Senior System Security Software Engineer, Platform Attestation

Washington, WA, US • Posted 1 day ago • Updated 5 hours ago
Full Time
On-site
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • System Security
  • Software Engineering
  • Privacy
  • Cloud Computing
  • Data Centers
  • Expect
  • FOCUS
  • C
  • C++
  • Cryptography
  • PKI
  • Hierarchical Storage Management
  • Authentication
  • Embedded Systems
  • Manufacturing
  • Firmware
  • ARM
  • System On A Chip
  • Management
  • Microcontrollers
  • Computer Hardware
  • Swift
  • Objective-C

Summary

The cloudOS System Software Engineering team is at the forefront of developing secure server software and is responsible for building the Apple Silicon server platform that powers Private Cloud Compute. We own the trust boundary between the physical hardware in our data centers and the services that run on it: before a node can serve a user request, we cryptographically prove its authenticity and integrity. We are looking for an exceptional security engineer with experience architecting and developing low-level, secure software to build new technologies to support Apple's product security and customer privacy principles.

In this role, you will be part of a team that builds and maintains system software such as kernel drivers, runtime libraries, frameworks, and daemons, and you will own the attestation architecture for the server platform. You will bring new chassis designs into attestation from the ground up, defining what is measured, how component identities are sealed during manufacturing, and how they are verified after deployment. And you will build the services that turn those measurements into one authoritative answer to whether every machine in our data centers is in a known good state.

The right candidate will have a successful track record of securing compute platforms and building end-to-end security solutions. You should have a strong mix of educational and practical experience, be comfortable working from silicon and firmware up through the services that verify them, and have a passion for diving head first into challenging problems.

Description

You will work cross-functionally with security teams throughout Apple as well as system software, platform design, SOC architects, manufacturing, data center operations, and cloud services teams to develop and integrate best in class hardware, software, and services. You will be responsible for the security of the platform that powers the next generation of data centers.

This position requires someone with strong technical strengths and an enthusiastic drive to secure systems by showing how they can be broken. Our controls have to hold against a remote attacker and against someone with physical access to a chassis who wants a modified machine to look genuine.

We are a dynamic, growing team spanning many disciplines, and we expect members to be willing to step out of their comfort zones to contribute to team objectives. A successful engineer in this role is one that is happy to have a wide breadth of influence as well as deep focus areas in the context of a rapidly evolving project.

Minimum Qualifications

7+ years of experience.

Proficiency in C/C++.

Background in developing and maintaining code security-critical codebases.

Understanding of applied cryptography, cryptography hardware, and key management, including PKI and HSM-backed certificate issuance.

Experience with mutual authentication and hardware-based attestation, including Secure Boot, firmware measurement, and challenge-response protocols.

Strong understanding of hardware/software interactions and low-level software.

Preferred Qualifications

Background in definition and design of secure embedded systems, and in bringing new hardware platforms from manufacturing into production.

Experience with server component firmware, such as ARM SoC architecture, baseboard management controllers, system-management microcontrollers, and power delivery.

Understanding of past, current, and emerging security exploit types targeting low-level systems, including physical and insider attacks on data center hardware.

Experience building and operating production services that verify security posture across a large fleet and detect drift over time.

Experience with Swift, Objective-C, and Apple development tools.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 90733111
  • Position Id: 40394ae8ce61ed21cb40e261dbf0ff25
  • Posted 1 day ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Washington

•

Today

Full-time

No location provided

•

Today

Full-time

USD 499,000.00 - 900,000.00 per year

Redmond, Washington

•

Today

Full-time

USD 130,000.00 - 165,000.00 per year

Redmond, Washington

•

Today

Full-time

USD 142,800.00 - 274,800.00 per year

Search all similar jobs