A Platform Engineer is responsible for the development of platforms that support the needs and use cases of different engineering teams across the organization. Creates reusable tools and workflows to streamline operational needs and facilitate automation tasks, supporting scalability of DevOps practices.
Platform Architecture Security Team Beaverton, Oregon, United States Hardware Summary Posted:
Sep 04, 2026
Role Number:
200681859-0505 At Apple, our Platform Architecture group is responsible for connecting our hardware, software, and servers into one unified system. You'll join a team of architects who are dedicated to securing the world's most advanced consumer devices. Our products are trusted for storing personal data, and our goal is to ensure cutting-edge safeguards for our users. The services our team supports exist to make those products secure: they establish the trust each device depends on, from the factory floor through every day in a customer's hands. We're looking for dedicated and inspired individuals to help improve on the security of Apple's products. Description In this role, you will define the architecture and oversee the operation of distributed systems that set and enforce security policy for the development, manufacture, deployment, and operation of Apple products, ultimately driving continuous security improvements for these products. This role is largely self-directed and suits an engineer with deep hands-on experience building and operating secure systems who is ready to grow into an architectural role. Responsibilities Define the security requirements and drive the security architecture for the distributed systems that set and enforce Apple's product security policy. Identify emerging threats and develop threat models for those services. Manage the security policy enforced by those services, reasoning about how they interact with Apple products to ensure end-to-end security guarantees are upheld. Build prototypes and tooling to validate security designs and automate policy enforcement. Lead cross-functional teams throughout the service lifecycle, from design through deployment and operation, to resolve system-level issues without sacrificing security or compromising availability and performance. Use a wide range of interpersonal and technical skills to champion robust security design and best practices across the teams that build and operate those services. Leverage strong written and oral communication skills to partner with engineering teams, demonstrating the confidence to advocate for security requirements even under pressure. natural curiosity and a problem-solving mindset to tackle unfamiliar systems and ambiguous project scopes, adapting quickly to keep security initiatives moving forward. Minimum Qualifications Bachelor's degree in Computer Science, Computer Engineering, related engineering degree or equivalent job-related experience. Experience applying security practices to the design, development, or operation of production services. Experience with common programming languages such as Python or Go. Experience conducting security architecture reviews, threat modeling, or identifying vulnerabilities in complex distributed systems. Experience with cryptography and security protocols, including at least two of the following: PKI, TLS, Key Management, Secure Boot, or Authentication/Authorization. Preferred Qualifications 10+ years of relevant industry experience. Ability to understand complex systems, employing strong critical thinking skills to identify security issues in implementation and architecture. Knowledge of cryptographic principles (e.g., symmetric vs asymmetric crypto, confidentiality vs integrity) and technologies such as authentication and authorization, key management, TLS, certificate lifecycle management, secure boot, and PKI. Experience designing and developing secure services and scalable infrastructure for highly available applications, such as distributed systems, micro-services, and cloud platforms. Familiarity with, or practical application of, threat modeling methodologies such as STRIDE or Trike. DevOps experience, such as continuous integration/continuous deployment (CI/CD), infrastructure as code (IaC), or automation of development, testing, and deployment pipelines. Ability to track emerging security trends and threats and proactively incorporate them into PKI architecture and signing policy to stay ahead of evolving risks. Experience with systems programming languages such as C or C++. Apple is an equal opportunity employer that is committed to inclusion and diversity. We seek to promote equal opportunity for all applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, Veteran status, or other legally protected characteristics. At Apple, we believe accessibility is a fundamental human right. You'll find that idea reflected in everything here — in our culture, our benefits and our digital tools. By welcoming as many perspectives as possible, we help you build a career where you feel like you belong. Apple accepts applications to this posting on an ongoing basis.