Skip to content
← Back to job listings

Application Security Engineer

SonarSource · Austin, United States

Imported listingfull-time6 days ago

About The Role

Join Sonar, a rapidly growing company focused on safeguarding its products and cloud platforms. As an Application Security Engineer, you will partner with product, platform, and infrastructure engineering teams to ensure security is integrated into the design and operation of our products. You will lead security assurance initiatives, investigate security findings, and strengthen customer trust. Additionally, you will monitor threat intelligence and continuously improve security processes. Enjoy a range of benefits, including a 401K plan, healthcare coverage, and generous time off.

  • Partnership with product, platform, and infrastructure engineering teams to ensure security is integrated into the design and operation of products and cloud platforms.
  • Leading security assurance and improvement initiatives, including independent security assessments, penetration tests, and red-team exercises.
  • Monitoring and interpreting threat intelligence to prioritize risks and make actionable recommendations for improving security.
  • Experience applying threat-modeling approaches, such as STRIDE, to improve design discussions and identify risks early
  • Practical experience using AI to automate repeatable security work, along with enthusiasm for building small tools and experiments that make security teams faster and more effective
  • Experience assessing and securing AI and agentic AI capabilities, with the curiosity to experiment, learn, and help define emerging best practices
  • Extensive experience conducting application security assessments, including code review and evaluation of authentication and authorization designs
  • Experience with penetration testing, red-team engagements, and bug-bounty programs, with an attacker mindset focused on protecting what matters most
  • Threat awareness and security automation
  • Security assurance and remediation
  • Secure product and cloud architecture
  • Extensive experience with application and cloud architectures, predominantly AWS, and a strong interest in how modern cloud patterns can strengthen or weaken security
  • Experience investigating and managing vulnerabilities, from triage and prioritization through to remediation and organizational learning
  • Familiarity with Azure, GCP, and Google Workspace is a plus, as is the appetite to learn new platforms and ecosystems as Sonar evolves

This is an external listing. JobSpring does not represent or verify the employer. Report this listing