Talent.com
Platform Security Engineer
Platform Security EngineerSaronic • San Diego, CA, US
Platform Security Engineer

Platform Security Engineer

Saronic • San Diego, CA, US
[job_card.30_days_ago]
[job_preview.job_type]
  • [job_card.permanent]
[job_card.job_description]

Job Description

Job Description

Saronic Technologies is a leader in revolutionizing defense autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations for the Department of Defense (DoD) through autonomous and intelligent platforms.

Saronic Technologies is a leader in defense autonomy at sea. We’re seeking a Platform Security Engineer to secure the cloud / edge where vessels, operators, and customers meet. You’ll own identity and access patterns, secrets and key management, secure network posture, and policy-as-code guardrails—working across AWS (including GovCloud), Terraform infrastructure, and service code to deliver trustworthy, auditable systems.

Senior Engineers : 3+ years securing production cloud platforms (identity, secrets / KMS, network posture), preferably in autonomy, robotics, aerospace, or defense.

Staff Engineers : 8+ years including technical leadership across secure-by-default platform modules, short-lived credential issuance, and cross-account policy design; demonstrated ownership from design through operational rollout.

Key Responsibilities

  • Design, develop, and maintain secure-by-default infrastructure on
  • AWS using Terraform (ALB / OIDC, IAM, KMS, Secrets Manager, Route53, VPC / SGs).
  • Standardize OIDC at the edge (ALB / ingress) for internal and external applications; define scopes, claims, and token lifecycles.
  • Own secrets and key management : KMS key policies, rotation schedules, cross-account access, and automated issuance for services and tools.
  • Enforce IMDSv2 required, least-privilege IAM roles, and tight security groups across modules; add CI / policy checks to prevent regressions.
  • Design secure protocols / APIs for service↔service and boat↔cloud communication (mTLS / TLS, certificate issuance / rotation, revocation).
  • Manage short-lived credentials used by fleet / overlay services; implement rotation, auditing, and incident response runbooks.
  • Prefer service-mediated S3 access over broad pre-signed URLs; codify bucket policies, logging, and access boundaries.
  • Build centralized, tamper-evident logging and audit trails; integrate detections and metrics to validate control effectiveness.
  • Perform threat modeling and security reviews; document patterns and drive adoption via reusable modules and guides.
  • Troubleshoot complex security issues in production; lead post-incident reviews and drive remediation to closure.
  • Stay current on cloud security best practices, especially for defense / government environments.

Required Qualifications :

  • Bachelor’s or Master’s degree in Computer Science, Software / Computer / Electrical Engineering, or a related field.
  • 3+ years building on AWS with Terraform (ALB / ELB, IAM, KMS, Secrets Manager, Route53, VPC / SGs).
  • Strong knowledge of cryptographic and IAM fundamentals (key policies, rotation, certificates, OIDC / OAuth2).
  • Demonstrated experience enforcing IMDSv2, least-privilege roles, and network controls at scale.
  • Experience designing secure protocols / APIs and integrating auth into service code (e.g., Go / Rust / TypeScript).
  • Proven ability to perform threat modeling and conduct design / code security reviews.
  • Excellent problem-solving and communication skills; effective collaboration across platform, embedded, and field teams.
  • This role requires the ability to obtain and maintain a security clearance
  • Preferred Qualifications :

  • Experience in AWS GovCloud, multi-account landing zones, and cross-account KMS / Secrets patterns
  • Familiarity with fleet / overlay VPN access control and short-lived credential issuance
  • Policy-as-code guardrails (e.g., OPA / Conftest, Terraform validations), drift detection, and CI integration
  • Centralized logging / SIEM and cloud threat detection (e.g., CloudTrail, GuardDuty) with audit readiness
  • PKI / CA management and, ideally, hardware roots of trust (TPM / secure elements) at the edge
  • DoD / defense domain familiarity and prior work under export-controlled constraints
  • Benefits :

    Medical Insurance :   Comprehensive health insurance plans covering a range of services

    Saronic pays 100% of the premium for employees and 80% for dependents

    Dental and Vision Insurance :   Coverage for routine dental check-ups, orthodontics, and vision care

    Saronic pays 100% of the premium under the basic plan for employees and 80% for dependents

    Time Off :   Generous PTO and Holidays

    Parental Leave :   Paid maternity and paternity leave to support new parents

    Competitive Salary :   Industry-standard salaries with opportunities for performance-based bonuses

    Retirement Plan :  401(k) plan

    Stock Options :  Equity options to give employees a stake in the company’s success

    Life and Disability Insurance :  Basic life insurance and short- and long-term disability coverage

    Pet Insurance :  Discounted pet insurance options including 24 / 7 Telehealth helpline

    Additional Perks :  Free lunch benefit and unlimited free drinks and snacks in the office

    This role requires access to export-controlled information or items that require “U.S. Person” status. As defined by U.S. law, individuals who are any one of the following are considered to be a “U.S. Person” : (1) U.S. citizens, (2) legal permanent residents (a.k.a. green card holders), and (3) certain protected classes of asylees and refugees, as defined in  8 U.S.C. 1324b(a)(3) .

    Saronic does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits.

