Senior Network Security Engineer, Infrastructure Services

AppleTexas, United StatesOn-siteFull-timeSenior, 5–8 yearsListed 1 hour ago

Apply now

About this role

Do you want to help build some of the largest and most consequential enterprise and customer technology systems in the world? Join Apple’s Information Systems and Technology (IS&T) organization.
IS&T is the engine behind everything Apple does for customers and for the people who build for them. It’s Apple’s central nervous system. Supporting 2.5 billion active Apple devices, processing billions of secure transactions, and keeping the technology that defines modern life running flawlessly, IS&T makes the impossible feel effortless.”

Do you love building solutions to handle global complexity and immense scale? Imagine what you could do here.

Infrastructure Services is part of IS&T and the foundation of Apple's global network operations — managing data center equipment and systems to deliver compute, storage, and networking services for teams across Apple, including its internal developer community. From individual facilities to a worldwide network, Infrastructure Services ensures the technology underneath everything works without question.

This is a hands-on engineering role spanning design, deployment, automation, and deep troubleshooting, where a single tunnel or site outage can stop a supply chain, a launch, or a partner integration. As a Senior Network Security Engineer, you will partner across software, hardware product teams, infrastructure, architecture, AIS, Operations, and security teams to design, engineer, and continuously improve resilient enterprise network services.

As Apple evolves toward Zero Trust and modern secure access architectures, you will help design multi-profile VPN services, scale partner and remote site connectivity, and build automation and agentic AI-driven workflows that transform from reactive support to predictive, self-healing engineering. Through curiosity, engineering innovation, and intelligent automation, you will continuously improve service reliability, security posture, and the end-user and partner experience at global scale.

We're looking for engineers who are naturally curious, take end-to-end ownership, and solve complex problems through engineering rather than operational workarounds. Successful candidates thrive in collaborative environments, embrace continuous learning, challenge conventional approaches, and leverage software, automation, observability, and AI to build intelligent, resilient, and scalable network services that deliver exceptional user experiences.

very day, Apple’s global remote access, VPN, and secure WAN infrastructure powers critical operations across Apple product engineering teams, Corporate users, retail footprint, manufacturing facilities, and external partner ecosystems. At this scale, a single degraded tunnel, routing misconfiguration, or remote site outage can stall a product launch, halt a supply chain, or disrupt a business-critical integration. You will be the engineer closest to that reality—Engineering, Reliability and operation resilient network security services across Cisco, Palo Alto Networks, and Fortinet platforms where reliability is paramount.

This role sits at the intersection of network security Engineering, Reliability, global edge connectivity, and intelligent automation. You will advance our Zero Trust journey by engineering scalable multi-profile VPN services, designing resilient hybrid SD-WAN fabrics, and establishing secure connectivity for remote facilities, 3PL logistics sites, and third-party partners. Just as importantly, you will eliminate operational toil by applying software engineering, infrastructure as code, and agentic AI workflows to evolve our systems from reactive troubleshooting into predictive, self-healing platforms.

Minimum Qualifications

8+ years of enterprise experience designing, deploying, and operating global network security, routing, Switching, remote access VPN, and WAN/SD-WAN architectures.
Deep firewall & edge platform expertise: Hands-on mastery of Cisco ASA / Firepower, Palo Alto Networks Firewalls, and Fortinet (FortiGate / FortiOS), including security policy architecture, NAT, NAT64 and platform lifecycle management.
Large-scale Remote Access & Zero Trust: Proven track record engineering multi-profile SSL and IPsec remote access services (split/full tunnel, device posture, per-app VPN) and integrating with modern ZTNA/SSE architectures.
Advanced IPsec & Site-to-Site Connectivity: Deep expertise in IKEv1/IKEv2, PKI/certificate authentication, crypto suites, VTI, DMVPN/FlexVPN, and resilient tunnel architecture for Client to site VPN, partners, 3PLs, and remote sites.
Complex Routing & WAN Edge: Advanced BGP and OSPF routing design across hybrid WAN/SD-WAN environments, including carrier peering, traffic engineering (communities, AS-path manipulation), VRF route-leaking, and L2/L3 segmentation.
Identity & Access Management Integration: Strong experience integrating network access with enterprise IAM systems—RADIUS, TACACS+, SAML/SSO, MFA, PKI certificate lifecycle, 802.1X, and NAC.
End-to-End Troubleshooting & Telemetry: Exceptional packet-level diagnostic skills (pcap, flow analysis, debugs, MTU/path latency issues) across security policies, overlay/underlay networks, and application layers.
Infrastructure Automation & Modern Tooling: Demonstrated proficiency automating network security provisioning and validation using Python, REST APIs, Ansible, or Terraform, with bonus experience leveraging AI/LLM-assisted workflows for operations and triage.

Preferred Qualifications

Bachelor's degree in Computer Science, Information Technology, Computer Engineering, Electrical Engineering, or a related technical discipline, or equivalent practical experience
Professional-level network security certifications, such as CCNP Security, PCNSE (Palo Alto Networks), JNCIP-SEC (Juniper), or equivalent demonstrated expertise.
Experience leading large-scale network migrations, such as transitioning legacy VPN and MPLS footprints toward modern Zero Trust (ZTNA), SASE, or SD-WAN architectures.
Background in hybrid cloud networking (AWS, Azure, or GCP), including cloud edge firewalls, transit architectures, and dedicated interconnects (Direct Connect / ExpressRoute).
Track record of applying software engineering and emerging AI/agentic workflows (Python, CI/CD, IaC, GenAI, Claude) to automate security provisioning and eliminate operational toil.
History of cross-functional technical leadership, with experience driving SLO-based reliability, security standards, and operational excellence beyond your immediate team.