You'll own the execution layer of product security - the systems, tooling, and processes that make security practice consistent and measurable across cloud, mobile, and embedded engineering domains.
Security tooling and CI/CD integration
Deploy and operationalize SAST, SCA, secrets scanning, DAST, and SBOM generation across engineering workflows
Integrate security tooling into CI/CD pipelines in partnership with Engineering Productivity teams. Ensure tooling produces high-signal, low-noise output that engineers engage with.
Security testing and penetration testing
Define scalable security testing practices across cloud, mobile, web, and connected devices
Scope, coordinate, and interpret results from third-party penetration testing engagements, including IoT and firmware assessments. Translate findings into clear remediation plans and track them through to closure.
Threat modeling and secure design
Support and scale threat modeling across cloud, mobile, and embedded domains including device-cloud-mobile trust boundaries
Provide practical secure design guidance throughout the SDLC - automating the groundwork wherever possible.
Vulnerability response and compliance
Support vulnerability intake, triage, and coordinated disclosure processes.
Partner with compliance and legal stakeholders to ensure security practices are auditable and regulatory-aligned
Automate and scale security practice
Build and extend AI-powered tooling that encodes security guidelines as agent skills
Replace static security documentation with automated workflows that embed security practice directly into engineering teams
Requirements
4+ years in software engineering, application security, or product security
Experience working directly with engineering teams in modern software development environments
Hands-on experience implementing and operationalizing security tooling: SAST, SCA, DAST, secrets scanning, or similar
Experience integrating security practices and tooling into CI/CD pipelines.
Experience using AI tools to automate security practices and previously manual activities
Experience scoping or coordinating penetration testing engagements and working with the results; experience with IoT or embedded device assessments is a strong plus
Experience working with IoT products, connected devices, or embedded systems is preferred but not required
Why This Role Matters
This role directly shapes:
How securely Sonos products are built - not in theory, but in day-to-day engineering practice
Sonos' ability to meet EU Cyber Resilience Act requirements, including PSIRT readiness and vulnerability reporting obligations
The engineering team's confidence in their security posture, from SBOM generation to penetration test outcomes
The scalability of a small Product Security team supporting a large, distributed engineering organization
#LI-hybrid
Your profile will be reviewed and you'll hear from us once we have an update. At Sonos we take the time to hire right and appreciate your patience.
Benefits
Vision insurance
Additional Information
At Sonos we want to create the ultimate listening experience for our customers and know that it starts by listening to each other. As part of the Sonos team, you'll collaborate with people of all styles, skill sets, and backgrounds to realize our vision while fostering a community where everyone feels included and empowered to do the best work of their lives.
Senior Product Security Engineer
About Sonos
At Sonos, we create the world's leading sound experiences. Our products span connected speakers, mobile applications, and cloud services - a technically diverse ecosystem where security is built into every layer.
We're looking for a Senior Product Security Engineer to help operationalize security practices across our engineering organization. This is an execution-focused role: you'll build the systems, integrate the tooling, and partner directly with product development teams to make secure design and development a consistent practice at scale.