Senior Network Security Engineer, Infrastructure Services - Jobs - Careers at Apple
- Engineer Zero Trust Multi-Profile VPN Services
- Design and scale multi-profile VPN architectures that advance Apple's Zero Trust journey, securing access across diverse user populations, device postures, and business functions.
- Design Resilient Hybrid SD-WAN Fabrics
- Architect and deploy resilient hybrid SD-WAN infrastructure that delivers secure, reliable connectivity for remote facilities, 3PL logistics sites, and third-party partner locations globally.
- Establish Secure Connectivity for Partners & Remote Sites
- Build and operationalize secure connectivity solutions for remote facilities, supply chain partners, and third-party integrations, ensuring consistent security posture across the ecosystem.
- Drive Automation & Agentic AI to Eliminate Operational Toil
- Apply software engineering, infrastructure as code, and agentic AI-driven workflows to transform reactive troubleshooting into predictive, self-healing systems, reducing manual effort and operational risk.
- Serve as Technical Interface & Trusted Advisor Across Teams
- Act as the key technical liaison across IS&T, GNS partners, Hardware and Software Product Engineering, InfoSec, and external carriers, guiding product teams through critical launch cutovers and strategic partner onboarding.
- Own End-to-End Reliability & Architectural Standards
- Take complete ownership of the infrastructure lifecycle, from deep packet-level troubleshooting to permanent architectural fixes, while authoring design standards, site templates, and runbooks that enable repeatable, global operations.
- 8+ years of enterprise experience designing, deploying, and operating global network security, routing, Switching, remote access VPN, and WAN/SD-WAN architectures.
- Deep firewall & edge platform expertise: Hands-on mastery of Cisco ASA / Firepower, Palo Alto Networks Firewalls, and Fortinet (FortiGate / FortiOS), including security policy architecture, NAT, NAT64 and platform lifecycle management.
- Large-scale Remote Access & Zero Trust: Proven track record engineering multi-profile SSL and IPsec remote access services (split/full tunnel, device posture, per-app VPN) and integrating with modern ZTNA/SSE architectures.
- Advanced IPsec & Site-to-Site Connectivity: Deep expertise in IKEv1/IKEv2, PKI/certificate authentication, crypto suites, VTI, DMVPN/FlexVPN, and resilient tunnel architecture for Client to site VPN, partners, 3PLs, and remote sites.
- Complex Routing & WAN Edge: Advanced BGP and OSPF routing design across hybrid WAN/SD-WAN environments, including carrier peering, traffic engineering (communities, AS-path manipulation), VRF route-leaking, and L2/L3 segmentation.
- Identity & Access Management Integration: Strong experience integrating network access with enterprise IAM systems—RADIUS, TACACS+, SAML/SSO, MFA, PKI certificate lifecycle, 802.1X, and NAC.
- End-to-End Troubleshooting & Telemetry: Exceptional packet-level diagnostic skills (pcap, flow analysis, debugs, MTU/path latency issues) across security policies, overlay/underlay networks, and application layers.
- Infrastructure Automation & Modern Tooling: Demonstrated proficiency automating network security provisioning and validation using Python, REST APIs, Ansible, or Terraform, with bonus experience leveraging AI/LLM-assisted workflows for operations and triage.
- Bachelor's degree in Computer Science, Information Technology, Computer Engineering, Electrical Engineering, or a related technical discipline, or equivalent practical experience
- Professional-level network security certifications, such as CCNP Security, PCNSE (Palo Alto Networks), JNCIP-SEC (Juniper), or equivalent demonstrated expertise.
- Experience leading large-scale network migrations, such as transitioning legacy VPN and MPLS footprints toward modern Zero Trust (ZTNA), SASE, or SD-WAN architectures.
- Background in hybrid cloud networking (AWS, Azure, or GCP), including cloud edge firewalls, transit architectures, and dedicated interconnects (Direct Connect / ExpressRoute).
- Track record of applying software engineering and emerging AI/agentic workflows (Python, CI/CD, IaC, GenAI, Claude) to automate security provisioning and eliminate operational toil.
- History of cross-functional technical leadership, with experience driving SLO-based reliability, security standards, and operational excellence beyond your immediate team.
Apple is an equal opportunity employer that is committed to inclusion and diversity. We seek to promote equal opportunity for all applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, Veteran status, or other legally protected characteristics. Learn more about your EEO rights as an applicant
At Apple, we believe accessibility is a fundamental human right. You’ll find that idea reflected in everything here — in our culture, our benefits and our digital tools. By welcoming as many perspectives as possible, we help you build a career where you feel like you belong.
Learn about accessibility in Apple’s workplace
Learn about reasonable accommodations for job applicants
Apple accepts applications to this posting on an ongoing basis.
Required Skills
Required Languages
🇬🇧 English