Application Security Engineer

Sonar Source
Austin
Workplace: OnsiteFull timeFunction: CybersecuritySkills: ["Security-by-design partnership","Root-cause analysis","Incident readiness","Risk prioritization","Automation mindset"]

Partner with product, platform, and infrastructure teams to build secure, resilient Sonar products and AWS-based cloud architecture “by design.” Conduct application security assessments, including authentication/authorization review and code review, and lead security assurance initiatives such as penetration tests and red-team exercises. Investigate complex product and internal security findings, drive remediation, support incident readiness, and use threat intelligence and security automation to scale the security program.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Sonar Source
Sonar Source
2 days ago

Application Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 1 hour agoStatus: Live

Job Summary

Partner with product, platform, and infrastructure teams to build secure, resilient Sonar products and AWS-based cloud architecture “by design.” Conduct application security assessments, including authentication/authorization review and code review, and lead security assurance initiatives such as penetration tests and red-team exercises. Investigate complex product and internal security findings, drive remediation, support incident readiness, and use threat intelligence and security automation to scale the security program.
Location: Austin
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity

Key Responsibilities

  • •Partner with product and engineering teams from early design stages to build secure, resilient solutions.
  • •Review product architectures and AWS environments to ensure security requirements inform technical decisions and final designs.
  • •Deliver security assurance initiatives, including security assessments, penetration tests, and red-team exercises, and translate findings into improvements and trust artifacts.
  • •Investigate complex product and internal security findings to identify root causes and drive durable remediation.
  • •Monitor threat intelligence, automate repeatable security work, and support incident response as needed, including on-call participation occasionally.

Pay and Benefits

Perks:Paid Leave401kPaid Parking

Key Requirements

  • •Extensive experience with application and cloud architectures, predominantly AWS.
  • •Experience conducting application security assessments, including code review and authentication/authorization evaluation.
  • •Experience assessing and securing AI and agentic AI capabilities and defining emerging best practices.
  • •Experience applying threat modeling approaches such as STRIDE to identify risks early.
  • •Experience with penetration testing, red-team engagements, and vulnerability triage through remediation and organizational learning.
Skills:Security-by-design partnershipRoot-cause analysisIncident readinessRisk prioritizationAutomation mindset
Tech Stack:AWSAzureGCPGoogle WorkspaceSTRIDEClaude CodeCodexCursorGitHub CopilotGeminiDevinSonarQubeSonarSweep

Company Brief

Sonar Source
Builds static code analysis and continuous inspection tools (SonarQube, SonarCloud, SonarLint) that identify bugs, vulnerabilities, and code smells across multiple languages to help teams improve code quality and maintainability.
Industry: Developer Tools
Company Size: Large (251 to 1,000 employees)
Growth: Established Company
Headquarters: Geneva, Switzerland
Founded: 2008
WebsiteLinkedIn