Security Engineer, Application Security

Saronic Technologies
San Diego, CA, United States
29 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Software Applications Microsoft Azure Cloud Computing Cloud Computing Security Code Review Continuous Integration DevOps Key Management Systems Development Life Cycle Secure Coding Software Engineering
+5 more
Enterprise Software Applications Software Security Devsecops Static Application Security Testing Dynamic Application Security Testing

Job description

Security at Saronic is a force multiplier, not a blocker. We’re looking for a Security Engineer for Application Security to empower our teams to ship fast without trading away safety to secure the software development lifecycle and supply chain across product, cloud, and enterprise systems. The software org ships rapidly and rely on the security team to provide guardrails to enable that speed and scale safely. You’ll be that owner, and you’ll fix whole classes of problems rather than chasing one bug at a time.

You’ll partner closely with Software, DevOps, Cloud, and Platform Engineering to make secure the default, not the exception., * Secure SDLC & DevSecOps: Run threat modeling and secure design and code reviews for new and existing systems. Integrate SAST, DAST, and SCA into CI/CD and secure pipelines from commit to deploy with gates that developers actually welcome.

  • Software Supply Chain: Own dependency and supply-chain security: SCA, SBOMs, artifact signing and provenance, and reducing accumulated dependency and secrets exposure.
  • Secrets & Application Controls: Govern secrets management, application allowlisting/blocklisting, and support data-loss-prevention through software controls.
  • Secure Self-Hosting Infrastructure: Design and harden the infrastructure and patterns for securely self-hosting software applications, for internal enterprise use, embedded within our products, and delivered to our customers, across AWS, Azure, and on-prem. Provide hardened base images, network isolation, identity and secrets management, patching, and monitoring so any team can stand up a self-hosted application securely by default instead of routing every request through manual review.
  • Partnership: Embed with engineering teams and build the tooling that scales security across the org.

Requirements

  • 5+ years in application security, DevSecOps, or product security, or an equivalent combination of experience and demonstrated ability
  • Hands-on secure SDLC: threat modeling, secure code review, and SAST/DAST/SCA in CI/CD
  • Software supply-chain security (SCA/SBOM/signing) and secrets management
  • Experience securing the deployment and self-hosting of applications (hardened images, isolation, identity, patching, monitoring)
  • Comfortable in scripting and Infrastructure-as-Code so you can build durable tooling, not one-off commands and clicks
  • Ability to obtain and maintain a U.S. security clearance, * Container and cloud security; application allowlisting
  • Securely self-hosting or delivering applications to customers across AWS, Azure, and on-prem
  • An attacker’s mindset; bug-bounty triage experience
  • Experience in defense, aerospace, or other high-assurance environments

About the company

Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations through autonomous and intelligent platforms.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:39 min

Addressing code review surrender and process exploitation

Laura Tacho Laura Tacho · World Congress 2026 Europe

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all