Senior Product Security Engineering
Listed on 2026-06-14
-
IT/Tech
Cybersecurity, Systems Engineer
Senior Product Security Engineer
We are looking for a Senior Product Security Engineer to help operationalize security practices across our engineering organization. This is an execution-focused role: you’ll build the systems, integrate the tooling, and partner directly with product development teams to make secure design and development a consistent practice at scale.
What You’ll Do- Own the execution layer of product security — the systems, tooling, and processes that make security practice consistent and measurable across cloud, mobile, and embedded engineering domains.
- Deploy and operationalize SAST, SCA, secrets scanning, DAST, and SBOM generation across engineering workflows.
- Integrate security tooling into CI/CD pipelines in partnership with Engineering Productivity teams.
- Ensure tooling produces high-signal, low-noise output that engineers engage with.
- Define scalable security testing practices across cloud, mobile, web, and connected devices.
- Scope, coordinate, and interpret results from third‑party penetration testing engagements, including IoT and firmware assessments.
- Translate findings into clear remediation plans and track them through to closure.
- Support and scale threat modeling across cloud, mobile, and embedded domains including device‑cloud‑mobile trust boundaries.
- Provide practical secure design guidance throughout the SDLC — automating the groundwork wherever possible.
- Support vulnerability intake, triage, and coordinated disclosure processes.
- Partner with compliance and legal stakeholders to ensure security practices are auditable and regulatory‑aligned.
- Automate and scale security practice by building and extending AI‑powered tooling that encodes security guidelines as agent skills, replacing static security documentation with automated workflows.
- 4+ years in software engineering, application security, or product security.
- Experience working directly with engineering teams in modern software development environments.
- Hands‑on experience implementing and operationalizing security tooling: SAST, SCA, DAST, secrets scanning, or similar.
- Experience integrating security practices and tooling into CI/CD pipelines.
- Experience using AI tools to automate security practices and previously manual activities.
- Experience scoping or coordinating penetration testing engagements and working with the results; experience with IoT or embedded device assessments is a strong plus.
- Experience working with IoT products, connected devices, or embedded systems is preferred but not required.
Sonos is in the transition from defining product security practices to executing them tooling decisions are largely made, the strategy is set, and the regulatory requirements are real. This role directly shapes how securely Sonos products are built — not in theory, but in day‑to‑day engineering practice; how Sonos meets EU Cyber Resilience Act requirements, including PSIRT readiness and vulnerability reporting obligations;
and the engineering team’s confidence in their security posture.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: