Application Security Engineer

Sonar Source
Geneva
Workplace: OnsiteFull timeFunction: CybersecuritySkills: ["Partnering with engineering teams","An attacker mindset","Investigative analysis","Translating findings","Incident readiness"]

Partner with product, platform, and infrastructure teams to bake security into Sonar’s products and supporting cloud platforms. Review architectures (including AWS environments), run security assurance through penetration tests and red-team exercises, investigate complex security findings, and improve incident readiness. Use threat intelligence and threat modeling (e.g., STRIDE) to prioritize risks, remediate vulnerabilities end-to-end, and automate repeatable security work—also assessing AI/agentic security capabilities to define emerging best practices.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Sonar Source
Sonar Source
3 days ago

Application Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 13 hours agoStatus: Live

Job Summary

Partner with product, platform, and infrastructure teams to bake security into Sonar’s products and supporting cloud platforms. Review architectures (including AWS environments), run security assurance through penetration tests and red-team exercises, investigate complex security findings, and improve incident readiness. Use threat intelligence and threat modeling (e.g., STRIDE) to prioritize risks, remediate vulnerabilities end-to-end, and automate repeatable security work—also assessing AI/agentic security capabilities to define emerging best practices.
Location: Geneva
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Partner with product, platform, and infrastructure teams to design and operate products and cloud platforms to Sonar’s security bar.
  • •Review product architectures and AWS environments to ensure security requirements inform technical decisions and final designs.
  • •Deliver security assurance initiatives, including deploying modern security tools and capabilities across the organization.
  • •Plan and manage independent security assessments (penetration tests, red-team exercises) and translate findings into practical improvements and trust artifacts.
  • •Investigate customer security concerns and complex internal security findings, drive durable remediation, and support teams during incidents (occasional on-call).

Key Requirements

  • •Extensive experience securing application and cloud architectures, predominantly AWS.
  • •Experience conducting application security assessments, including code review and evaluating authentication and authorization designs.
  • •Experience assessing and securing AI and agentic AI capabilities and defining emerging best practices.
  • •Experience applying threat-modeling approaches such as STRIDE to identify risks early and improve design discussions.
  • •Experience with penetration testing, red-team engagements, and bug-bounty programs, plus vulnerability triage through remediation and organizational learning.
Experience:CloudApplication securityPenetration testingAIAgentic AI
Skills:Partnering with engineering teamsAn attacker mindsetInvestigative analysisTranslating findingsIncident readiness
Tech Stack:AWSAzureGCPGoogle WorkspaceSTRIDE

Company Brief

Sonar Source
Builds static code analysis and continuous inspection tools (SonarQube, SonarCloud, SonarLint) that identify bugs, vulnerabilities, and code smells across multiple languages to help teams improve code quality and maintainability.
Industry: Developer Tools
Company Size: Large (251 to 1,000 employees)
Growth: Established Company
Headquarters: Geneva, Switzerland
Founded: 2008
WebsiteLinkedIn