← Back to results

threat-modeling jobs in San Diego

$128,900 – $219,100 · Posted 3 days ago

Design and build secure cryptographic services—including key management, PKI, and secrets distribution—for a large-scale multi-tenant SaaS platform. Apply ML/AI techniques to detect cryptographic misuse and anomalies in near real time.… Operate services on Kubernetes, manage CI/CD pipelines, and respond to security incidents. Requires 4+ years of production software engineering experience, advanced knowledge of distributed systems and cryptographic primitives, and demonstrated security-conscious coding practices.

San DiegoLast seen 1 day ago
$172,000 – $200,000 · Posted 3 days ago

Senior Application Security Engineer responsible for building and tuning Turquoise's application security scanning program (SAST, DAST, SCA, container, IaC scanning) and triaging findings from scans, penetration tests, and bug bounties. Day-to-day work includes partnering with engineering teams to remediate vulnerabilities, performing threat modeling, maintaining secure-coding standards, and supporting incident response for application-layer issues.… Requires 5+ years in application security or software engineering with security focus, deep hands-on experience with scanning tools, strong understanding of OWASP Top 10 and common vulnerability classes, and experience securing cloud environments and CI/CD pipelines.

San DiegoLast seen 1 day ago
$128,900 – $219,100 · Posted 4 days ago

Design and build secure cryptographic services (key management, PKI, secrets distribution) for ServiceNow's multi-tenant SaaS platform, ensuring FIPS compliance and regulated-environment requirements. Apply ML/statistical techniques to detect cryptographic misuse, anomalies in key usage, and suspicious access patterns in near real-time.… Operate services on Kubernetes, manage CI/CD pipelines, handle on-call duties, and collaborate with security architects to translate compliance requirements into production code. Requires 4+ years of production software engineering (Java, Go, or equivalent OO language), deep knowledge of distributed systems and cryptographic primitives, and hands-on Kubernetes deployment experience.

San DiegoLast seen 2 days ago
$240,000 – $345,000 · Posted 6 days ago

Lead a team of security engineers (staff, senior staff, principal levels) owning product security across Intuit's ecosystem, including security reviews, design consults, and risk evaluations. Transform security processes from manual to automation/agent-first, defining baseline controls and security standards for cloud platforms (AWS, GCP, Azure) while raising the bar for AI/agentic systems.… Partner with business and engineering leaders to surface risks early, inform decisions, and drive adoption of security controls across large organizations. Requires 8+ years in security engineering, 3+ years managing managers, deep technical expertise in application security and threat modeling, and demonstrated experience rebuilding security programs with hands-on automation.

San DiegoLast seen 5 days ago
$150,000 – $215,000 · Posted 6 days ago

Senior Cybersecurity Engineer applying cybersecurity principles throughout system lifecycles to identify and reduce cyber risk. Responsibilities include building and applying threat models (STRIDE, PASTA, attack trees), analyzing complex systems and architectures from a security perspective, identifying vulnerabilities and weaknesses, evaluating defensive technologies, and translating findings into actionable recommendations.… Requires 7+ years of industry experience, deep knowledge of cybersecurity engineering, system/network security, vulnerability analysis, and cyber risk management, plus an active DoD Secret Clearance with ability to obtain TS/SCI.

San DiegoLast seen 4 days ago
$150,000 – $215,000 · Posted 7 days ago

Senior Cybersecurity Engineer supporting Navy and DoD mission systems. The role involves applying cybersecurity engineering principles across the system lifecycle—building threat models (STRIDE, PASTA, attack trees), analyzing complex systems and networks for vulnerabilities, assessing cyber risk and mission impact, and translating findings into actionable engineering recommendations.… Requires 7+ years of industry experience, a Bachelor's in a technical field (Cybersecurity, Computer Science, Systems Engineering, or related), demonstrated threat-modeling expertise, and DoD 8570.01 IAM/IAT/IASAE certification.

