As part of the Sonos team, you’ll collaborate with people of all styles, skill sets, and backgrounds to realize our vision while fostering a community where everyone feels included and empowered to do the best work of their lives.About SonosSonos makes the world's leading listening experiences — and the products behind them span a technically diverse ecosystem: embedded firmware, mobile applications, web platforms, cloud services, and partners. If you're looking for an opportunity to apply security principles across technical domains, and work on an outstanding consumer product, this is a great opportunity.The Product Security team combines modern security tooling, automation, and AI with industry-defining security frameworks and direct development team partnerships. We’re creating AI-powered workflows that encode security guidelines, automate the groundwork for threat modeling, and replace manual triage with intelligent pipelines. If you think security policy should run in a pipeline rather than live in a document, you'll fit right in.What You’ll DoYou’ll own the execution layer of product security — the systems, tooling, and processes that make security practice consistent and measurable across cloud, mobile, and embedded engineering domains.Automate and scale security practiceIntegrate and operationalize security tooling (SAST, SCA, secrets scanning, DAST, SBOM) across engineering workflows, ensuring findings are high-signal and actionablePartner with engineering teams to embed secure-by-design and secure-by-default practices directly into how they buildBuild and extend AI-powered security tooling that encodes guidelines as automated workflows — replacing manual review steps with intelligent pipelines that run in CI/CDTest, assess, and design securelyLead and scale threat modeling across cloud, mobile, and embedded domains, including device-cloud-mobile trust boundariesEstablish repeatable security testing practices using automation and targeted manual assessmentScope and coordinate third-party penetration testing engagements across cloud, mobile, web, and connected devices — including IoT and firmware assessmentsRespond and complySupport vulnerability intake, triage, coordinated disclosure, and PSIRT readinessWhat You’ll Bring4+ years in software engineering, application security, or product securityExperience working directly with engineering teams in modern software development environmentsHands-on experience implementing and operationalizing security tooling: SAST, SCA, DAST, secrets scanning, or similarExperience integrating security practices and tooling into CI/CD pipelines Experience using AI tools to automate security practices and previously manual activitiesExperience scoping or coordinating penetration testing engagements and working with the results; SummaryLocation: GlasgowType: Full time
Senior Security Applications Engineer in Glasgow employer: Sonos
At Sonos, we pride ourselves on fostering a collaborative and inclusive work environment where every team member is empowered to contribute their unique skills and perspectives. As a Senior Application Security Engineer, you'll not only play a crucial role in enhancing our product security but also benefit from our commitment to employee growth through innovative projects and cutting-edge technology. Located in a vibrant community, we offer a dynamic workplace that values creativity and encourages professional development, making it an exceptional place to build a rewarding career.