Saronic
Posted 1w ago

Security Engineer, Application Security

Saronic
Austin or San Diego
OnsiteFull Time
Responsibilities
  • running threat modeling
  • securing pipelines
  • hardening infrastructure
Requirements
  • Requires 5+ years in application security
  • DevSecOps, or product security
  • Secure SDLC
  • Supply-chain security
  • Secrets management
  • Self-hosting
  • Scripting
  • Infrastructure-as-Code, and ability to obtain U.S. security clearance
Technical tools mentioned
SASTDASTSCACI/CDSBOMAWSAzureInfrastructure-as-Code

Job description

Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations through autonomous and intelligent platforms.

Security at Saronic is a force multiplier, not a blocker. We’re looking for a Security Engineer for Application Security to empower our teams to ship fast without trading away safety to secure the software development lifecycle and supply chain across product, cloud, and enterprise systems. The software org ships rapidly and rely on the security team to provide guardrails to enable that speed and scale safely. You’ll be that owner, and you’ll fix whole classes of problems rather than chasing one bug at a time.

You’ll partner closely with Software, DevOps, Cloud, and Platform Engineering to make secure the default, not the exception.

This is an opportunity to build the application-security function from a strong foundation, own the security of the pipelines and supply chain that produce mission-critical software, and build the guardrails and paved roads that let teams deploy securely by default.

What You’ll Do

  • Secure SDLC & DevSecOps: Run threat modeling and secure design and code reviews for new and existing systems. Integrate SAST, DAST, and SCA into CI/CD and secure pipelines from commit to deploy with gates that developers actually welcome.

  • Software Supply Chain: Own dependency and supply-chain security: SCA, SBOMs, artifact signing and provenance, and reducing accumulated dependency and secrets exposure.

  • Secrets & Application Controls: Govern secrets management, application allowlisting/blocklisting, and support data-loss-prevention through software controls.

  • Secure Self-Hosting Infrastructure: Design and harden the infrastructure and patterns for securely self-hosting software applications, for internal enterprise use, embedded within our products, and delivered to our customers, across AWS, Azure, and on-prem. Provide hardened base images, network isolation, identity and secrets management, patching, and monitoring so any team can stand up a self-hosted application securely by default instead of routing every request through manual review.

  • Partnership: Embed with engineering teams and build the tooling that scales security across the org.

Required Qualifications

· 5+ years in application security, DevSecOps, or product security, or an equivalent combination of experience and demonstrated ability

· Hands-on secure SDLC: threat modeling, secure code review, and SAST/DAST/SCA in CI/CD

· Software supply-chain security (SCA/SBOM/signing) and secrets management

· Experience securing the deployment and self-hosting of applications (hardened images, isolation, identity, patching, monitoring)

· Comfortable in scripting and Infrastructure-as-Code so you can build durable tooling, not one-off commands and clicks

· Ability to obtain and maintain a U.S. security clearance

Preferred Qualifications

· Container and cloud security; application allowlisting

· Securely self-hosting or delivering applications to customers across AWS, Azure, and on-prem

· An attacker’s mindset; bug-bounty triage experience

· Experience in defense, aerospace, or other high-assurance environments

If this role is based in the United States, it requires access to export-controlled information or items that require “U.S. Person” status. As defined by U.S. law, individuals who are any one of the following are considered to be a “U.S. Person”: (1) U.S. citizens, (2) legal permanent residents (a.k.a. green card holders), and (3) certain protected classes of asylees and refugees, as defined in 8 U.S.C. 1324b(a)(3).

Saronic does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits. We are also committed to providing reasonable accommodations for qualified individuals with disabilities.

About Saronic

Building autonomous surface vessels for maritime defense operations.

Year founded
2022
Employees
300
Organization type
Private
Latest investment
Raised $1.75B Series D (2026) — led by Kleiner Perkins
Headquarters
US

Similar jobs

Application Security Engineer roles near Austin, Texas
2d
Save
Mark Applied
Hide
Confluent - Staff Security Engineer
Poughkeepsie or Lowell or Rochester or Tucson or Research Triangle Park or Armonk or Boston or Bellevue or Atlanta or San Jose or Dallas or Austin or San Francisco or Seattle
$161k-$299k/yr RemoteFull Time
IBM
IBMNew York Stock Exchange: IBM: Global technology providing enterprise software, cloud, and consulting.
10+ YOERequires a bachelor's degree and 10+ years of application security experience, with expertise in secure architecture, cloud-native platforms, security automation, CI/CD, and Go, Python, or Java.
Go, Python, Java, CI/CD, AI, LLMs
1w
Save
Mark Applied
Hide
Sr. Application Security Engineer
Fort Mill or Charlotte or New York City or San Diego or Austin or Tempe
$101k-$168k/yr HybridFull Time
LPL Financial
LPL FinancialNASDAQ: LPLA: Provides independent financial advisory and wealth management services.
5+ YOERequires 5+ years of application security experience, manual API and web testing, vulnerability analysis, security libraries, scanning tools, risk evaluation, secure SDLC, DevSecOps, and strong communication skills.
Synopsys, Black Duck, JFrog, Prisma Cloud, Burp Suite, Postman, C#, Java, HTML, CSS, JavaScript, React, Angular, REST, CI/CD, OWASP Top 10, IAST
1w
Save
Mark Applied
Hide
Sr. Application Security Engineer
Fort Mill or Charlotte or New York City or San Diego or Austin or Tempe
$101k-$168k/yr HybridFull Time
LPL Financial
LPL FinancialNASDAQ: LPLA: Provides wealth management and brokerage services to financial advisors.
5+ YOERequires 5+ years of application security experience, manual API and web testing, vulnerability analysis, security libraries, scanning tools, risk evaluation, secure SDLC, DevSecOps, and CI/CD expertise.
Synopsys, BlackDuck, J-Frog, PrismaCloud, Burpsuite, Postman, C#, Java, HTML, CSS, JS, React, Angular, REST, DevSecOps, CI/CD
3w
Save
Mark Applied
Hide
Application Security Engineer - ADR
Quincy or Toronto or Austin or Atlanta
$120k-$203k/yr OnsiteFull Time
State Street
State StreetNYSE: STT: Provides investment servicing and management to institutional investors.
6+ YOEHands-on experience with application security, ADR/RASP/WAAP, SAST/DAST/SCA, cloud (Azure/AWS), DevSecOps, secure SDLC, threat detection, incident response, and relevant security certifications.
Java, .NET, Python, Node.js, Azure, AWS, SAST, DAST, SCA, API Security, Container Security, Runtime Application Self-Protection (RASP), Web Application and API Protection (WAAP), Ansible, Terraform, Kubernetes, Infrastructure as Code (IaC), Agile, DevOps
4w
Save
Mark Applied
Hide
Senior Application Security Engineer
Austin, Texas, United States
$95k/yr HybridFull Time
University of Texas at Austin
University of Texas at Austin: Provides public higher education and conducts academic research.
Experience in application security, secure code review, SAST/DAST/SCA, cloud security (Azure), and application vulnerability management; bachelor\u0002s degree or equivalent.
Microsoft Azure, Adobe Experience Cloud, Burp Suite, OWASP ZAP, Metasploit, Checkmarx, Veracode, SonarQube
5mo
Save
Mark Applied
Hide
Senior Application Security Engineer II
Austin or Chicago or Washington or New York
$165k-$185k/yr HybridFull Time
Upside
Upside: Personalized cashback rewards platform for everyday brick-and-mortar purchases.
6+ YOE6+ years in application or product security; experience with SAST/SCA; AWS security architecture; Python code review; AI in security; Bachelor's preferred.
GitHub, Python, Terraform, AWS, SQL, ChatGPT, Snowflake
5y
Save
Mark Applied
Hide
Senior Application Security Engineer
San Francisco or Austin or Concord
$180k-$210k/yr RemoteFull Time
Qualia
Qualia: Cloud platform for digital real estate closing and settlement.
8+ YOE8+ years in AppSec or security engineering; strong offensive testing; build security tooling; AWS, Kubernetes/EKS, and IaC experience; coding in Python/Go/Ruby/TypeScript.
Burp Suite, Semgrep, SAST, DAST, SCA, IaC scanning, Terraform, AWS, Kubernetes, Docker, CI/CD security gates
1mo
Save
Mark Applied
Hide
Sr. Application Security Testing Engineer
Austin, Texas, United States
$165k-$201k/yr OnsiteFull Time
3M
3MNYSE: MMM: Manufacturers diversified industrial, safety, consumer, and electronics products.
3+ YOEBachelor's in cybersecurity/computer science/technology, 3+ years application security experience, hands-on SAST/DAST/SCA and CI/CD integration, threat modeling knowledge, strong communication; must be authorized to work without sponsorship.
SAST, DAST, SCA, GitHub, Azure DevOps, CI/CD