Apollo GraphQL
Staff Security Operations Engineer
US time zones (remote) · Staff+
Sponsorship not specifiedDetected 47 days ago
Full-Stack DevelopmentCode ReviewAWSGCPKubernetesTerraformCI/CDAPI DevelopmentGraphQLRESTCybersecuritySIEMSOARSOC OperationsDetection EngineeringIncident ResponseComplianceAuditingSupply ChainCustomer SuccessLeadership
About the role
- Are you a security engineer who thinks like an attacker but works like a builder.
Responsibilities
- Partner with engineering teams to conduct threat modeling and security reviews on new features and architecture changes
- Drive security requirements into the SDLC, embedding security gates into CI/CD pipelines
- Act as a security advisor for product teams building customer-facing features, particularly those involving authentication, authorization, and data handling
- Implement and maintain adherence to SOC 2 and other cloud security frameworks
- Build and tune monitoring, logging, and alerting systems to improve visibility while reducing noise
- Drive automation of SecOps workflows to speed up investigation and response
- Someone who can find the flaw in an API design before it ships, write the tooling to catch the next one automatically, and partner with engineering teams to build more secure software end to end?
- Someone who can own the detection and response capabilities that keep infrastructure safe, and still show up sharp when an incident needs an expert hand?
- As a Staff Security Engineer at Apollo, you'll bring deep expertise across both application security and security operations to help us protect the products we build and the infrastructure we run them on.
- This is a high-impact, high-ownership role where you'll shape how we approach secure development, lead detection and response, and be a trusted partner to engineering teams building Apollo's API platform.
Requirements
- 6+ years in security engineering, spanning both application security and security operations
- Deep expertise with detection and response in cloud-native environments
- Track record of influencing security culture across an engineering organization
- Strong knowledge of SOC 2, ISO 27001, or similar security frameworks
- Track record of influencing operational security culture and practices without direct authority
Nice to have
- Experience working with AI security - either in detection, incident response, or product security contexts
- Prior experience supporting enterprise customer audits or due diligence processes
- Familiarity with Terraform, Kubernetes, or other modern infrastructure stacks
- Hands-on experience with threat hunting and detection engineering
- Experience securing GraphQL APIs, federation, or API gateway patterns
- Familiarity with software supply chain security (SBOM, Sigstore, dependency auditing)
- Whether you binge-watch a series on Netflix, plan faraway vacations from your phone, or read international news online, you've likely used Apollo's technology this week.
- We're not looking to rest on our laurels though - we're aiming to change how software is built.
Apply directly at Apollo GraphQL →Create a free account for alerts like thisView Apollo GraphQL immigration profile
This listing is sourced directly from Apollo GraphQL's careers page and normalized into a canonical job model.