Senior Security Engineer

SonarSource US, Inc.
Austin, TX, United States
2 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Amazon Web Services Bash Shell Software as a Service Cloud Computing Security Encodings Information Leak Prevention Python (Programming Language) Software Engineering SONAR (Symantec) Software Vulnerability Management Cloud Platform System
+2 more
Software Security Gsuite

Job description

As a Senior Security Engineer in Austin, you will provide senior-level expertise to leadership, engineering, and Go-To-Market teams while assisting with incident response when necessary. Your primary focus will be partnering with infrastructure and product teams to implement secure-by-design architecture, practical security automation, and advanced vulnerability management., * Secure by design: Partner with product, platform, and infrastructure engineering teams to design and implement secure solutions.

  • Security review: Review cloud,network and endpoint architectures to ensure security requirements are identified early and integrated effectively.
  • Cloud security: Help engineering teams improve security across the software development lifecycle, cloud environments, and supporting services.
  • Vulnerability management: Investigate security findings, validate risk, partner with owners on remediation plans, and help drive issues to closure.
  • Security engineering projects: Develop and implement security specific solutions that support Sonar’s strategic security plan, including evaluating and introducing new tools and capabilities.
  • Data Leakage: Drive DLP efforts across the company.
  • Customer trust support: Investigate and help address customer security concerns related to Sonar products, cloud platforms, and security controls.
  • Security incidents: As needed, act as a security subject matter expert during investigations, containment, remediation, and post-incident follow-up.
  • Threat management: Review relevant threat intelligence, assess how it applies to Sonar, and recommend practical mitigations.
  • Standards and guidance: Contribute to security patterns, engineering guidance, and repeatable practices that make the secure path the easiest path for teams.

Requirements

Do you have experience in Vulnerability management?, * You can demonstrate strong hands-on experience in security engineering, cloud security, application security, or a closely related discipline.

  • You can demonstrate in-depth experience with cloud architectures, primarily AWS.
  • You can demonstrate experience reviewing architectures and embedding security requirements into engineering and operational workflows.
  • You can demonstrate experience assessing and securing modern application environments, including AI and agentic AI features.
  • You can demonstrate experience with vulnerability investigation, prioritization, and remediation management.
  • You can demonstrate practical scripting and automation experience using tools such as Python or Bash.
  • You are comfortable working across technical and non-technical stakeholders and can communicate risk and recommendations clearly.
  • Experience with SaaS environments. Wiz, CrowdStrike, and Google Workspace are a plus.

Benefits & conditions

Pulled from the full job description

  • 401(k) matching
  • Paid time off, * Flexible comprehensive employee benefit package.
  • We encourage usage of our robust time-off allocations. You will receive 23 days of PTO per calendar year (on a pro-rated basis depending on your employment start date), with additional time provided for sickness, life events and holidays
  • .We offer an exciting 401(k) plan that has a 4% match, fully vested on day one of participation.
  • Fully paid parking in the heart of downtown Austin, Texas.
  • Global workforce with employees in 20+ countries representing 35+ unique nationalities.
  • We have an annual kick-off somewhere in the world where we meet to build relationships and goals for the company.
  • Monthly catered events, and team events

About the company

Sonar is driving the future of agent-centric software development. As the leader in AI code review and verification, we solve a critical problem: ensuring that software generated by AI-assisted developers or autonomous agents is reliable, secure, and maintainable.

Integrating seamlessly with Claude Code, Codex, Cursor, GitHub Copilot, Gemini, and Devin, we help over 75% of the Fortune 100 build trusted, reliable, compliant software. Customers who use Sonar are 44% less likely to report an outage due to AI-generated code.

We believe code verification is the critical missing link in the Agent-Centric Development Cycle (AC/DC). Industry giants like Nvidia, ServiceNow, Booking.com, Goldman Sachs, AstraZeneca, and Ford Motor Company.count on us to provide independent, explainable, consistent review and governance of their AI-generated code via products like:

  • SonarQube: The world’s leading AI code review and verification platform.
  • SonarQube Foundation Agent: Currently topping the leaderboards for agentic software repair.
  • SonarSweep & Sonar Context Augmentation: Providing the enterprise-grade context and constraints agents need to be truly effective.

Our team operates across global hubs in Austin, Bochum, Dubai, Geneva, London, Singapore, Tokyo, and Washington D.C. We move with a mindset we call CODE:

  • Committed to our customers and community.
  • Obsessed with quality.
  • Deliberate in our decisions.
  • Effective as one team.

With over $400M in revenue and profitable, fast-paced growth, we are building the backbone of the AI software revolution. If you’re hungry to have an impact, want to build at a fast pace, and ready to work at the forefront of AI, we want to hear from you.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:17 min

Optimizing character encoding with Kim variable byte encoding

Douglas Crockford Douglas Crockford · World Congress 2024

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:12 min

Distilling cross-encoder models into smaller efficient sentence embedding models

Marek Suppa · LIVE

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

54 sec

Interpreting complex terminal commands safely using external explanation utilities

Dan Cranney +2 · LIVE

Videos

See all

Related articles

See all