Security Engineer - Health Software
Description
Imagine what you could do here. At Apple, great ideas have a way of becoming great products, services, and customer experiences very quickly - making the kind of impact that changes people's lives.
The Apple Health Software team embodies the core Apple values around delighting our customers with groundbreaking user experiences, empowering users to live a better - and healthier - life, while keeping their data safe, private, and secure.
We are seeking a self-driven senior security engineer to join Apple’s Health team to contribute to efforts supporting Apple’s health research tools and ecosystem. As a member of our team, you will have the unique and rewarding opportunity to enable teams across the company to conduct health research and ensure that research participant data is safe, private, and secure.
Description
As a Senior Security Engineer, you will be responsible for ensuring the security of the systems used to develop Apple’s health features. You will conduct manual application security tests and audit source code to support releases. You'll construct security testing plans and conduct testing to ensure security controls are in place and implemented correctly. You may develop tooling to support security improvement initiatives for the platform and provide security guidance for new projects, features, and changes to Health related projects.
Responsibilities
Conduct manual application security tests and audit source code to support releases
Design and execute comprehensive security testing plans to validate security controls are properly implemented
Perform threat modeling exercises for new features and research tools
Review architecture and design documents to identify security risks and recommend mitigations
Develop and maintain security tooling and automation to improve the security posture of our platform
Provide security guidance and consultation for new projects, features, and changes to Health related projects
Minimum qualifications
10+ years of experience in security engineering
Bachelor’s degree in Computer Science, Information Security, or a related technical field (or equivalent practical experience)
Extensive knowledge of security principles, technologies, and best practices across multiple domains, including cloud security, network security, application security, and data security
Experience with threat modeling, vulnerability management, incident response, and security automation
Comprehensive grasp of security risks and challenges associated with large-scale, complex systems and datasets
Background in building scalable software systems and platforms
Strong communication and collaboration skills, with the ability to succinctly communicate security concerns to mixed audiences
Preferred qualifications
Background in web application development and/or code auditing
Experience with security testing and review of medical or health related applications
Experience with multi-cloud platform applications
Demonstrated contributions to the security community (e.g., publications, presentations, open-source projects)