Senior Security Software Engineer, Software Supply Chain Security

Apple Inc

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Seattle, WA
Salary
$175,000–$308,500 / yr
Posted
15 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $183k
This role $242k
$112k most similar roles pay here $330k

This role pays more than 93% of similar roles. Most pay $151,475–$214,250 — the shaded band above. At the midpoint, this role pays about $242k versus about $183k for comparable roles.

Based on 240 similar postings.

Employer

About Apple Inc

Apple Inc. is a multinational technology company known for designing and manufacturing consumer electronics, software, and online services, including the iPhone, Mac, iPad, and App Store. Industry: Consumer Electronics & Software

Apple Inc currently has 1984 open roles on FindRole.

Listed pay typically runs $175,000–$277,600 across 1590 roles with salary data.

Most-posted roles

View all roles at Apple Inc

At a glance

TL;DR · Senior Security Software Engineer, Software Supply Chain Security

Senior Security Software Engineer, Software Supply Chain Security joins the Dependency Risk & Automation Team within Apple Services Engineering. This senior role involves taking technical ownership of software composition analysis and vulnerability intelligence to manage risks across a heterogeneous estate of projects. You will model and correlate software inventory data, set engineering quality standards, and mentor team members on supply chain risk. The work addresses challenges posed by AI coding assistants and automated dependency choices. Key technologies include Go, Java, Maven, Gradle, and Go Modules, alongside tools for SBOM standards like CycloneDX and SPDX, and vulnerability feeds such as NVD and OSV. You will also navigate CI/CD pipelines, Kubernetes, and AWS infrastructure while managing risks related to OCI images, SLSA attestations, and graph-based data modeling to ensure actionable security signals for internal engineering teams.

What you'll do

  • Model and correlate software inventory and vulnerability data across a large, heterogeneous estate of projects.
  • Transform raw vulnerability feeds into prioritized, actionable security signals for engineering teams.
  • Define security standards and architectural requirements for managing dependencies introduced by AI coding assistants.
  • Develop automated systems to manage dependency curation and allow-listing at scale.
  • Lead the technical architecture and design decisions for software composition analysis (SCA) platforms.
  • Mentor engineers on how to identify, analyze, and mitigate software supply chain risks.
  • Integrate SBOM standards and vulnerability data into internal build systems and CI/CD pipelines.

What we're looking for

  • 8+ years of experience in security software engineering with ownership of a system or platform and experience in supply chain security, dependency management, and OSS risk.
  • Deep proficiency in Go and strong proficiency in Java, including their respective dependency ecosystems like Go Modules and Maven/Gradle.
  • Experience with SBOM standards, SCA tooling, and vulnerability data sources to turn raw feeds into prioritized signals.
  • Track record of technical leadership, including driving architecture decisions, setting direction for teams or platforms, and mentoring other engineers.
  • Experience with software delivery pipelines (CI/CD, build systems) and cloud/container infrastructure such as Kubernetes or AWS.
  • Practical experience with AI coding assistants or agentic development tools and an understanding of AI-specific supply chain risks.
  • Familiarity with specific SBOM formats (CycloneDX, SPDX), purl standards, OCI image concepts, and SLSA attestations (preferred).
  • Experience with graph-based data modeling, automated dependency curation systems, and spec-driven development workflows (preferred).

More like this

Similar roles

Senior Software Engineer, Security

Apple Inc

Seattle, WA 7 days ago $175,000$308,500
Python Go Java LLM Prompt Engineering CI/CD Distributed Systems gRPC Bash Linux macOS Containerization Data Pipelines Dynamic Analysis Artifact Signing Threat Modeling Taint Analysis
10+ yrs exp

Senior Security Engineer

Apple Inc

Seattle, WA 21 days ago $175,000$308,500
Threat Modeling Python Java Go Swift Kubernetes Cloud-Native Architecture Distributed Systems Container Orchestration Artificial Intelligence Machine Learning Security Review Vulnerability Discovery Multi-tenant System Design
10+ yrs exp

Senior Security Engineer

Apple Inc

Seattle, WA 149 days ago $175,000$263,300
AI/ML LLM Vector Databases Prompt Injection Threat Modeling Security Assessment Cloud-Native Automation MCP A2A Data Leakage
5+ yrs exp

Senior Security Engineer

Apple Inc

Cupertino, CA 149 days ago $184,700$277,600
AI/ML LLM Vector Databases Prompt Injection Threat Modeling Cloud-Native Security Assessment Automation MCP A2A
5+ yrs exp

Software Supply Chain Security Engineer

State Street

Quincy, MA 8 days ago $120,000$202,500
AppSec DevSecOps CI/CD Software Supply Chain Security JFrog Artifactory Maven Central PyPI SLSA Java Python .Net Node.js AWS Azure Ansible Terraform Kubernetes Infrastructure as Code Agile
10+ yrs exp

Software Supply Chain Security Engineer

State Street

Quincy, MA +3 45 days ago $90,000$157,500
AppSec DevSecOps Software Supply Chain Security CI/CD JFrog Artifactory Maven Central PyPI SLSA Java Python .Net Node.js AWS Azure Ansible Terraform Kubernetes Infrastructure as Code Agile
6+ yrs exp