Architect, Perimeter and Network Security, Enterprise Technology Services
Core
Architecting Apple's perimeter and network security platform to protect services at scale across edge proxies, load balancers, service mesh, and API/AI gateways.
Role type
Senior IC Security Architect (Perimeter & Network)
Builds
Scalable security defenses including WAF, DDoS mitigation, bot prevention, TLS management, and real-time threat intelligence.
Domain
Cybersecurity, Network Infrastructure, Cloud Security
Required skills
Perimeter security architecture, WAF design, DDoS mitigation, Bot detection, TLS/mTLS, TCP/IP, HTTP/HTTPS, Proxy technologies (NGINX, Envoy, HAProxy), IP networking (BGP, NAT), Orchestration/control plane design, Java/J2EE, Cloud architecture (GCP, AWS)
Preferred skills
Proxy engine internals (C, C++, Lua, WASM), Auth/Authorization frameworks (OAuth, mTLS), Service mesh (Istio), Containerization (Kubernetes), IaC (Terraform), Distributed systems design, Real-time data pipelines, Observability, OWASP threat models
Technologies
NGINX, Envoy, HAProxy, Java, GCP, AWS, Kubernetes, Docker, Terraform, Ansible, Istio, QUIC, DNS
Responsibilities
Define long-term security architecture and roadmap for perimeter defenses. Design WAF rule engines, DDoS mitigation, and bot detection systems. Own architecture across edge, origin, service mesh, and API gateways. Lead technical design reviews and establish security standards. Mentor senior engineers through design collaboration and code reviews. Represent security perspective in cross-organizational forums.
Seniority
Senior, hands-on IC
