Senior Security Engineer
SonarSourceAbout the role
Who is Sonar?
Sonar is driving the future of agent-centric software development. As the leader in AI code review and verification, we solve a critical problem: ensuring that software generated by AI-assisted developers or autonomous agents is reliable, secure, and maintainable.
Integrating seamlessly with Claude Code, Codex, Cursor, GitHub Copilot, Gemini, and Devin, we help over 75% of the Fortune 100 build trusted, reliable, compliant software. Customers who use Sonar are 44% less likely to report an outage due to AI-generated code.
We believe code verification is the critical missing link in the Agent-Centric Development Cycle (AC/DC). Industry giants like Nvidia, ServiceNow, Booking.com, Goldman Sachs, AstraZeneca, and Ford Motor Company.count on us to provide independent, explainable, consistent review and governance of their AI-generated code via products like:
-
SonarQube: The world’s leading AI code review and verification platform.
-
SonarQube Foundation Agent: Currently topping the leaderboards for agentic software repair.
-
SonarSweep & Sonar Context Augmentation: Providing the enterprise-grade context and constraints agents need to be truly effective.
Our team operates across global hubs in Austin, Bochum, Dubai, Geneva, London, Singapore, Tokyo, and Washington D.C. We move with a mindset we call CODE:
-
Committed to our customers and community.
-
Obsessed with quality.
-
Deliberate in our decisions.
-
Effective as one team.
With over $400M in revenue and profitable, fast-paced growth, we are building the backbone of the AI software revolution. If you’re hungry to have an impact, want to build at a fast pace, and ready to work at the forefront of AI, we want to hear from you.
What you will do
-
Secure by design: Partner with product, platform, and infrastructure engineering teams to design and implement secure solutions.
-
Security review: Review cloud,network and endpoint architectures to ensure security requirements are identified early and integrated effectively.
-
Cloud security: Help engineering teams improve security across the software development lifecycle, cloud environments, and supporting services.
-
Vulnerability management: Investigate security findings, validate risk, partner with owners on remediation plans, and help drive issues to closure.
-
Security engineering projects: Develop and implement security specific solutions that support Sonar’s strategic security plan, including evaluating and introducing new tools and capabilities.
-
Data Leakage: Drive DLP efforts across the company.
-
Customer trust support: Investigate and help address customer security concerns related to Sonar products, cloud platforms, and security controls.
-
Security incidents: As needed, act as a security subject matter expert during investigations, containment, remediation, and post-incident follow-up.
-
Threat management: Review relevant threat intelligence, assess how it applies to Sonar, and recommend practical mitigations.
-
Standards and guidance: Contribute to security patterns, engineering guidance, and repeatable practices that make the secure path the easiest path for teams.
Experience and qualifications
-
You can demonstrate strong hands-on experience in security engineering, cloud security, application security, or a closely related discipline.
-
You can demonstrate in-depth experience with cloud architectures, primarily AWS.
-
You can demonstrate experience reviewing architectures and embedding security requirements into engineering and operational workflows.
-
You can demonstrate experience assessing and securing modern application environments, including AI and agentic AI feature
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s