San DiegoLast seen 5 days ago
$190,000 – $270,000 · Posted 10 days ago

Lead the security architecture for satellite onboard systems, designing secure boot chains, attestation mechanisms, and trust boundaries across hardware, firmware, and payload compute. You will conduct threat modeling, implement Hardware Root of Trust solutions (TPM, secure elements, eFuse), manage firmware signing processes, and develop incident response procedures for onboard system compromise.… The role requires close collaboration with hardware and firmware teams to embed security best practices throughout the platform development lifecycle, plus mentoring and recruiting for the security organization.

San DiegoLast seen 8 days ago
$167,500 – $251,300 · Posted 11 days ago

The Senior Security AI Risk Analyst will assess and secure AI-enabled systems at Sony Interactive Entertainment, identifying material security risks, control gaps, and data classification issues. The role requires translating findings into actionable recommendations, partnering with Responsible AI & Governance and security teams, and maintaining a portfolio view of emerging AI security trends.… Candidates must have 6+ years securing technical systems with recent hands-on generative AI experience, strong knowledge of modern AI stacks, and the ability to interrogate designs, trace data flows, and identify security weaknesses in LLM and agentic systems. The position demands both deep security fundamentals (identity, permissions, data protection, monitoring) and a practical builder mindset to use tooling, APIs, and automation to explore and improve systems.

San DiegoLast seen 9 days ago
$121,624 – $217,710 · Posted 11 days ago

Information Security Engineer III will lead security architecture reviews and threat modeling for data, analytics, AI, and cloud initiatives at an insurance company. The role involves designing and implementing security controls for AWS data platforms and AI/ML workloads, providing oversight of LLM usage and emerging AI threats, and mentoring engineering teams on secure development practices.… You will partner with Engineering, Cloud, Data, and Operations teams to embed security into system design, manage compliance with NIST, NYDFS, PCI DSS, and CPRA/CCPA standards, and evaluate third-party vendors and security tools. The position requires 8+ years of security engineering experience, 3-5 years in AWS cloud security, and expertise in threat modeling, risk assessment, and incident management.

San DiegoLast seen 9 days ago
Posted 11 days ago

AMD is seeking an AI Systems Security Architect to drive system-wide threat modeling and security analysis across hardware, firmware, and software platforms. The role involves designing secure debug architectures, writing platform security specifications, and leveraging AI-assisted engineering tooling to accelerate security analysis.… The ideal candidate has deep expertise in computer architecture, confidential computing, root of trust, boot chain architecture, firmware security, cryptography, and threat modeling at platform scope, with proficiency in C/C++ and experience securing AI/ML workloads at datacenter scale.

San DiegoLast seen 9 days ago
$153,600 – $215,000 · Posted 12 days ago

Lead embedded software and firmware development for Amazon's satellite RF systems, designing and implementing ASIC firmware, command systems, telemetry processing, and autonomous capabilities. Write robust software in Linux and RTOS environments, build hardware interfaces using protocols like I2C, SPI, UART, and Ethernet, and drive security architecture through threat modeling and secure coding practices.… Collaborate with hardware design teams to bring custom silicon from concept through secure bring-up and integration, optimizing for space-grade reliability and production testing.

San DiegoLast seen 10 days ago
$175,000 – $195,000 · Posted 12 days ago

Staff-level hands-on security engineer responsible for designing and implementing platform security across Crucible, cloud infrastructure, and edge deployments. You will write code, harden Kubernetes and Linux systems, build identity and access controls, secure the software supply chain, and automate security into CI/CD workflows.… The role requires 8+ years of security engineering experience, strong software engineering skills, deep cloud and container security expertise, and the ability to support accreditation processes like ATO.

San DiegoLast seen 10 days ago
Posted 15 days ago

This role leads product security engineering for FDA-regulated medical devices (Class I/II) and their cloud-connected platforms. The engineer owns the full security lifecycle—threat modeling, risk assessments, security architecture, secure SDLC integration, and regulatory documentation—balancing patient safety, data protection, and FDA compliance.… Responsibilities span device and cloud security, vulnerability management, SBOM processes, and cross-functional collaboration with engineering, quality, and regulatory teams. Required: 5+ years cybersecurity experience, hands-on work with embedded/cloud/application security, FDA submission experience, and medical device development background.

