Senior Security Software Engineer, Software Supply Chain Security
Core
Architecting and owning the software supply chain security platform to model, correlate, and prioritize vulnerability risks across Apple's internal and open-source projects, including those generated by AI coding assistants.
Role type
Senior IC security software engineer (software supply chain)
Builds
A trusted, prioritized picture of software composition analysis (SCA) and vulnerability intelligence for engineering teams and security leadership.
Domain
Software supply chain security, dependency management, and open-source risk.
Required skills
Go, Java, software composition analysis (SCA), vulnerability data sources (NVD, OSV, GitHub Advisories), CI/CD pipelines, cloud/container infrastructure (Kubernetes, AWS), AI coding assistants, SBOM standards, dependency ecosystems (Go Modules, Maven/Gradle)
Preferred skills
CycloneDX, SPDX, cdxgen, syft, Package URL (purl), Open Container Initiative (OCI), SLSA, graph-based data modeling, automated dependency curation, spec-driven development
Technologies
Go, Java, Kubernetes, AWS, NVD, OSV, GitHub Advisories, CycloneDX, SPDX, SLSA
Responsibilities
Shape how software inventory and vulnerability data are modeled and correlated; set the engineering quality bar for the platform; mentor engineers on supply chain risk reasoning; define secure software development practices for AI-generated code.
Seniority
Senior, hands-on IC with technical leadership