    [job_alerts.create_a_job]

    Engineer Platform • San Diego, CA, US

    [internal_linking.similar_jobs]
    Principal Full-Stack Engineer : Cloud, AI & Security Leader

    Principal Full-Stack Engineer : Cloud, AI & Security Leader

    Blue Shield of CA • San Diego, CA, United States
    [job_card.full_time]
    A healthcare organization is seeking a Full Stack Engineer, Principal to advance care coordination and technology initiatives. You will lead the architecture and delivery of innovative healthcare so...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Corporate Security Engineer

    Corporate Security Engineer

    Saronic • San Diego, CA, US
    [job_card.permanent]
    Saronic Technologies is a leader in revolutionizing defense autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations for the Department of Defense (DoD) ...[show_more]
    [last_updated.last_updated_30] • [promoted]
    RedHat DevSecOps Engineer

    RedHat DevSecOps Engineer

    Scientific Research Corporation • San Diego, CA, United States
    [job_card.full_time]
    Estimated Starting Salary Range : USD $96,600.Salary to be determined by the education, experience, knowledge, skills, and abilities of the applicant, internal equity, and alignment with market data...[show_more]
    [last_updated.last_updated_variable_hours] • [promoted] • [new]
    Air Interdiction Agent

    Air Interdiction Agent

    US Customs and Border Protection • Santee, CA, US
    [job_card.full_time]
    Pilot—CBP Air Interdiction Agent.NEW RECRUITMENT AND RETENTION INCENTIVES!.Air and Marine Operations (AMO), a component of U. Customs and Border Protection (CBP), offers skilled Pilots interes...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Forward Deployed Software Engineer - US Government

    Forward Deployed Software Engineer - US Government

    Palantir Technologies • San Diego, CA, US
    [job_card.full_time]
    Palantir builds the world’s leading software for data-driven decisions and operations.By bringing the right data to the people who need it, our platforms empower our partners to develop lifes...[show_more]
    [last_updated.last_updated_30] • [promoted]
    ServiceNow Security Organization (SSO) Associate Application Security Engineer Intern

    ServiceNow Security Organization (SSO) Associate Application Security Engineer Intern

    ServiceNow • San Diego, California, USA
    [job_card.full_time]
    The ServiceNow Security Organization delivers world-class innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most s...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Software Engineer Platform Security

    Senior Software Engineer Platform Security

    ServiceNow • San Diego, California, USA
    [job_card.full_time]
    What you get to do in this role : .Design develop and maintain high-quality scalable and secure cryptographic solutions that meet the rigorous requirements of FIPS compliance and regulated environmen...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Network Defense and Firewall Security Engineer

    Network Defense and Firewall Security Engineer

    Systems Technology Forum • San Diego, California, USA
    [job_card.full_time]
    Systems Technology Forum LTD (STF) is an established industry partner with a passion for exceptional performance and an unwavering commitment to our clients. As a premier provider of management engi...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Principal Software Engineer

    Principal Software Engineer

    Tendo • San Diego, CA, US
    [job_card.full_time]
    We are looking for a software engineering leader who is passionate about creating next-generation healthcare software that will dramatically improve the lives of patients, clinicians, and caregiver...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Technology Vulnerability Management Engineer

    Technology Vulnerability Management Engineer

    Cooley LLP • San Diego, CA, United States
    [job_card.full_time]
    Technology Vulnerability Management Engineer.Cooley is seeking a Technology Vulnerability Management Engineer to join the Security team. Cooley Technology embraces a culture of customer service exce...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Information Security Engineer

    Information Security Engineer

    InsideHigherEd • El Cajon, California, United States
    [job_card.full_time]
    Throughout Grossmont-Cuyamaca Community College District, CA.The Grossmont-Cuyamaca Community College District is seeking a qualified individual as an. The Incumbent is responsible for implementing ...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Embedded Security Engineer

    Embedded Security Engineer

    Saronic • San Diego, CA, US
    [job_card.permanent]
    Saronic Technologies is a leader in revolutionizing defense autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations for the Department of Defense (DoD) ...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Cyber Security Engineer III

    Cyber Security Engineer III

    PingWind • San Diego, CA, US
    [job_card.full_time]
    M in accordance with (IAW) DFARS 252.Baseline Certification, minimum IAT Level III .Bachelor’s degree in Cybersecurity, Cyber Operations, Cyber Engineering, Information System, Inf...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Staff Product Security Engineer (SSDL)

    Staff Product Security Engineer (SSDL)

    ServiceNow • San Diego, California, USA
    [job_card.full_time]
    PLEASE NOTE • • : This role requires a minimum of 2 days per week in our San Diego CA ServiceNow Office.Please do not apply if you cannot meet this requirement. The ServiceNow Security Organizati...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Manager Global Security Engineering

    Manager Global Security Engineering

    DexCom • San Diego, California, USA
    [job_card.full_time]
    Dexcom Corporation (NASDAQ DXCM) is a pioneer and global leader in continuous glucose monitoring (CGM).Dexcom began as a small company with a big dream : To forever change how diabetes is managed.To...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Cybersecurity Engineer III

    Cybersecurity Engineer III

    Clearance Jobs • San Diego, CA, US
    [job_card.full_time]
    Senior Cybersecurity Engineer III.Imagine One is currently seeking multiple candidates for "contingent" positions supporting the U. We are looking for Senior Cybersecurity Engineer III to provide re...[show_more]
    [last_updated.last_updated_variable_hours] • [promoted] • [new]
    Cyber Security Engineer, Principal

    Cyber Security Engineer, Principal

    Qualcomm • San Diego, CA, United States
    [job_card.full_time]
    Information Technology Group, Information Technology Group > .Addresses the requirement for engineering practitioners in cybersecurity functions. Protects vital electronic systems and data from attac...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Security Agent - Hillcrest - 137731

    Security Agent - Hillcrest - 137731

    UC San Diego • San Diego, CA, United States
    [job_card.full_time]
    West Arbor Drive, San Diego, CA 92103, United States .Filing Deadline : Fri 12 / 19 / 2025.UC San Diego values and welcomes people from all backgrounds. If you are interested in being part o...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]