San DiegoLast seen 13 days ago
$157,000 – $235,000 · Posted 19 days ago

Design and build on-device security systems for Snap's Specs wearable devices, including permissions, access control, sandboxing, and trusted execution boundaries. Develop security and privacy controls for on-device AI features, focusing on model integrity, sensitive data handling, and inference-time protections.… Research and implement security features across Snap OS, firmware, applications, and cloud-connected surfaces. Improve fuzzing infrastructure, automated security testing, and continuous validation pipelines for OS components, IPC mechanisms, and AI data flows.

San DiegoLast seen 16 days ago
Posted 19 days ago

Secure the application development lifecycle and software supply chain as a Security Engineer, embedding with engineering teams to design and implement threat modeling, secure code review, SAST/DAST/SCA integration into CI/CD pipelines, and secrets management. Own dependency and supply-chain security including SCA, SBOMs, and artifact signing, while designing hardened infrastructure patterns for self-hosted applications across AWS, Azure, and on-premises.… Build durable tooling through scripting and Infrastructure-as-Code to scale security across the organization, making secure deployment and controls the default rather than exceptions.

San DiegoLast seen 17 days ago
$118,095 – $200,762 · Posted 21 days ago

Principal Cyber Architect supporting DoD systems engineering teams on Assessment and Authorization (A&A) activities, cyber design and implementation, and DevSecOps integration. Responsibilities include conducting vulnerability assessments, analyzing static/dynamic code scans, developing system security plans, and ensuring compliance with RMF controls and DISA STIGs.… Requires Bachelor's in Cyber/Systems/Software/Electrical Engineering plus 6+ years of experience and one DoDM 8140 compliant certification (CCSP, CISSP-ISSEP/ISSAP, CSSLP, or Cloud+). Experience with MBSE, Cameo, Zero Trust Architecture, threat modeling, and offensive security analysis preferred.

San DiegoLast seen 19 days ago
Posted 26 days ago

Senior Embedded Software Engineer responsible for developing complex real-time embedded systems for electroporation therapy delivery, including firmware, device drivers, middleware, embedded UI applications, and system-level software. The role requires 7+ years of embedded software development experience with modern C++, ARM Cortex-M processors, RTOS frameworks (ThreadX, FreeRTOS, etc.), and expertise in real-time control systems, closed-loop feedback, safety-critical software, and cybersecurity implementation.… Responsibilities span architecture design, hardware-software integration, verification and validation, CI/CD support, and cross-functional collaboration with electrical, mechanical, and regulatory teams. The candidate must demonstrate proficiency with embedded development tools, debugging hardware, IEC 62304/IEC 60601 compliance standards, and FDA cybersecurity guidance.

San DiegoLast seen 24 days ago
Posted 27 days ago

Senior embedded software engineer leading secure firmware development for satellite communication systems. Designs and implements hardware interfaces using protocols like I2C, SPI, UART, and Ethernet with embedded security controls.… Collaborates with hardware architects and security teams to bring custom silicon from concept through secure verification and production integration. Requires 7+ years of professional software engineering with deep expertise in secure embedded systems, RTOS, real-time constraints, threat modeling, and penetration testing methodologies.

San DiegoLast seen 5 days ago
$87,100 – $157,450 · Posted 1 month ago

This role combines risk management governance with specialty systems engineering (reliability, availability, radiation effects, cybersecurity) and model-based systems engineering (MBSE). The engineer will develop risk policies and mitigation strategies, conduct or facilitate reliability/availability/radiation/cybersecurity analyses, and translate these findings into SysML models in Cameo Systems Modeler for traceability and trade-study analysis.… The position requires cross-functional collaboration with program management, design engineering, and logistics to integrate specialty drivers into program baselines and compliance with standards like MIL-STD-785 and NIST RMF.

