Security Engineer, Application Security

Saronic Technologies

2h ago 0 views 0 applications
Full-time On-site
Austin, TX
Competitive
Full-time
Security Engineer Application Security

Job Description

Application Security Enginee

At Saronic Technologies, we're not just building technology; we're revolutionizing autonomy at sea. We develop state-of-the-art, intelligent platforms that enhance maritime operations, pushing the boundaries of what's possible. Join us to secure the future of autonomous navigation.

Elevate Security as a Force Multiplier, Not a Blocker
At Saronic, security is fundamental to our mission – it's a force multiplier that enables our rapid innovation. We're seeking a passionate and proactive Application Security Engineer to empower our engineering teams. You won't just find vulnerabilities; you'll own the security of our entire software development lifecycle (SDLC) and supply chain across product, cloud, and enterprise systems.

This is a unique opportunity to build and shape the application security function from a strong foundation. You'll move beyond reactive bug-chasing to architect durable guardrails and 'paved roads' that allow our teams to deploy mission-critical software securely by default, accelerating our progress without compromising safety. You will be instrumental in making security an inherent part of our development culture, partnering closely with Software, DevOps, Cloud, and Platform Engineering to weave security into the fabric of everything we build.

What You'll Deliver: Impact & Innovation
As our Application Security Engineer, you will:

Architect Secure SDLC & DevSecOps: Lead threat modeling, secure design reviews, and code reviews for both new and existing systems. Drive the integration of SAST, DAST, and SCA directly into our CI/CD pipelines, establishing security gates that are embraced by developers, not seen as obstacles.
Fortify the Software Supply Chain: Take ownership of our software supply chain security. This includes comprehensive SCA, generating SBOMs, ensuring artifact signing and provenance, and strategically reducing dependency and secrets exposure across our ecosystem.
Master Secrets & Application Controls: Define and govern robust secrets management strategies. Implement and manage application allowlisting/blocklisting, and contribute to data loss prevention through advanced software controls.
Engineer Secure Self-Hosting Environments: Design and harden critical infrastructure and patterns for securely self-hosting applications. This spans internal enterprise use, embedded product solutions, and customer deployments across AWS, Azure, and on-premise environments. You’ll provide hardened base images, enforce network isolation, implement identity and secrets management, streamline patching, and enhance monitoring – enabling teams to deploy securely by default without manual bottlenecks.
Drive Security Partnerships & Tooling: Embed yourself within engineering teams, fostering strong collaborative relationships. Develop scalable security tooling that empowers the entire organization to build and ship securely at speed.

What You'll Bring: Your Expertise

5+ years of hands-on experience in Application Security, DevSecOps, or Product Security, or a combination of experience and proven capability.
Deep expertise in Secure SDLC practices: threat modeling, secure code review, and integrating SAST/DAST/SCA into CI/CD pipelines.
Proven track record with **Software Supply Chain Security**, including SCA, SBOMs, artifact signing, and robust secrets management.
Extensive experience securing the deployment and self-hosting of applications, encompassing hardened images, network isolation, identity and secrets management, patching strategies, and monitoring.
Proficiency in scripting and Infrastructure-as-Code (IaC) to develop scalable, durable security tooling.
Ability to obtain and maintain a U.S. security clearance.

Bonus Points For:

Expertise in Container and Cloud Security, including advanced application allowlisting.
Demonstrated experience in securely self-hosting or delivering complex applications to customers across diverse environments (AWS, Azure, and on-premise).
An "attacker's mindset" with experience in bug bounty triage or penetration testing.
Background in defense, aerospace, or other high-assurance security environments.

If this role is based in the United States, it requires access to export-controlled information or items that require “U.S. Person” status. As defined by U.S. law, individuals who are any one of the following are considered to be a “U.S. Person”: (1) U.S. citizens, (2) legal permanent residents (a.k.a. green card holders), and (3) certain protected classes of asylees and refugees, as defined in 8 U.S.C. 1324b(a)(3).
Saronic does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits. We are also committed to providing reasonable accommodations for qualified individuals with disabilities.

CyberJob.app

Your trusted source for cybersecurity job opportunities worldwide.


© 2026 CyberJob.app. All rights reserved.