AI & Data Security Engineer

Apple Apple · Big Tech · Austin, TX +2 · Sales and Business Development

This role focuses on securing data throughout the AI lifecycle, including data classification, access control, model deployment, and agentic applications. The engineer will design and enforce security policies, lead red team exercises, and develop security standards for AI products.

What you'd actually do

  1. Design and implement security architecture for AI use cases, ensuring secure data access and usage through role-based access controls and authorized provisioning.
  2. Ensure AI use cases are aligned with Apple’s data classification standards, including appropriate data handling, storage, retention requirements and access controls.
  3. Implement and manage user id and persona based row-level security policies for data stored in Snowflake and other data systems connected to US applications.
  4. Design and implement API-based security controls for AI applications, including authentication, authorization and data access policies to protect sensitive information and ensure compliant data consumption.
  5. Lead adversarial testing of AI systems to identify vulnerabilities, drive remediation, and safeguard Apple data from misuse and malicious activity.

Skills

Required

  • Python
  • Java
  • Go
  • Snowflake
  • Databricks
  • RBAC
  • row-level security
  • column-level security
  • API security
  • OAuth2
  • OIDC
  • SAML
  • JWT
  • GDPR
  • CCPA
  • security logging
  • audit trails
  • monitoring solutions

Nice to have

  • AI/ML Security Expertise
  • LLM-powered applications
  • autonomous AI agents
  • RAG architectures
  • prompt injection
  • red team exercises
  • penetration testing
  • threat modeling
  • machine learning models
  • AI systems
  • Cross-Functional Leadership
  • Advanced Threat Detection
  • anomaly detection systems
  • technical writing
  • Master's degree
  • CISSP
  • CISM
  • Cloud Security certifications

What the JD emphasized

  • 8+ years of professional experience in data security, cybersecurity, security architecture, or data engineering with a primary focus on security.
  • Proven hands-on experience designing and implementing Role-Based Access Control (RBAC), row-level, and column-level security policies in modern cloud data platforms (specifically Snowflake and/or Databricks/DBX).
  • Strong expertise in API security controls, authentication, and authorization protocols (e.g., OAuth2, OIDC, SAML, JWT) to protect data access.
  • Solid understanding of data privacy regulations (e.g., GDPR, CCPA) and experience translating these regulatory requirements into technical data governance and access controls.
  • Experience implementing security logging, audit trails, and monitoring solutions to detect unauthorized access or data exfiltration.
  • Direct experience securing AI/ML lifecycles, LLM-powered applications, or autonomous AI agents (e.g., securing RAG architectures, mitigating prompt injection, defining data access boundaries for AI).
  • Experience leading or participating in red team exercises, penetration testing, or threat modeling specifically tailored to machine learning models and AI systems.

Other signals

  • securing data across the full AI lifecycle
  • designing and enforcing row-level security policies
  • API-driven access controls
  • role-based data grants across AI pipelines, chat interfaces, and autonomous agents
  • red team exercises to proactively identify vulnerabilities in AI systems