NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Security Engineer in United Kingdom
24 days ago
Apply with autofill
Apply with autofill
Sonos·24 days ago
24 days ago

Senior Application Security Engineer

Glasgow, United KingdomMid · 5-8 yearsSecurity Engineer

Sign up free to see how well your resume matches this role.

Boost your chances at sonos

How you compare FREE

?
Your scoreYour score: not yet known
→
43
Top 10%Top 10%: 43 out of 100

Top 10% of NextRaise users matched against Security Engineer roles in United Kingdom.

Must-have skills for this role

  • sast
  • ci/cd
  • sca
  • dast

PDF or DOCX · no account needed

Apply faster with autofill FREEThe NextRaise extension autofills your application in one click.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

About this role

At Sonos we want to create the ultimate listening experience for our customers and know that it starts by listening to each other. As part of the Sonos team, you’ll collaborate with people of all styles, skill sets, and backgrounds to realize our vision while fostering a community where everyone feels included and empowered to do the best work of their lives.

Senior Product Security Engineer

About Sonos

At Sonos, we create the world’s leading sound experiences. Our products span connected speakers, mobile applications, and cloud services — a technically diverse ecosystem where security is built into every layer.

We’re looking for a Senior Product Security Engineer to help operationalize security practices across our engineering organization. This is an execution-focused role: you’ll build the systems, integrate the tooling, and partner directly with product development teams to make secure design and development a consistent practice at scale.

What You’ll Do

You’ll own the execution layer of product security — the systems, tooling, and processes that make security practice consistent and measurable across cloud, mobile, and embedded engineering domains.

Security tooling and CI/CD integration

  • Deploy and operationalize SAST, SCA, secrets scanning, DAST, and SBOM generation across engineering workflows

  • Integrate security tooling into CI/CD pipelines in partnership with Engineering Productivity teams. Ensure tooling produces high-signal, low-noise output that engineers engage with.

Security testing and penetration testing

  • Define scalable security testing practices across cloud, mobile, web, and connected devices

  • Scope, coordinate, and interpret results from third-party penetration testing engagements, including IoT and firmware assessments. Translate findings into clear remediation plans and track them through to closure.

Threat modeling and secure design

  • Support and scale threat modeling across cloud, mobile, and embedded domains including device-cloud-mobile trust boundaries

  • Provide practical secure design guidance throughout the SDLC — automating the groundwork wherever possible.

Vulnerability response and compliance

  • Support vulnerability intake, triage, and coordinated disclosure processes. 

  • Partner with compliance and legal stakeholders to ensure security practices are auditable and regulatory-aligned

Automate and scale security practice

  • Build and extend AI-powered tooling that encodes security guidelines as agent skills

  • Replace static security documentation with automated workflows that embed security practice directly into engineering teams

What You’ll Bring

  • 4+ years in software engineering, application security, or product security

  • Experience working directly with engineering teams in modern software development environments

  • Hands-on experience implementing and operationalizing security tooling: SAST, SCA, DAST, secrets scanning, or similar

  • Experience integrating security practices and tooling into CI/CD pipelines. 

  • Experience using AI tools to automate security practices and previously manual activities

  • Experience scoping or coordinating penetration testing engagements and working with the results; experience with IoT or embedded device assessments is a strong plus

  • Experience working with IoT products, connected devices, or embedded systems is preferred but not required
     

​Why This Role Matters

Sonos is in the transition from defining product security practices to executing them at scale. The tooling decisions are largely made, the strategy is set, and the regulatory requirements are real. What’s needed now is an engineer who can make it all work in practice — across cloud, mobile, and embedded domains — in a way that developers actually adopt.

This role directly shapes:

  • How securely Sonos products are built — not in theory, but in day-to-day engineering practice

  • Sonos’ ability to meet EU Cyber Resilience Act requirements, including PSIRT readiness and vulnerability reporting obligations

  • The engineering team’s confidence in their security posture, from SBOM generation to penetration test outcomes

  • The scalability of a small Product Security team supporting a large, distributed engineering organization

#LI-hybrid

Your profile will be reviewed and you'll hear from us once we have an update. At Sonos we take the time to hire right and appreciate your patience.

Company

Sonos
Glasgow, United Kingdom

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Sonos's careers site·first seen 4 Jul 2026·last verified 8 Sept 2026·How we source jobs

Similar jobs

  • Senior Security Engineer at capcoLondon, United Kingdom–match not yet calculated
  • Principal Security Engineer at capcoLondon, United Kingdom–match not yet calculated
  • Staff Security Engineer, Abuse Control at StripeLondon, United Kingdom–match not yet calculated
  • Security Engineer (Contractor) at gdmsiBlackwood, United Kingdom–match not yet calculated
  • Senior Security Engineer, AWS Security Verification & Validation Team at Amazon{"normalizedCountryCode":"GBR", United Kingdom–match not yet calculated

Browse more jobs

  • Security Engineer jobs in United Kingdom
  • Security Analyst jobs in United Kingdom
  • Penetration Tester jobs in United Kingdom
  • Cloud Security Engineer jobs in United Kingdom
  • Security Engineer jobs in United States
  • Security Engineer jobs in India