Manager, Security Engineering Program Manager, Risk & Vulnerability Management, Apple Services Engineering
Summary
Apple Services Engineering (ASE) team is one of the most exciting examples of Apple's long-held passion for combining art and technology! We enable Apple's apps and services, and we do it on an extensive scale, to hundreds of millions of customers in over 35 languages to more than 150 countries. The ASE Security team is seeking an experienced Engineering Program Management leader to build and lead a team of Security Engineering Program Managers supporting our Risk & Vulnerability Management team. Within ASE, you and your team will work with colleagues across Apple to identify, prioritize, and reduce security risk, and to make sure vulnerabilities are remediated quickly and consistently across our services and infrastructure.
As our work is integral to the entire infrastructure stack, you will have the opportunity to work with a wide variety of engineering teams across Apple. We cultivate strong relationships, build trust, and influence without direct authority. We communicate openly and clearly, collaborate enthusiastically, and value a diverse culture of healthy debate. Do these points resonate with you? If so, we want to talk!
Description
As a Security Engineering Program Management leader in ASE, you are both a people leader and a functional expert in security risk and vulnerability management at scale. While working directly with ASE's Risk & Vulnerability Management team, security engineering, and service owners across Apple, you and your team will turn risk and vulnerability data into prioritized, well-run programs that measurably reduce risk. This will include scaling the Vulnerability Management program, driving remediation efforts across the organization, managing the delivery of security controls, guardrails, and frameworks that help protect our customers' data in Apple's infrastructure, and giving leadership clear visibility into our risk posture. This is a hands-on leadership role: you will stay close to the details of your programs while growing a team of program managers and shaping how security risk work gets done across ASE. You and your team will be responsible for identifying, planning, and delivering program security outcomes by engaging a broad set of internal and external stakeholders.
Responsibilities
- Build and lead a team of Security Engineering Program Managers through hiring, coaching, and career development, helping both early-career and experienced team members do their best work.
- Foster an inclusive team culture of accountability and continuous learning, where different perspectives are sought out and valued, with clear priorities, expectations, and regular, actionable feedback.
- Define and operationalize risk and vulnerability management programs, owning end-to-end delivery of multiple concurrent programs, including scope, requirements, timelines, and prioritization.
- Partner with the Risk & Vulnerability Management team and engineering leaders to build roadmaps and turn priorities into executable plans.
- Manage cross-functional dependencies, risks, and changes effectively by optimizing scope, schedule, and resources accordingly.
- Leverage data to identify recurring themes, surface high-impact opportunities to reduce security risk, and drive prioritization.
- Define and report on program health, success metrics, and active progress, including remediation progress and risk reduction over time.
- Develop and own communication plans to proactively share program status, issues, and risk posture with stakeholders at all levels, including senior leadership.
- Build consensus while navigating ambiguity, influencing peers and stakeholders without direct authority.
- Improve how security programs are planned and run across ASE by iterating on processes, frameworks, and metrics that scale.
Minimum Qualifications
- 8+ years of experience in technical program management, including 4+ years managing projects or programs in the field of security, OR a combination of 4+ years of program management and 4+ years in a related field such as security engineering, vulnerability management, risk management, or engineering leadership.
- 3+ years of experience managing people, such as a team of program managers, engineers, or other technical professionals.
- People Leadership: Experience hiring, coaching, and developing team members at different stages of their careers.
- Project Management: Proficiency in managing complex projects, including defining scopes, setting timelines, and coordinating cross-functional teams to ensure timely and successful delivery.
- Risk Management Skills: Ability to use data to identify, assess, and prioritize security risks, and to communicate appropriate mitigation strategies to protect organizational assets.
- Technical Proficiency: A solid understanding of software development, systems engineering, or related technical fields to effectively oversee vulnerability management and remediation programs.
- Education: BS in Computer Science, Computer Engineering or other technical field or equivalent industry experience
Preferred Qualifications
- Build Trust and Influence: Experience fostering collaboration and influencing stakeholders without direct authority to achieve program objectives.
- Communication Skills: Ability to convey complex technical information to both technical and non technical audiences, including executive and senior leadership, with clarity, confidence, and alignment.
- Drive What Matters: Able to focus and simplify, balancing the details with goals, priorities, and trade-offs in mind.
- Experience building or scaling a vulnerability management or security risk management program.
- Familiarity with vulnerability prioritization and risk assessment practices, such as CVSS or similar scoring approaches.
- Experience with cloud security.
- Experience using data visualization tools such as Tableau to report on program health and risk posture.
- Familiarity with applying AI tools to program management or security workflows.
- Experience in talent development, succession planning, or organizational design.
- Industry certifications in security or risk management (e.g., CISSP, CISM, CRISC), or equivalent experience.
Pay & Benefits
At Apple, base pay is one part of our total compensation package and is determined within a range. This provides the opportunity to progress as you grow and develop within a role. The base pay range for this role is between $174,200 and $303,800, and your base pay will depend on your skills, qualifications, experience, and location.Apple employees also have the opportunity to become an Apple shareholder through participation in Apple’s discretionary employee stock programs. Apple employees are eligible for discretionary restricted stock unit awards, and can purchase Apple stock at a discount if voluntarily participating in Apple’s Employee Stock Purchase Plan. You’ll also receive benefits including: Comprehensive medical and dental coverage, retirement benefits, a range of discounted products and free services, and for formal education related to advancing your career at Apple, reimbursement for certain educational expenses — including tuition. Additionally, this role might be eligible for discretionary bonuses or commission payments as well as relocation. Learn more about Apple Benefits
Note: Apple benefit, compensation and employee stock programs are subject to eligibility requirements and other terms of the applicable plan or program.
Apple is an equal opportunity employer that is committed to inclusion and diversity. We seek to promote equal opportunity for all applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, Veteran status, or other legally protected characteristics. Learn more about your EEO rights as an applicant