
Sr. Engineering Program Manager, Security Site Reliability Engineering, Apple Services Engineering
- Seattle, WA
- Permanent
- Full-time
- As a Security SRE Engineering Program Manager in ASE, you are both a technical and functional expert in the world of securing enterprise servers and services at scale. You'll partner with a diverse set of teams across Apple to provide them with groundbreaking secure infrastructure that operates at a substantial scale and uses open-source technologies such as Kubernetes along with proprietary systems. You will work directly with SRE and Engineering teams to deliver security improvements, creative mitigations, and remediation strategies across Apple to exceed our high expectations.
- This is not a task-based job; we are accountable for delivering secure and performant systems. Partnering with program and engineering leaders and teams, you will influence and drive every aspect of software and hardware development and deployment including definition, design, integration, build, qualification, and release processes; identify release blockers and run the implementation and deployment of remediations to development, QA, and production environments both on-premise and in public cloud infrastructure globally.
- You can expect to partner with engineering and other multi-functional teams to identify opportunities to secure our services and machines, to gather input, then deploy and improve those security controls. You will also work closely with other engineering teams to make security-improving changes to their tools, processes, and workflows.
- 8-10 years of proven experience in technical program management in at least one of the following areas: security review, adversarial and/or collaborative testing, detection and response, incident and/or vulnerability management, education, outreach, or automation of testing, tooling, or remediations.
- Experience leading Cloud native Infrastructure programs.
- A BS/MS in Computer Science, Engineering or a similar technical field is preferred.
- Experience in several of the following areas: Software Security Assurance, Application Security, Threat Modeling, Secure Coding Practices, Vulnerability Assessment, Secure Development Lifecycle (SDLC), Security Requirements Analysis, Secure tunneling protocols (IPSec, TLS, Etc.), Secure Architecture Design, Secure Development Tools and Techniques, Certificate-based authentication, encryption, Secure Development Frameworks (e.g., OWASP SAMM), Secure Software Development Methodologies (e.g., Agile, DevSecOps), enterprise server administration and management at scale.
- Outstanding verbal and written communication skills.
- Demonstrated ability to work effectively with and influence multiple collaborators across a highly matrixed, multi- functional organization.
- Strong facilitation skills (requirements sessions, design meetings, progress and status meetings).