You and the process

With a person
Anna, in-house recruiter
9 years hiring engineers
30 minutes with a real recruiter
They read your CV with you, on a call, and say where the offers are being lost.
Didn’t find what you were looking for? Tell us what to build
Be the first to open itNo views yet
Sonos

Senior Application Security Engineer

  • Hybrid
  • 6+ years

Salary

Not stated

AI summary

For members

The whole posting in a few lines. Sign up to read it here and on every role you open.

Sign Up to Read

Description

At Sonos we want to create the ultimate listening experience for our customers and know that it starts by listening to each other. As part of the Sonos team, you’ll collaborate with people of all styles, skill sets, and backgrounds to realize our vision while fostering a community where everyone feels included and empowered to do the best work of their lives.

Location: Glasgow - Hybrid (3 days in office)

About Sonos

Sonos makes the world's leading listening experiences — and the products behind them span a technically diverse ecosystem: embedded firmware, mobile applications, web platforms, cloud services, and partners. If you're looking for an opportunity to apply security principles across technical domains, and work on an outstanding consumer product, this is a great opportunity.

The Product Security team combines modern security tooling, automation, and AI with industry-defining security frameworks and direct development team partnerships. We enable secure-by-design and secure-by-default practices that are a natural part of how engineers work. We’re creating AI-powered workflows that encode security guidelines, automate the groundwork for threat modeling, and replace manual triage with intelligent pipelines. If you think security policy should run in a pipeline rather than live in a document, you'll fit right in.

Responsibilities

  • You’ll own the execution layer of product security — the systems, tooling, and processes that make security practice consistent and measurable across cloud, mobile, and embedded engineering domains;
  • Partner with engineering teams to identify and manage security risks across the software development lifecycle, from design through deployment
  • Integrate and operationalize security tooling across CI/CD workflows, ensuring findings are high-signal, actionable, and lead to practical remediation
  • Build automated and AI-assisted security workflows that turn security guidance into repeatable engineering practices and reduce manual effort
  • Lead threat modelling across product domains and help teams identify and address risks at key trust boundaries
  • Establish repeatable security testing practices using automation and targeted manual assessment
  • Coordinate penetration testing and targeted security assessments across relevant product domains
  • Support vulnerability intake, triage, remediation, coordinated disclosure, and Product Security Incident Response Team (PSIRT) readiness
  • What You’ll Bring
  • 3+ years in software engineering, application security, or product security
  • Experience working directly with engineering teams in modern software development environments
  • Hands-on experience implementing and operationalizing security tooling
  • Experience integrating security practices and tooling into CI/CD pipelines
  • Experience using AI tools to automate security practices and previously manual activities
  • Experience scoping or coordinating penetration testing engagements
  • #li-hybrid
  • Your profile will be reviewed and you'll hear from us once we have an update. At Sonos we take the time to hire right and appreciate your patience.

Where you’d work

Part of the week in the office

About the company

Sonos

Offices in Glasgow, United Kingdom, United Kingdom

Also hiring in Boston, United States, United States, NL, Canada and 3 more places

Your chances

Worth a look before you spend an evening tailoring a CV for it.

  • 19 checks run
  • 3 red flags

Still hiring?

13 checks

1 red flag

How crowded?

6 checks

2 red flags

Fits Me

How well does this role fit you?

Answer a few questions or drop your CV, and every role gets a fit score with the reasons, this one first.

  • Your field
  • Level
  • Stack
  • Work model
  • Salary floor
  • Must-haves
Details11 facts · Role, Location, Compensation, Employment
Tech stack
  • CI/CD
Seniority
Senior
Type
Full-time
Specialty
Security
Region
United Kingdom
Pay period
Annual
Show 5 more factsShow less

Role

Category
DevOps & Infrastructure
Specialty
Security
Seniority
Senior
Experience
3+ years
Tech stack
  • CI/CD

Location

Work model
Hybrid
Region
United Kingdom
Offices
  • Glasgow, United Kingdom
  • United Kingdom

Compensation

Salary
Salary by agreement
Pay period
Annual

Employment

Type
Full-time

Something wrong with this vacancy?

Similar vacancies

  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer, New Grad

    Salary by agreement

    • Office · Dublin
    • Junior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Senior Security Operations Analyst

    Salary by agreement

    • Hybrid · Wellington, Auckland
    • Senior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Platform Security Engineer

    £90,000 - 160,000 / year

    • Hybrid · London
    • Mid-Level
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer

    $275,000 - 345,000 / year

    • Office · London

Share this vacancy

What's wrong with it?

The employer never sees who reported.

Reason