Apollo GraphQL

Staff Security Operations Engineer

Apollo GraphQL3 weeks ago
Location

US time zones (remote)

Type

Full Time

Salary

USD 230,000 – 255,000

Level

Staff

Role

Security Operations Engineer

Posted

Jun 4, 2026

Full TimeStaff

The role

Summary

Apollo GraphQL is seeking a Staff Security Operations Engineer to lead and transform their security infrastructure. The ideal candidate will bring deep expertise in application and infrastructure security, focusing on proactively protecting GraphQL platforms through innovative security strategies, threat modeling, and cross-team collaboration.

What you'll do

Security Program Development: Establish and evolve Apollo's application security program, including implementing SAST/DAST tooling, dependency scanning, and secure coding standards.
Threat Modeling and Security Reviews: Conduct comprehensive threat modeling and security reviews for new features and architectural changes, identifying potential vulnerabilities before deployment.
CI/CD Security Integration: Drive security requirements into the Software Development Life Cycle (SDLC) by embedding security gates into CI/CD pipelines.
Incident Detection and Response: Advance Apollo's detection and response strategy, build monitoring systems, and participate in on-call rotations to manage security escalations.
Compliance Management: Implement and maintain adherence to SOC 2 and other cloud security frameworks, supporting enterprise security standards.

What we look for

Technical

Application SecurityComprehensive understanding of OWASP standards, threat modeling, secure code review, and API security patterns.
Cloud SecurityProficient in cloud security controls for AWS and GCP, with expertise across infrastructure and application security layers.
Security ToolingExperience building and automating security tooling using scripting/programming languages, SIEM, SOAR, and AppSec tools.

Education

Security CertificationsStrong knowledge of SOC 2, ISO 27001, or equivalent security framework certifications preferred.

Experience

Security EngineeringMinimum 6+ years in security engineering, covering both application security and security operations.
Incident ResponseProven ability to lead or coordinate incident response across multiple teams.
Security CultureTrack record of influencing operational security practices and culture without direct authority.

Skills

Required skills

Threat ModelingAdvanced capability to identify and mitigate potential security risks in software design
Security ScriptingProficiency in developing security automation and tooling
Cloud SecurityDeep understanding of security controls in cloud-native environments

Nice to have

AI SecurityExperience with AI security in detection, incident response, or product security contexts
GraphQL SecurityExpertise in securing GraphQL APIs, federation, or API gateway patterns

Compensation & benefits

Salary

USD 230,000 – 255,000 (annual)

Benefits

Competitive Compensation

Salary range of $230K-$255K with potential for equity

Remote Work

Fully remote position within US time zones

Professional Development

Opportunities to work on cutting-edge GraphQL and security technologies

Innovation Culture

Work with a company transforming API development and security practices


Interview process

  1. 1
    Initial Screening Review of resume and security engineering background
  2. 2
    Technical Assessment Security-focused coding challenge and architecture review
  3. 3
    Security Design Interview In-depth discussion of security strategies and past incident responses
  4. 4
    Team Collaboration Interview Assess communication skills and ability to work across engineering teams
  5. 5
    Final Leadership Interview Meeting with security and engineering leadership to evaluate strategic thinking

Apply for this position

You'll be redirected to the company's application page