Senior Security Engineer
TLDR
Provide expertise in implementing secure architecture and automation to enhance vulnerability management while collaborating across teams at a leading software development company.
Secure by design: Partner with product, platform, and infrastructure engineering teams to design and implement secure solutions.
Security review: Review cloud, network and endpoint architectures to ensure security requirements are identified early and integrated effectively.
Cloud security: Help engineering teams improve security across the software development lifecycle, cloud environments, and supporting services.
Vulnerability management: Investigate security findings, validate risk, partner with owners on remediation plans, and help drive issues to closure.
Security engineering projects: Develop and implement security specific solutions that support Sonar’s strategic security plan, including evaluating and introducing new tools and capabilities.
Data Leakage: Drive DLP efforts across the company.
Customer trust support: Investigate and help address customer security concerns related to Sonar products, cloud platforms, and security controls.
Security incidents: As needed, act as a security subject matter expert during investigations, containment, remediation, and post-incident follow-up.
Threat management: Review relevant threat intelligence, assess how it applies to Sonar, and recommend practical mitigations.
Standards and guidance: Contribute to security patterns, engineering guidance, and repeatable practices that make the secure path the easiest path for teams.
You can demonstrate strong hands-on experience in security engineering, cloud security, application security, or a closely related discipline.
You can demonstrate in-depth experience with cloud architectures, primarily AWS.
You can demonstrate experience reviewing architectures and embedding security requirements into engineering and operational workflows.
You can demonstrate experience assessing and securing modern application environments, including AI and agentic AI features.
You can demonstrate experience with vulnerability investigation, prioritization, and remediation management.
You can demonstrate practical scripting and automation experience using tools such as Python or Bash.
You are comfortable working across technical and non-technical stakeholders and can communicate risk and recommendations clearly.
Experience with SaaS environments. Wiz, CrowdStrike, and Google Workspace are a plus.
At Sonar, we believe that our diversity is our strength. We are a global company that values and respects different backgrounds, perspectives, and cultures. We are committed to fostering a diverse and inclusive work environment where everyone feels valued and empowered to contribute their best. We are proud to be an equal opportunity employer and welcome all qualified applicants, regardless of race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.
If you need any accommodation, please reach out to us at [email protected].
All offers of employment at Sonar are contingent upon the results of a comprehensive background check and reference verification conducted before the start date.
We do not currently support visa candidates in the US.
Applications that are submitted through agencies or third party recruiters will not be considered.
SonarSource builds powerful code quality and security tools that help developers prevent issues in software production. Targeting development teams and organizations of all sizes, their solutions streamline workflows and enhance productivity, leveraging both human and AI-driven contributions. With support for over 30 programming languages and widespread adoption, SonarSource is committed to creating secure, reliable, and maintainable applications.
- Founded
- Founded 2008
- Employees
- 51-200 employees
- Industry
- Internet Software & Services
- Total raised
- $45M raised