Apple · 19 hours ago
Senior Detection Creation Engineer
Apple is a leading technology company known for its innovative products and services. They are seeking a Detection Creation Engineer to develop security detections that identify active malicious activity across Apple’s services and infrastructure, collaborating closely with engineering teams to ensure robust security measures are in place.
AppsArtificial Intelligence (AI)BroadcastingDigital EntertainmentFoundational AIMedia and EntertainmentMobile DevicesOperating SystemsTVWearables
Responsibilities
Develop security detections that identify active malicious activity across Apple’s services and infrastructure, implementing detection logic in Scala Spark (Databricks) and on-host detection frameworks (Falco rules)
Analyze attacker behaviors and translate them into observable patterns across diverse telemetry sources including system call events, network logs, database access logs, endpoint security telemetry, Kubernetes audit logs, and other security-relevant data sources
Collaborate with engineering teams to understand system architectures, identify detection opportunities, and develop detections that are both high-fidelity and operationally sustainable
Tune and optimize detections based on real-world alert data, reducing false positives while maintaining coverage of malicious behaviors
Operationalize detections by working with security operations teams to ensure alerts are actionable, triaged efficiently, and integrated into incident response workflows
Document detection logic and rationale to enable knowledge sharing across the security organization
Qualification
Required
5+ years of experience in security detection, threat hunting, incident response, penetration testing, red teaming, or related security disciplines
Demonstrated understanding of real attacker behaviors, tactics, and techniques
Proficiency in at least one programming language (Python, Scala, Java, Go, or similar) with the ability and willingness to learn Scala
Bachelor's degree in Computer Science, Cybersecurity, Engineering, Information Systems, or related field, or equivalent professional experience
Experience analyzing security telemetry data to identify malicious activity or anomalous behaviors
Preferred
Prior experience writing detections in Scala, Python, or other languages for large-scale data processing systems
Experience with Apache Spark, Databricks, or similar large-scale distributed compute frameworks
Hands-on experience with on-host detection rules engine systems (Falco or similar)
Deep technical expertise in one or more areas: Linux system internals, network protocols, web application security, container/Kubernetes security, or cloud infrastructure
Experience with multiple security-relevant telemetry sources: system call traces (network, process, file), endpoint detection and response (EDR) data, network traffic analysis, application logs, database audit logs, cloud provider audit logs
Understanding of evasion techniques and how attackers attempt to avoid detection
Contributions to open-source security projects or published research on detection techniques
Experience with detection engineering at scale, including managing false positive rates and detection tuning methodologies
Benefits
Comprehensive medical and dental coverage
Retirement benefits
A range of discounted products and free services
Reimbursement for certain educational expenses — including tuition
Discretionary bonuses
Commission payments
Relocation
Company
Apple
Apple is a technology company that designs, manufactures, and markets consumer electronics, personal computers, and software.
H1B Sponsorship
Apple has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (6998)
2024 (3766)
2023 (3939)
2022 (4822)
2021 (4060)
2020 (3656)
Funding
Current Stage
Public CompanyTotal Funding
$5.67BKey Investors
Berkshire HathawayMicrosoftSequoia Capital
2025-05-05Post Ipo Debt· $4.5B
2025-01-16Post Ipo Debt· $0.31M
2021-04-30Post Ipo Equity
Leadership Team
Tim Cook
CEO
Craig Federighi
SVP, Software Engineering
Recent News
Venrock
2025-12-01
2025-09-25
Mac Daily News
2025-09-25
Company data provided by crunchbase