> Markdown version of [/jobs/ext/278775-engineering-program-manager-security-infrastructure-apple-services-engineering](https://www.wearedevelopers.com/jobs/ext/278775-engineering-program-manager-security-infrastructure-apple-services-engineering). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Engineering Program Manager, Security Infrastructure, Apple Services Engineering - **Company:** Apple Inc. - **Location:** Seattle, WA, United States - **Experience:** Experienced - **Salary:** $163,300.0 - $290,100.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Systems Engineering, Cloud Computing, Cloud Computing Security, Cyber Security, Red Team (Cyber Security), Software Engineering, Mitre Att&ck, Functional Dependencies, Information Technology - **Published:** May 21, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3e339666eb52c97f ## About the Role Do you have experience in Technical Proficiency?, Do you have a Bachelor's degree?, Proven history of building or scaling an offensive security or red team program. Prior hands-on experience in a penetration testing, red team, or security engineering role. Experience with cloud security and cloud-based attack surfaces. Risk Management Skills: Ability to identify, assess, and prioritize security risks surfaced through offensive testing, and communicate appropriate remediation strategies to protect organizational assets. Build Trust and Influence: Experience fostering collaboration and influencing stakeholders without direct authority to achieve program objectives. Communication Skills: Ability to convey complex technical information to both technical and non-technical stakeholders, ensuring clarity and alignment. Analytical and Problem-Solving Abilities: Strong analytical skills to assess complex security challenges and develop innovative solutions to address them. Drive What Matters: Able to focus and simplify, balancing the details with goals, priorities, and trade-offs in mind. Minimum Qualifications 5+ years of experience managing projects or programs in the field of security. 2+ years of experience working in offensive security, red team operations, or penetration testing. Project Management Expertise: Proficiency in managing complex projects, including defining scopes, setting timelines, and coordinating cross-functional teams to ensure timely and successful delivery. Technical Proficiency: A solid understanding of software development, systems engineering, or related technical fields to effectively oversee offensive security programs and engage credibly with red team engineers. Offensive Security Fluency: Working knowledge of red team operations, penetration testing methodologies, adversary simulation, and common attack frameworks such as MITRE ATT&CK. BS in Computer Science or related technical field or relevant industry experience ## Description As a Security Engineering Program Manager in ASE, you are both a technical and functional expert in the world of offensive security and adversarial testing at scale. While working directly with ASE's red team and engineering partners, you will identify opportunities to strengthen our security posture through targeted adversarial exercises and simulation. This will include driving the end-to-end planning and execution of red team engagements, managing remediation tracking, and working with service owners to develop innovative solutions to complex security challenges. You will be responsible for identifying, planning, and delivering program security outcomes by independently engaging a broad set of stakeholders.","responsibilities":"Operationalize key cross-functional offensive security initiatives and programs that require security domain, systems, and engineering-level knowledge. Manage cross-functional dependencies, risks, and changes effectively by optimizing scope, schedule, and resources accordingly. Create project plans which deliver consistency, clarity, and build alignment across teams. Help influence peers and stakeholders and build consensus while dealing with ambiguity. Develop and own communication plans to effectively and proactively communicate program status, engagement outcomes, and risks to stakeholders. Define and report on program health, success metrics, and active progress of red team engagements and remediation efforts. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [WebAssembly: The Next Frontier of Cloud Computing](https://www.wearedevelopers.com/videos/972-webassembly-the-next-frontier-of-cloud-computing) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)