AI Systems Security Engineer (Agent Systems), SEAR

Apple Inc.
Cupertino, CA, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Artificial Intelligence Automated Storage and Retrieval Systems Automation of Tests Cyber Security Computer Engineering Distributed Systems Machine Learning Role-Based Access Control Cloud Services Azure Machine Learning Software Engineering Cloud Platform System
+5 more
Large Language Models Integration Tests Information Technology Build Tools Virtual Agents

Job description

Apple’s Security Engineering & Architecture organization protects the systems and experiences used by people around the world. The ML Security Engineering team brings together machine learning, systems security, and product engineering to help ensure that Apple Intelligence and other AI-powered experiences are secure, private, and trustworthy. We are seeking an AI Systems Security Engineer to design, build, and deploy the security foundations for agentic and tool-using AI systems. You will develop the architectural controls that govern how agents access tools, services, memory, user data, and other privileged capabilities-and ensure those controls remain effective when models encounter malicious, untrusted, or adversarial inputs. You will work closely with ML security researchers, AI/ML platform teams, operating-system engineers, product security, privacy, and product teams. Research will identify emerging attacks and promising defenses; you will translate those findings into robust platform capabilities, reusable frameworks, launch requirements, and production protections. Success in this role is measured by security properties that can be enforced, tested, observed, and maintained across shipping systems., Agentic AI systems introduce a new security boundary: probabilistic models interpret untrusted content while making decisions that can affect tools, data, and user-visible state. Securing these systems requires more than model-level safeguards. It requires carefully designed trust boundaries, least-privilege interfaces, execution controls, isolation mechanisms, and defense-in-depth across the complete AI system. In this role, you will own critical elements of that security architecture. You will build systems that mediate agent actions, constrain authority, preserve data and instruction provenance, isolate untrusted execution, and prevent compromised model behavior from becoming unauthorized system behavior. You will also develop the infrastructure needed to validate these protections continuously: adversarial integration tests, security invariants, policy conformance checks, telemetry, deployment gates, and tools for investigating failures. The solutions must meet demanding product requirements for latency, reliability, privacy, debuggability, and compatibility across Apple platforms and services.

Requirements

  • Bachelor’s degree in computer science, computer engineering, security, or a related field, or equivalent practical experience.
  • Significant experience designing and shipping security-critical systems, platform security mechanisms, or large-scale systems software.
  • Strong understanding of security architecture, trust boundaries, least privilege, authorization, isolation, secure execution, and defense-in-depth.
  • Demonstrated ability to convert threat models and security requirements into reliable production implementations.
  • Strong software engineering skills in one or more systems or platform languages, with experience building maintainable, testable, and performance-sensitive software.
  • Experience working across organizational boundaries to influence architecture and deliver security improvements in complex production systems.

Preferred Qualifications

  • Experience securing LLM-based, agentic, tool-using, or other probabilistic AI systems.
  • Experience with capability systems, sandboxing, policy engines, information-flow controls, provenance systems, secure IPC/RPC, or workload isolation.
  • Familiarity with attacks against agent systems, including prompt injection, unauthorized tool use, privilege escalation, data exfiltration, memory poisoning, and multi-stage attacks.
  • Experience building security evaluation infrastructure, fuzzing systems, adversarial test frameworks, runtime monitors, or automated release gates.
  • Experience securing operating systems, distributed systems, application platforms, cloud services, or privacy-sensitive consumer products.
  • Understanding of ML inference systems and the interaction between models, context construction, orchestration layers, retrieval systems, tools, and product code.
  • Ability to evaluate security designs against practical constraints such as latency, availability, privacy, compatibility, and diagnosability.
  • Track record of delivering foundational security mechanisms adopted by multiple products or engineering organizations.
  • Excellent written and verbal communication skills, including the ability to explain subtle security properties to research, engineering, and product audiences.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.techcareers.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

48 sec

Exploring alternative build tools and experimental web components

Sasha Shynkevich · LIVE

3:21 min

Navigating the ethical integration of virtual colleagues

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

2:41 min

Transitioning artificial intelligence infrastructure into scalable commodity cloud services

juarezjunior juarezjunior · WWC 2024

4:15 min

Security integration and AI skepticism in developer tooling

Chris Heilmann +2 · LIVE

2:09 min

Configuring IDEs and build tools for Java 17

Daniel Strmečki · LIVE

1:55 min

Current state of security in AI applications

Deepu Deepu · WWC 2025

Videos

See all

Related articles

See all