At a Glance
- Tasks: Join the ACOS team to build secure software for Apple's cloud infrastructure.
- Company: Be part of Apple, a leader in technology and innovation.
- Benefits: Competitive salary, health benefits, and opportunities for remote work.
- Other info: Collaborative environment focused on continuous learning and career growth.
- Why this job: Make a real impact on security at scale while working with cutting-edge technology.
- Qualifications: Strong backend software engineering skills and knowledge of security concepts required.
The predicted salary is between 60000 - 80000 £ per year.
Join the Apple Cloud Object Store (ACOS) team as a Software Engineer with a focus on security. The ACOS team, which is part of Apple Services Engineering organisation, is one of the most critical infrastructure teams at Apple, storing and serving petabytes of data across Apple's services. The ASE organization builds and operates the cloud infrastructure underpinning Apple's services, bringing together compute, storage, networking, and security into a unified Apple Cloud platform. In this role you'll work at the intersection of distributed systems engineering and security — building the authentication, authorisation, and encryption foundations that protect data at exabyte scale.
The security challenges in a large-scale cloud object store are deep and varied. You will work on problems such as:
- Designing and evolving authentication systems to meet modern security standards.
- Implementing and improving encryption-at-rest schemes with robust key lifecycle management at scale.
- Building IAM policy enforcement at high throughput.
- Driving compliance for a multi-region storage platform.
- Conducting threat modeling for a system handling hundreds of thousands of requests per second.
You'll also contribute to broader storage engineering work — durability, availability, multi-tenancy, and performance — making this a well-rounded SWE role with a security-first mindset.
Responsibilities
- Join a highly collaborative team that values mutual support and security-first engineering.
- Own and contribute to security infrastructure projects across authentication, authorisation, and encryption — building platforms that the rest of the storage org consumes.
- Implement and evolve authentication systems to meet modern security standards: improving credential security, integrating with other Apple services, and ensuring consistent auth across storage products.
- Build and maintain encryption-at-rest infrastructure: key lifecycle management, encryption standard upgrades, and ensuring cryptographic coverage at scale.
- Participate in threat modeling for new and existing features; embed security reviews into the design and launch process.
- Identify, scope, and lead projects that span security, reliability, isolation, scalability, and maintainability — this is a broad SWE role, not a pure security role.
- Work across teams to identify improvement areas, build consensus, and participate in roadmap and security planning discussions.
- Collaborate with Apple's Security and Privacy orgs, serving as the storage org's point of contact for security matters.
Minimum Qualifications
- Solid backend software engineering experience with strong computer science fundamentals: networking, distributed systems, and security concepts.
- Good understanding of authentication and authorisation: familiarity with protocols such as SigV4, OAuth2, mTLS, or IAM-style policy systems.
- Understanding of cryptographic fundamentals: symmetric encryption, key hierarchies, certificate management, or secret management systems.
- Experience driving complex projects end-to-end and collaborating across teams.
Preferred Qualifications
- Experience with IAM systems, STS/short-lived credentials, or policy-based access control.
- Hands-on experience with encryption infrastructure: key rotation, envelope encryption, or integrating with secret managers (HashiCorp Vault, AWS KMS, or equivalent).
- Familiarity with compliance frameworks such as PCI-DSS or SOX in a cloud infrastructure context.
- Experience with threat modeling methodologies or conducting security design reviews.
Software Engineer, Security employer: Omaze
Contact Detail:
Omaze Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Software Engineer, Security
✨Tip Number 1
Network like a pro! Attend tech meetups, conferences, or online webinars related to software engineering and security. It's a great way to meet industry folks and get your name out there.
✨Tip Number 2
Show off your skills! Work on personal projects or contribute to open-source software that showcases your expertise in security and distributed systems. This can really make you stand out during interviews.
✨Tip Number 3
Prepare for those technical interviews! Brush up on your coding skills and be ready to discuss your approach to security challenges. Practising with mock interviews can help you feel more confident.
✨Tip Number 4
Don't forget to apply through our website! We love seeing candidates who are genuinely interested in joining our team. Plus, it gives you a chance to showcase your enthusiasm for the role.
We think you need these skills to ace Software Engineer, Security
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights your backend software engineering experience and security knowledge. Use keywords from the job description to show that you understand what we're looking for.
Showcase Your Projects: Include specific examples of projects where you've tackled authentication, authorisation, or encryption challenges. We love seeing how you've driven complex projects end-to-end!
Be Clear and Concise: When writing your application, keep it clear and to the point. We appreciate straightforward communication, so avoid jargon unless it's relevant to the role.
Apply Through Our Website: Don't forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for the role. We can’t wait to see what you bring to the table!
How to prepare for a job interview at Omaze
✨Know Your Security Fundamentals
Make sure you brush up on your knowledge of authentication and authorisation protocols like OAuth2 and mTLS. Being able to discuss these concepts confidently will show that you understand the core security principles that are crucial for the role.
✨Showcase Your Project Experience
Prepare to talk about complex projects you've driven from start to finish, especially those involving security or distributed systems. Highlight your collaboration with other teams and how you navigated challenges, as this will demonstrate your ability to work in a highly collaborative environment.
✨Familiarise Yourself with Compliance Frameworks
Since compliance is a big part of the role, it’s a good idea to have a basic understanding of frameworks like PCI-DSS or SOX. Be ready to discuss how you’ve applied these in past projects or how you would approach compliance in a cloud infrastructure context.
✨Prepare for Technical Questions
Expect technical questions related to encryption, key management, and threat modelling. Practise explaining your thought process clearly and concisely, as this will help you convey your problem-solving skills effectively during the interview.