San DiegoLast seen 1 month ago
$115,000 – $200,000 · Posted 1 month ago

Conduct software security assessments, vulnerability testing, penetration testing, and threat analysis on TrellisWare products. Perform static and dynamic analysis, reverse engineering, and incident investigation while ensuring compliance with FIPS 140, NIST STIG, and other regulatory standards.… Requires 5+ years industry experience with 3+ years software development and 2+ years vulnerability testing, proficiency in Python/C++/Java, and at least one security certification (Security+, CISSP, OSCP, or SANS/GIAC).

San DiegoLast seen 16 days ago
$180,000 – $270,000 · Posted 1 month ago

Senior Staff Product Security Engineer responsible for security incident response, vulnerability detection and mitigation across Qualcomm products, particularly in mobile, IoT, and automotive domains. The role involves binary analysis and reverse engineering of exploits, secure code review, vulnerability assessment, security testing, and coordinating with external security researchers and customers on patch adoption and disclosure.… Requires 6+ years of security engineering experience with expertise in at least two areas such as binary analysis, incident response, fuzzing, malware analysis, embedded firmware security, or automotive security. Must work independently, evaluate new security tools and technologies, and communicate technical findings internally and externally.

San DiegoLast seen 1 month ago
$220,000 – $280,000 · Posted 1 month ago

Lead a comprehensive security architecture program for Logos Space's ground-based satellite terminals, with technical ownership of end-to-end security design across mmWave apertures, RF/baseband subsystems, and baseband hardware. Design and implement RF-related datalink security, secure wireless protocols, threat models, and secure provisioning workflows while ensuring compliance with FIPS and other cryptographic standards.… Mentor security engineers, oversee manufacturing security and chain-of-custody processes, and collaborate with hardware and RAN teams to integrate security controls. This is a hands-on role with potential to build a team, requiring 7–10 years of embedded security experience, proficiency in C/C++/Rust and Python, and deep knowledge of threat modeling, secure boot, firmware security, and anti-tampering mechanisms.

San DiegoLast seen 1 month ago
$80,000 – $110,000 · Posted 1 month ago

This cybersecurity engineer role focuses on securing cloud infrastructure (AWS, Azure, GCP), containerized environments (Docker, Kubernetes), and applications through vulnerability management, risk assessment, and security architecture review. The position requires hands-on experience with SIEM, EDR, WAF configuration, and embedding security scanning (SAST, DAST, SCA) into CI/CD pipelines.… The engineer will conduct threat modeling, manage IAM policies, perform penetration testing coordination, support incident response and post-incident reviews, and partner with engineering teams to balance security with delivery. The role also includes compliance support, vendor risk assessments, and serving in an on-call rotation for after-hours security incidents.

San DiegoLast seen 25 days ago
$157,000 – $235,000 · Posted 1 month ago

Design and implement security and privacy controls for on-device AI features on Snap OS, including model integrity, secure data handling, inference-time privacy protections, and sensor access controls. Research and develop security features across firmware, applications, system services, and cloud-connected device surfaces.… Improve fuzzing infrastructure, automated security testing, and continuous validation pipelines for OS components, IPC mechanisms, parsers, drivers, firmware, and AI data flows. Requires 5+ years developing production software in C, C++, or Rust and 3+ years building security or platform protection features for Linux-based, embedded, mobile, or wearable systems.

San DiegoLast seen 26 days ago
Posted 1 month ago

This Staff Engineer role owns and executes BD's product security lifecycle for FDA-regulated medical device dispensing systems and their cloud platforms. Key responsibilities include defining end-to-end security architecture, conducting threat modeling and risk assessments, implementing secure SDLC practices aligned to NIST/OWASP/BSIMM, managing SBOMs and vulnerability remediation, and ensuring regulatory compliance (IEC 62304, ISO 14971, FDA cybersecurity guidance).… The role requires 5+ years of cybersecurity experience with FDA Class I/II devices, hands-on expertise in embedded/cloud/application security, and the ability to balance security controls with usability while supporting FDA submissions.

San DiegoLast seen 1 month ago