Security Engineer, Network Security

Saronic

San Diego (CA)

On-site

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Saronic in San Diego, CA seeks a Security Engineer to own network security end to end across enterprise, on‑prem and AWS cloud, including vessel communications. You will partner with IT, Cloud Security, Operations, and engineering teams to secure every path from operator to vessel.

The role emphasizes designing secure architectures, implementing Zero Trust, managing cryptography and keys, and building observability and automation for scalable, resilient networks in challenging environments.

Qualifications

  • 5+ years of hands-on enterprise network security experience.
  • Strong fundamentals: routing/BGP, TCP/UDP, TLS/PKI, DNS.
  • Experience with firewalls (Palo Alto, Cisco, Aruba) and VPN/Zero Trust.
  • Background in cryptography, key management, and secure links over constrained networks.

Responsibilities

  • Own enterprise and cloud network security end to end across on‑prem, AWS, and vessel communications.
  • Design secure network architecture including VPC segmentation and private connectivity.
  • Implement zero-trust/ZTNA and retirement of flat networks and legacy VPNs.
  • Develop network observability, telemetry, and NOC support with IT teams.
  • Automate network security using infrastructure‑as‑code and configuration validation.

Job description

  • Security at Saronic is a force multiplier, not a blocker
  • We’re looking for a Security Engineer to own network security end to end, including the corporate enterprise, our on-prem and production environments, our AWS cloud, and the communications and cryptography that keep autonomous vessels connected in contested, bandwidth-limited environments
  • Today this work is handled part-time by engineers with other primary duties; you will own it
  • You’ll partner with Information Technology, Enterprise Technology, Internal Apps, Infrastructure, Software, Mission Operations, Forward Deployed Engineers, Cloud Security, Product Security, and Security Operations and the teams building our vessels and their communications to secure every path from the operator to the vessel
  • This is an opportunity to design network security across a uniquely broad surface (enterprise, on-prem, cloud, and vessel comms), solve genuinely hard problems in securing constrained maritime links, and build the automation that keeps segmentation enforced as the footprint scales
  • Enterprise & On-Prem Network Security: Own firewalls, segmentation and microsegmentation, wireless, DNS, VPN/ZTNA, and device hardening across a growing multi-site footprint, including corporate offices, data centers, and on-prem and production environments (i.e., Palo Alto, Cisco, Aruba; GlobalProtect, Tailscale/WireGuard, IPsec)
  • Move the enterprise toward zero-trust access and retire flat-network and legacy-VPN patterns
  • Cloud Network Security: Design secure network architecture in AWS (commercial and GovCloud): VPC segmentation, private connectivity, and egress control
  • Vessel Communications & Cryptography: Secure all vessel networking and communications, including cellular (LTE/5G), RF and radio links, SATCOM, mesh networking, and line-of-sight and beyond-line-of-sight connectivity, along with the command-and-control paths to and from vessels and platforms such as Echelon
  • Own cryptography and key management for platform communications, protect data in transit and at rest, and design resilient, secure links over intermittent, contested, low-bandwidth, and high-latency conditions
  • Network Observability & NOC: Increase network visibility and observability (flow logs, telemetry, and monitoring) across enterprise, on-prem, and cloud, and partner with Information Technology to support the build-out of the Network Operations Center (NOC)
  • Automation & Monitoring: Automate network security (segmentation-as-code, configuration validation) and support network-based

Ability to obtain and maintain a U.S. security clearance5+ years of hands-on enterprise network security experience, or an equivalent combination of experience and demonstrated abilityStrong L3-L7 fundamentals: routing/BGP, TCP/UDP, TLS/PKI, and DNSCloud network security experience (AWS VPC design and controls)Designed and operated firewalls, segmentation, VPN, and wireless in production (i.e., Palo Alto, Cisco, Aruba; GlobalProtect, WireGuard/IPsec)Zero Trust / SASE / ZTNA architectureNetwork observability and visibility tooling, and experience standing up or supporting a Network Operations Center (NOC)Secure design of SATCOM, RF, cellular, or mesh links; software-defined radio and spectrum awareness; COMSEC and cryptographic key managementNetwork automation at scale through scripting and Infrastructure-as-CodeExperience in defense, maritime, aerospace, or other high-assurance environmentsOccasional reaching, bending, or stooping to access file drawers, cabinets, or office suppliesLifting and carrying items up to 20 pounds occasionally (e.g., office supplies, packages)Visual acuity to read screens, documents, and reportsOccasional standing and walking within the officeProlonged periods of sitting at a desk and working on a computerManual dexterity to operate a computer keyboard, mouse, and other office equipment

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer, Network Security
Security Engineer, Network Security

Saronic Technologies • San Diego (CA)

On-site
USD 110,000 - 160,000
Medical Insurance
Dental and Vision Insurance
Time Off
+7
Security Engineer, Network Security
Security Engineer, Network Security

Saronic Technologies • Austin (TX)

On-site
USD 120,000 - 180,000
Medical Insurance
Time Off (PTO & Holidays)
Parental Leave
+5
Security Engineer: Zero-Trust Network & Vessel Communications
Security Engineer: Zero-Trust Network & Vessel Communications

Saronic Technologies • San Diego (CA)

On-site
USD 110,000 - 160,000
Medical Insurance
Dental and Vision Insurance
Time Off
+7
Network Security Engineer – Zero-Trust & Vessel Communications
Network Security Engineer – Zero-Trust & Vessel Communications

Saronic • San Diego (CA)

On-site
USD 120,000 - 160,000
Security Engineer, Cyber Threat Intelligence
Security Engineer, Cyber Threat Intelligence

Saronic • San Diego (CA)

On-site
USD 120,000 - 170,000
Security Engineer, Application Security
Security Engineer, Application Security

Saronic • Austin (TX)

On-site
USD 120,000 - 190,000
Security Engineer, Application Security
Security Engineer, Application Security

Saronic Technologies Inc. • Town of Texas (WI)

On-site
USD 120,000 - 150,000
Security Engineer, Application Security
Security Engineer, Application Security

Saronic Technologies • Austin (TX)

On-site
USD 120,000 - 180,000
Security Engineer, Application Security
Security Engineer, Application Security

Saronic Technologies • San Diego (CA)

On-site
USD 120,000 - 160,000
Network Security Engineer — Zero-Trust for Maritime Cloud
Network Security Engineer — Zero-Trust for Maritime Cloud

Saronic Technologies • Austin (TX)

On-site
USD 120,000 - 180,000
Medical Insurance
Time Off (PTO & Holidays)
Parental Leave
+5