Senior Detection Creation Engineer

Apple onsite • Seattlefull_time
The people here at Apple don’t just craft products — they build the kind of wonder that revolutionizes entire industries. It’s the diversity of those people and their ideas that inspires the innovation that runs through everything we do, including our approach to security. Join Apple, and help us protect the services that billions of customers rely on every day. The Detection team within Apple Services Engineering (ASE) is responsible for building advanced detections that protect approximately three-quarters of Apple’s systems and services. We achieve this by partnering closely with engineering teams to develop a deep technical understanding of how these systems operate, along with a comprehensive grasp of the threat landscape. This allows us to build state-of-the-art security detections that proactively defend against real-world attacks. We’re looking for a Detection Creation Engineer who combines deep security intuition with technical implementation skills. In this role, you’ll craft detection logic that catches active malicious activity across Apple’s infrastructure. You’ll need to think like an attacker, understand how malicious behaviors manifest in telemetry data, and translate that knowledge into high-fidelity detections that protect our customers. This is a hands-on technical role where you’ll write detection code in Scala Spark (Databricks notebooks) and configuration files for on-host detection systems (such as Falco rules). While we don’t require prior Scala experience, we do expect strong programming fundamentals and the curiosity to dive deep into new technologies. If you’re passionate about understanding attacker tradecraft and translating that knowledge into defensive capabilities, we’d love to hear from you!