Architect, Perimeter and Network Security, Enterprise Technology Services
Job in
Sunnyvale, Santa Clara County, California, 94085, USA
Listed on 2026-06-02
Listing for:
Apple Inc.
Full Time
position Listed on 2026-06-02
Job specializations:
-
IT/Tech
Cybersecurity, Systems Engineer, Network Security, Cloud Computing
Job Description & How to Apply Below
0026T specializes in building forward-looking, extremely scalable systems and solutions in two areas:
Information Security and general-purpose, reusable platforms in the space of Integration and Orchestration. The team has a passion for solving challenging problems, exploring new domains, and engineering transformational solutions. We operate with a startup mindset - lean teams, high ownership, and technical leaders who flex across domains to build and scale new capabilities.
The Emerging Technologies team is seeking an industry-recognized Architect to serve as the domain expert for Apple's perimeter and network security platform. You will be the technical authority across the full traffic path - edge proxies, origin/application load balancers, service mesh, and API u0026 AI security gateways - architecting the defenses that protect Apple's services are looking for someone who brings deep, proven expertise in perimeter security, threat mitigation, and proxy technologies - a technical leader whose experience and reputation precede them.
In this role, you will own the architecture and technical direction of the systems that deliver Apple's security capabilities - WAF protection against OWASP threats, DDoS mitigation, Bot Prevention, TLS termination/origination, real-time threat intelligence, and security policy enforcement across protocols (TCP, UDP, HTTP/HTTPS). These capabilities are powered by L4/L7 proxy runtimes and a Java-based orchestration platform that manages configuration, policy distribution, and lifecycle management at fleet scale.
You will define the long-term security architecture vision, drive technically complex initiatives end-to-end, and shape how these systems evolve across on-premises data centers and public cloud environments (GCP, AWS), ensuring Apple's defenses remain resilient, adaptive, and secure as threats and scale grow. This is a deeply technical, hands-on role for a recognized industry expert. You are expected to write code, prototype solutions, lead design efforts, and raise the technical bar for the entire team - not through management authority, but through expertise, influence, and the quality of your work.
This role is also deeply cross-functional - you will partner with Apple's security and cloud infrastructure teams to drive a unified security vision, and work directly with application teams across the company to understand their traffic patterns and solve their integrated security needs.
Experience with proxy engine internals - C, C++, Lua, or WASM-based customization of NGINX, Envoy, or similar engines for implementing security controls in the runtime data path. Deep knowledge of authentication/authorization frameworks (OAuth, mTLS, certificate management) and secure software development lifecycle practices.
Experience with service mesh architectures (Istio, Envoy-based), API u0026 AI security gateway patterns, containerization (Kubernetes, Docker), and infrastructure-as-code (Terraform, Ansible). Expertise in distributed systems design patterns - consensus protocols, eventual consistency, data replication, and partition tolerance trade-offs. Experience designing real-time data pipelines and event-driven architectures for threat intelligence or security telemetry wledge of observability at the platform level - designing systems for meaningful security logging, metrics, distributed tracing, and alerting.
Familiarity with OWASP threat models, CVE analysis, threat landscape trends, and security incident response from an engineering perspective. Comfortable working across Java, Python, Go, and scripting languages as the problem demands. Recognized industry expertise in perimeter/network security - demonstrated through contributions to open-source security projects, conference talks, or a track record at companies operating security infrastructure at internet scale. Named inventor or co-inventor on granted patents or…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×