/EverifyPosterEnglish.pdf) .
Apple is committed to working with and providing reasonable accommodation to applicants with physical and mental disabilities. Reasonable Accommodation and Drug Free Workplace policy Learn more .
Apple is a drug-free workplace. Reasonable Accommodation and Drug Free Workplace policy Learn more .
Apple will consider for employment all qualified applicants with criminal histories in a manner consistent with applicable law. If you're applying for a position in San Francisco, review the San Francisco Fair Chance Ordinance guidelines applicable in your area.
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.