Platform Security Engineer - Wallet Payments & Commerce
Summary
The Wallet & Payments Security Solutions team sits at the intersection of developer experience and customer trust, building the foundational security layer that every product in the Apple Pay portfolio depends on. We are a group of security engineers passionate about enabling fast, safe engineering at scale across a modern, Kubernetes-based multi-cloud platform. This role is an opportunity to shape secure-by-default practices across Apple Pay engineering organizations working on Payments, Transit, Access, & Identity products. If you're passionate about security and customer safety, we may have the job for you.
Description
As a Platform Security Engineer on the Wallet & Payments Security Solutions team, you will design, build, and operate security application frameworks and solutions for a Kubernetes-based developer platform spanning multiple cloud providers. You will partner closely with platform and product engineering teams to embed security into every stage of the development lifecycle, ensuring guardrails never become friction. Your work will directly protect Apple customers and the engineers who build the products they rely on every day. Further, as part of this role, you will frequently collaborate with other security engineers and architects across Apple to identify, define and design security solutions which elevate overall security profile of Apple Services.
Responsibilities
- Develop internal frameworks, libraries, tools and processes that make the secure path the easiest path for every engineer on the platform
- Design and implement security frameworks, controls, tooling, and automation for a Kubernetes-based multi-cloud platform serving Wallet & Payments Engineering
- Champion secure-by-default infrastructure patterns and drive adoption of safe engineering practices across the organization without sacrificing developer velocity
- Partner with platform, product, and infrastructure engineering teams to identify security risks and deliver pragmatic mitigations at the architectural level
- Conduct threat modeling of new platform capabilities to incorporate security during early phases of platform development
- Respond to and lead resolution of incidents affecting the security of developer platform, conducting thorough post-incident reviews
- Work AI-forward by using coding agents and LLM-based tooling as a normal part of development, and own the correctness of what you ship regardless of what drafted it.
Minimum Qualifications
- 5+ years of experience in platform security and/or software engineering experience in infrastructure and application development, or a closely related security engineering discipline
- Experience in Go, Kotlin/Java and Spring Framework.
- Familiarity with current and emerging security architecture design for cloud environments
- Ability to communicate thoughtfully and clearly, both verbally and in writing, to discuss complex technical concepts with diverse audiences, including global teams.
- Passion for developer enablement and building "security as a product"
- Ability to influence engineering culture through documentation, advocacy, and cross-team collaboration rather than mandate alone
- The tenacity and perseverance to drive a complex project all the way from conception to production.
- BS in Computer Science or equivalent experience/skills in application development and security.
Preferred Qualifications
- Prior experience contributing to or driving a secure-by-default platform initiative across a large engineering organization
- Experience with Identity and Access management frameworks
- Deep expertise in Kubernetes security, including RBAC, admission control, pod security standards, network policy, and workload identity
- Experience designing and implementing security controls across at least two major cloud providers
- Experience hardening containers and orchestration: image provenance, admission control, runtime and network policy, service mesh configuration, and clean isolation across micro services
- Experience with Supply Chain Security and optimizing Vulnerability management loop.
- Identity protocols and applied cryptography in practice: OAuth2, OIDC, JWT, SAML, mutual TLS, PKI , encryption and signing primitives.
- Fluency with coding agents and LLM-based development tooling, and judgment about when to trust their output.