{"schemaVersion":"jobsearcher.job.v1","id":"e983410cee5331b52158ea6d","url":"https://jobsearcher.com/jobs/e983410cee5331b52158ea6d","canonicalUrl":"https://jobsearcher.com/jobs/e983410cee5331b52158ea6d","title":"Security Engineer, Application Security","description":"Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations through autonomous and intelligent platforms.\nSecurity at Saronic is a force multiplier, not a blocker. We’re looking for a Security Engineer for Application Security to empower our teams to ship fast without trading away safety to secure the software development lifecycle and supply chain across product, cloud, and enterprise systems. The software org ships rapidly and rely on the security team to provide guardrails to enable that speed and scale safely. You’ll be that owner, and you’ll fix whole classes of problems rather than chasing one bug at a time.\nYou’ll partner closely with Software, DevOps, Cloud, and Platform Engineering to make secure the default, not the exception.\nThis is an opportunity to build the application-security function from a strong foundation, own the security of the pipelines and supply chain that produce mission-critical software, and build the guardrails and paved roads that let teams deploy securely by default.\nWhat You’ll Do\nSecure SDLC & DevSecOps: Run threat modeling and secure design and code reviews for new and existing systems. Integrate SAST, DAST, and SCA into CI/CD and secure pipelines from commit to deploy with gates that developers actually welcome.\nSoftware Supply Chain: Own dependency and supply-chain security: SCA, SBOMs, artifact signing and provenance, and reducing accumulated dependency and secrets exposure.\nSecrets & Application Controls: Govern secrets management, application allowlisting/blocklisting, and support data-loss-prevention through software controls.\nSecure Self-Hosting Infrastructure: Design and harden the infrastructure and patterns for securely self-hosting software applications, for internal enterprise use, embedded within our products, and delivered to our customers, across AWS, Azure, and on-prem. Provide hardened base images, network isolation, identity and secrets management, patching, and monitoring so any team can stand up a self-hosted application securely by default instead of routing every request through manual review.\nPartnership: Embed with engineering teams and build the tooling that scales security across the org.\nRequired Qualifications\n5+ years in application security, DevSecOps, or product security, or an equivalent combination of experience and demonstrated ability\nHands-on secure SDLC: threat modeling, secure code review, and SAST/DAST/SCA in CI/CD\nSoftware supply-chain security (SCA/SBOM/signing) and secrets management\nExperience securing the deployment and self-hosting of applications (hardened images, isolation, identity, patching, monitoring)\nComfortable in scripting and Infrastructure-as-Code so you can build durable tooling, not one-off commands and clicks\nAbility to obtain and maintain a U.S. security clearance\nPreferred Qualifications\nContainer and cloud security; application allowlisting\nSecurely self-hosting or delivering applications to customers across AWS, Azure, and on-prem\nAn attacker’s mindset; bug-bounty triage experience\nExperience in defense, aerospace, or other high-assurance environments\nIf this role is based in the United States, it requires access to export-controlled information or items that require “U.S. Person” status. As defined by U.S. law, individuals who are any one of the following are considered to be a “U.S. Person”: (1) U.S. citizens, (2) legal permanent residents (a.k.a. green card holders), and (3) certain protected classes of asylees and refugees, as defined in 8 U.S.C. 1324b(a)(3).\n\nSaronic does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits. We are also committed to providing reasonable accommodations for qualified individuals with disabilities.","company":"Saronic Technologies","rawCompany":"saronic technologies","city":"San Diego","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-08-06T10:23:34.456Z","occupations":[{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security Engineer, Application Security","description":"Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations through autonomous and intelligent platforms.\nSecurity at Saronic is a force multiplier, not a blocker. We’re looking for a Security Engineer for Application Security to empower our teams to ship fast without trading away safety to secure the software development lifecycle and supply chain across product, cloud, and enterprise systems. The software org ships rapidly and rely on the security team to provide guardrails to enable that speed and scale safely. You’ll be that owner, and you’ll fix whole classes of problems rather than chasing one bug at a time.\nYou’ll partner closely with Software, DevOps, Cloud, and Platform Engineering to make secure the default, not the exception.\nThis is an opportunity to build the application-security function from a strong foundation, own the security of the pipelines and supply chain that produce mission-critical software, and build the guardrails and paved roads that let teams deploy securely by default.\nWhat You’ll Do\nSecure SDLC & DevSecOps: Run threat modeling and secure design and code reviews for new and existing systems. Integrate SAST, DAST, and SCA into CI/CD and secure pipelines from commit to deploy with gates that developers actually welcome.\nSoftware Supply Chain: Own dependency and supply-chain security: SCA, SBOMs, artifact signing and provenance, and reducing accumulated dependency and secrets exposure.\nSecrets & Application Controls: Govern secrets management, application allowlisting/blocklisting, and support data-loss-prevention through software controls.\nSecure Self-Hosting Infrastructure: Design and harden the infrastructure and patterns for securely self-hosting software applications, for internal enterprise use, embedded within our products, and delivered to our customers, across AWS, Azure, and on-prem. Provide hardened base images, network isolation, identity and secrets management, patching, and monitoring so any team can stand up a self-hosted application securely by default instead of routing every request through manual review.\nPartnership: Embed with engineering teams and build the tooling that scales security across the org.\nRequired Qualifications\n5+ years in application security, DevSecOps, or product security, or an equivalent combination of experience and demonstrated ability\nHands-on secure SDLC: threat modeling, secure code review, and SAST/DAST/SCA in CI/CD\nSoftware supply-chain security (SCA/SBOM/signing) and secrets management\nExperience securing the deployment and self-hosting of applications (hardened images, isolation, identity, patching, monitoring)\nComfortable in scripting and Infrastructure-as-Code so you can build durable tooling, not one-off commands and clicks\nAbility to obtain and maintain a U.S. security clearance\nPreferred Qualifications\nContainer and cloud security; application allowlisting\nSecurely self-hosting or delivering applications to customers across AWS, Azure, and on-prem\nAn attacker’s mindset; bug-bounty triage experience\nExperience in defense, aerospace, or other high-assurance environments\nIf this role is based in the United States, it requires access to export-controlled information or items that require “U.S. Person” status. As defined by U.S. law, individuals who are any one of the following are considered to be a “U.S. Person”: (1) U.S. citizens, (2) legal permanent residents (a.k.a. green card holders), and (3) certain protected classes of asylees and refugees, as defined in 8 U.S.C. 1324b(a)(3).\n\nSaronic does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits. We are also committed to providing reasonable accommodations for qualified individuals with disabilities.","datePosted":"2026-08-06T10:23:34.456Z","dateModified":"2026-08-06T10:23:34.456Z","hiringOrganization":{"@type":"Organization","name":"Saronic Technologies","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Diego","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"e983410cee5331b52158ea6d"},"url":"https://jobsearcher.com/jobs/e983410cee5331b52158ea6d"}}