SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Saronic Technologies is building autonomous surface vessels for maritime defense. This Security Engineer role focuses on Application Security and DevSecOps, owning the security of the software development lifecycle, supply chain, and deployment infrastructure.
You will secure the SDLC by running threat modeling, secure design reviews, and code reviews for new and existing systems. You'll integrate SAST, DAST, and SCA tools into CI/CD pipelines, creating security gates that developers welcome rather than resist. Your goal is to make secure the default, not the exception.
You'll own software supply-chain security, including dependency management, SBOMs, artifact signing, provenance tracking, and reducing accumulated dependency and secrets exposure. You'll govern secrets management, application allowlisting/blocklisting, and support data-loss-prevention through software controls.
A key focus is designing and hardening infrastructure patterns for securely self-hosting applications across AWS, Azure, and on-premises environments. You'll provide hardened base images, network isolation, identity and secrets management, patching strategies, and monitoring so engineering teams can deploy securely by default without manual review bottlenecks.
You'll embed with engineering teams, build scalable security tooling, and partner closely with Software, DevOps, Cloud, and Platform Engineering. This is an opportunity to build the application-security function from a strong foundation and fix whole classes of problems rather than chasing individual bugs.
Required: 5+ years in application security, DevSecOps, or product security. Hands-on experience with secure SDLC (threat modeling, secure code review, SAST/DAST/SCA in CI/CD), software supply-chain security, secrets management, and securing self-hosted applications. Comfortable with scripting and Infrastructure-as-Code. Must be able to obtain and maintain a U.S. security clearance and have U.S. Person status.
Preferred: Container and cloud security, application allowlisting, experience self-hosting or delivering applications across AWS/Azure/on-prem, bug-bounty triage, or background in defense/aerospace/high-assurance environments.