Jobs and Careers
SO
Staff Security Engineer
SonarSourceUnited StatesRemotefull_timeVerifiedPosted 12 Apr 2026
About the role
What You Will Do Daily:
- Security Strategy: Support the development of strategic security goals and maintain their alignment with the company mission and priorities.
- Secure by design: Closely collaborate with product engineering teams to co‑create secure, resilient solutions, bringing security considerations into the earliest stages of design.
- Secure by design: Review product architectures and cloud solutions with a critical and curious eye, ensuring security requirements are not only integrated but actively shape the final design.
- Offensive security: Drive internal and external security reviews, penetration tests, and red‑team exercises that challenge assumptions and reveal real‑world attack paths, periodically.
- Offensive security: Lead the selection, coordination, and oversight of external pen testing services and security certifications, transforming their findings into meaningful improvements.
- Projects and initiatives: Drive high‑impact security initiatives from the strategic security plan — from evaluating new approaches to rolling out cutting‑edge tools and capabilities across the organization.
- Customer trust: Investigate and manage customer security concerns with empathy and rigor, turning challenging questions into opportunities to deepen trust.
- Resolve security issues: Dive into complex security findings in products and internal systems, investigate root causes, and guide teams to robust, sustainable remediation.
- Security incidents: Act as a security subject matter expert during security incidents, helping teams to quickly understand, contain, and learn from emerging threats.
The Experience You Will Need:
- You can demonstrate in‑depth experience with cloud architectures - primarily AWS and distributed networks, and you’re motivated to keep exploring how modern cloud patterns can both strengthen and weaken security.
- You can demonstrate deep experience with application security assessments, including reviewing code and evaluating authentication and authorization designs with a high level of curiosity and rigor.
- You can demonstrate experience assessing and securing AI, Agentic and MCPs, and you are eager to experiment, learn, and define best practices in this fast‑moving space.
- You can demonstrate experience in penetration testing, red‑team engagements, and bug bounty programs, and you enjoy thinking like an attacker to protect what matters most.
- You can demonstrate experience with vulnerability investigation and management, from triage and prioritization to driving remediation and learning across teams.
- You can demonstrate experience with threat modeling using frameworks like STRIDE, and you naturally use these techniques to spark better design discussions.
- You can demonstrate hands-on experience with coding, “vibe‑coding,” and scripting (for example, Python, Bash), and you enjoy building small tools and experiments that make security work faster and smarter.
- Familiarity with Azure, GCP, and Google Workspace is a plus and so is a desire to keep learning new platforms and ecosystems as Sonar evolves.
Why You Will Love It Here:
- Our culture and mission set us apart. We have a dynamic work culture that values respect and kindness and embraces the right to fail (and get right back up again!).
- Great people make a great company. We value people skills as much as technical skills and strive to keep things friendly while still being passionate leaders in our domains.
- We have a flexible work policy that includes 3 days in-office and 2 days work-from-home each week for those located near our office locations; some locations such as Dubai, India, Japan and Australia operate fully remotely.
- We have a growth mindset. We love learning and believe continuous education is critical to our success. In an ever-changing industry, new skills are necessary, and we're happy to help our team acquire them.
- As the leader in our field, our products and services are as strong as our internal team members.
- We embrace transparency with regular meetings, cascading messages and updates on the growth and success of our organization.
Benefits of Working with Sonar:
- Flexible comprehensive employee benefit package.
- We encourage usage of our robust time-off allocations. You will receive 23 days of PTO per calendar year (on a pro-rated basis depending on your employment start date), with additional time provided for sickness, life events and holidays.
- We offer an exciting 401(k) plan that has a 4% match, fully vested on day one of participation.
- Generous discretionary Company Grow
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s