Senior Application Security Engineer

Sonos, Inc.

Glasgow

On-site

GBP 70,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Sonos, Inc. in Glasgow is looking for a Senior Product Security Engineer to enhance product security practices. You will own the execution layer of product security, ensuring consistent and measurable practices across cloud, mobile, and embedded environments. The ideal candidate will have over 4 years of relevant experience and a strong background in security tooling integration.

The position directly impacts Sonos' ability to meet regulatory requirements and enhances the entire engineering team's security confidence.

Qualifications

  • 4+ years of experience in software engineering, application security, or product security.
  • Experience working directly with engineering teams in software development environments.
  • Experience working with IoT products, connected devices, or embedded systems preferred.

Responsibilities

  • Own the execution layer of product security across cloud, mobile, and embedded engineering.
  • Deploy and operationalize security tooling in engineering workflows.
  • Support vulnerability intake, triage, and coordinated disclosure processes.

Skills

Experience integrating security practices and tooling into CI/CD pipelines.
Experience scoping or coordinating penetration testing engagements.
4+ years in software engineering, application security, or product security
Hands-on experience implementing and operationalizing security tooling
Using AI tools to automate security practices

Tools

SAST
SCA
DAST
Secrets scanning

Job description

Senior Product Security Engineer

At Sonos we want to create the ultimate listening experience for our customers and know that it starts by listening to each other. As part of the Sonos team, you’ll collaborate with people of all styles, skill sets, and backgrounds to realize our vision while fostering a community where everyone feels included and empowered to do the best work of their lives.

About Sonos

At Sonos, we create the world’s leading sound experiences. Our products span connected speakers, mobile applications, and cloud services — a technically diverse ecosystem where security is built into every layer.

What You’ll Do

You’ll own the execution layer of product security — the systems, tooling, and processes that make security practice consistent and measurable across cloud, mobile, and embedded engineering domains.

Security tooling and CI/CD integration
  • Deploy and operationalize SAST, SCA, secrets scanning, DAST, and SBOM generation across engineering workflows
  • Integrate security tooling into CI/CD pipelines in partnership with Engineering Productivity teams. Ensure tooling produces high-signal, low-noise output that engineers engage with.
Security testing and penetration testing
  • Define scalable security testing practices across cloud, mobile, web, and connected devices
  • Scope, coordinate, and interpret results from third‑party penetration testing engagements, including IoT and firmware assessments. Translate findings into clear remediation plans and track them through to closure.
Threat modeling and secure design
  • Support and scale threat modeling across cloud, mobile, and embedded domains including device‑cloud‑mobile trust boundaries
  • Provide practical secure design guidance throughout the SDLC — automating the groundwork wherever possible.
Vulnerability response and compliance
  • Support vulnerability intake, triage, and coordinated disclosure processes.
  • Partner with compliance and legal stakeholders to ensure security practices are auditable and regulatory‑aligned
Automate and scale security practice
  • Build and extend AI‑powered tooling that encodes security guidelines as agent skills
  • Replace static security documentation with automated workflows that embed security practice directly into engineering teams
What You’ll Bring
  • 4+ years in software engineering, application security, or product security
  • Experience working directly with engineering teams in modern software development environments
  • Hands‑on experience implementing and operationalizing security tooling: SAST, SCA, DAST, secrets scanning, or similar
  • Experience integrating security practices and tooling into CI/CD pipelines.
  • Experience using AI tools to automate security practices and previously manual activities
  • Experience scoping or coordinating penetration testing engagements and working with the results; experience with IoT or embedded device assessments is a strong plus
  • Experience working with IoT products, connected devices, or embedded systems is preferred but not required
Why This Role Matters

Sonos is in the transition from defining product security practices to executing them at scale. The tooling decisions are largely made, the strategy is set, and the regulatory requirements are real. What’s needed now is an engineer who can make it all work in practice — across cloud, mobile, and embedded domains — in a way that developers actually adopt.

This role directly shapes:

  • How securely Sonos products are built — not in theory, but in day‑to‑day engineering practice
  • Sonos’ ability to meet EU Cyber Resilience Act requirements, including PSIRT readiness and vulnerability reporting obligations
  • The engineering team’s confidence in their security posture, from SBOM generation to penetration test outcomes
  • The scalability of a small Product Security team supporting a large, distributed engineering organization
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

Sonos, Inc. • Glasgow

On-site
GBP 60,000 - 90,000
Senior Product Security Engineer - Secure SDLC & IoT
Senior Product Security Engineer - Secure SDLC & IoT

Sonos, Inc. • Glasgow

On-site
GBP 70,000 - 90,000
Senior App Security Engineer — AI-Driven CI/CD Security
Senior App Security Engineer — AI-Driven CI/CD Security

Sonos, Inc. • Glasgow

On-site
GBP 60,000 - 90,000
Product Security Engineer
Product Security Engineer

Action1 Corporation • United Kingdom

Hybrid
GBP 60,000 - 85,000
Fully remote work environment
Opportunity to work on a real security product
Close collaboration with teams
+1
Senior Product Security Specialist
Senior Product Security Specialist

Bestman Solutions • City Of London

Hybrid
GBP 70,000 - 90,000
Senior Security Engineer
Senior Security Engineer

Spendesk • Greater London

On-site
GBP 90,000 - 120,000
Security Engineer
Security Engineer

Copello • Uxbridge

Hybrid
GBP 85,000 - 120,000
Senior Security Engineer
Senior Security Engineer

Atarus • England

On-site
GBP 70,000 - 90,000
Budget for certifications
Opportunities for continuous learning
Clear progression to Staff / Principal Security Engineer
Lead Security Engineer
Lead Security Engineer

Winston Fox • Greater London

On-site
GBP 70,000 - 95,000
Security Engineering Lead
Security Engineering Lead

United States Digital Space LLC • Greater London

On-site
GBP 120,000 - 150,000
Equity in an early-stage tech company
25 days holiday plus local public hols
Apple hardware
+4