Senior Application Security Engineer in Glasgow

Senior Application Security Engineer in Glasgow

Glasgow Full-Time 60000 - 75000 £ / year (est.) Home office (partial)
Sonos

At a Glance

  • Tasks: Own product security execution, automate practices, and integrate security tooling across engineering workflows.
  • Company: Join Sonos, a leader in creating exceptional listening experiences with a diverse and inclusive team.
  • Benefits: Competitive salary, flexible work options, and opportunities for professional growth.
  • Other info: Collaborative environment focused on innovation and career development.
  • Why this job: Make a real impact on security practices while working with cutting-edge technology.
  • Qualifications: 4+ years in software or application security, with hands-on experience in security tooling.

The predicted salary is between 60000 - 75000 £ per year.

At Sonos we want to create the ultimate listening experience for our customers and know that it starts by listening to each other. As part of the Sonos team, you’ll collaborate with people of all styles, skill sets, and backgrounds to realize our vision while fostering a community where everyone feels included and empowered to do the best work of their lives.

About Sonos: Sonos makes the world's leading listening experiences — and the products behind them span a technically diverse ecosystem: embedded firmware, mobile applications, web platforms, cloud services, and partners. If you're looking for an opportunity to apply security principles across technical domains, and work on an outstanding consumer product, this is a great opportunity.

The Product Security team combines modern security tooling, automation, and AI with industry-defining security frameworks and direct development team partnerships. We enable secure-by-design and secure-by-default practices that are a natural part of how engineers work. We’re creating AI-powered workflows that encode security guidelines, automate the groundwork for threat modeling, and replace manual triage with intelligent pipelines. If you think security policy should run in a pipeline rather than live in a document, you'll fit right in.

What You’ll Do:

  • You’ll own the execution layer of product security — the systems, tooling, and processes that make security practice consistent and measurable across cloud, mobile, and embedded engineering domains.
  • Automate and scale security practice.
  • Integrate and operationalize security tooling (SAST, SCA, secrets scanning, DAST, SBOM) across engineering workflows, ensuring findings are high-signal and actionable.
  • Partner with engineering teams to embed secure-by-design and secure-by-default practices directly into how they build.
  • Build and extend AI-powered security tooling that encodes guidelines as automated workflows — replacing manual review steps with intelligent pipelines that run in CI/CD.
  • Test, assess, and design securely.
  • Lead and scale threat modeling across cloud, mobile, and embedded domains, including device-cloud-mobile trust boundaries.
  • Establish repeatable security testing practices using automation and targeted manual assessment.
  • Scope and coordinate third-party penetration testing engagements across cloud, mobile, web, and connected devices — including IoT and firmware assessments.
  • Support vulnerability intake, triage, coordinated disclosure, and PSIRT readiness.

What You’ll Bring:

  • 4+ years in software engineering, application security, or product security.
  • Experience working directly with engineering teams in modern software development environments.
  • Hands-on experience implementing and operationalizing security tooling: SAST, SCA, DAST, secrets scanning, or similar.
  • Experience integrating security practices and tooling into CI/CD pipelines.
  • Experience using AI tools to automate security practices and previously manual activities.
  • Experience scoping or coordinating penetration testing engagements and working with the results; experience with IoT or embedded device assessments is a strong plus.
  • Experience working with IoT products, connected devices, or embedded systems is preferred but not required.

Your profile will be reviewed and you'll hear from us once we have an update. At Sonos we take the time to hire right and appreciate your patience.

Senior Application Security Engineer in Glasgow employer: Sonos

At Sonos, we pride ourselves on fostering a collaborative and inclusive work environment where every team member is empowered to contribute their unique skills and perspectives. As a Senior Application Security Engineer, you'll not only play a crucial role in enhancing our product security but also benefit from our commitment to employee growth through innovative projects and cutting-edge technology. Located in a vibrant community, we offer a dynamic workplace that values creativity and encourages professional development, making it an exceptional place to build a rewarding career.

Sonos

Contact Details:

Sonos Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Application Security Engineer in Glasgow

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Sonos, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Sonos

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Sonos. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Senior Application Security Engineer in Glasgow

Application Security
Security Tooling (SAST, SCA, DAST, secrets scanning)
CI/CD Integration
Threat Modeling
Vulnerability Management
Penetration Testing
Automation of Security Practices

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Sonos insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Sonos that you’re committed to staying ahead in the game.

How to prepare for a job interview at Sonos

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Sonos to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Sonos.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.