Jobs · Information Technology · California

Security Engineer, Application Security

Saronic Technologies · San Diego, CA · 2 days ago
On-siteInformation TechnologyFull-time

About the role

Saronic Technologies seeks a Security Engineer for Application Security to join our dynamic team. The ideal candidate will be responsible for securing the software development lifecycle and supply chain, ensuring that our teams can ship software quickly while maintaining high standards of security.

Responsibilities

  • Run threat modeling and secure design and code reviews for new and existing systems.
  • Integrate SAST, DAST, and SCA into CI/CD and secure pipelines from commit to deploy with gates that developers welcome.
  • Own dependency and supply-chain security: SCA, SBOMs, artifact signing and provenance, and reduce accumulated dependency and secrets exposure.
  • Govern secrets management, application allowlisting/blocklisting, and support data-loss-prevention through software controls.
  • Secure self-hosting infrastructure: design and harden the infrastructure and patterns for securely self-hosting software applications, for internal enterprise use, embedded within our products, and delivered to our customers, across AWS, Azure, and on-prem.
  • Provide hardened base images, network isolation, identity and secrets management, patching, and monitoring so any team can stand up a self-hosted application securely by default instead of routing every request through manual review.
  • Embed with engineering teams and build the tooling that scales security across the org.

Requirements

  • 5+ years in application security, DevSecOps, or product security, or an equivalent combination of experience and demonstrated ability.
  • Hands-on secure SDLC: threat modeling, secure code review, and SAST/DAST/SCA in CI/CD.
  • Software supply-chain security (SCA/SBOM/signing) and secrets management.
  • Experience securing the deployment and self-hosting of applications (hardened images, isolation, identity, patching, monitoring).
  • Comfortable in scripting and Infrastructure-as-Code so you can build durable tooling, not one-off commands and clicks.
  • Ability to obtain and maintain a U.S. security clearance.

Qualifications

  • Required qualifications include:
  • Experience in container and cloud security.
  • Experience in application allowlisting.
  • Experience in securely self-hosting or delivering applications to customers across AWS, Azure, and on-prem.
  • An attacker’s mindset; bug-bounty triage experience.
  • Experience in defense, aerospace, or other high-assurance environments.

Preferred Qualifications

  • Container and cloud security; application allowlisting.
  • Securely self-hosting or delivering applications to customers across AWS, Azure, and on-prem.
  • An attacker’s mindset; bug-bounty triage experience.
  • Experience in defense, aerospace, or other high-assurance environments.

Benefits

We offer a competitive compensation package, including a comprehensive benefits program that includes health insurance, retirement plans, and paid time off.

Pay

Compensation is commensurate with experience.

Schedule

The position is full-time.

Skills

Strong skills in application security, DevSecOps, and software supply-chain security are essential.

Benefits

We offer a comprehensive benefits package, including health insurance, retirement plans, and paid time off.

Similar jobs