Application Security Engineer — SonarSource (Sonar)
- Location
- Genève
- Contract
- full-time
- Posted
- 23 days ago
Role overview
Who is Sonar?
Sonar is driving the future of agent-centric software development.
As the leader in AI code review and verification, we solve a critical problem: ensuring that software generated by AI-assisted developers or autonomous agents is reliable, secure, and maintainable.
- Who is Sonar?
- Sonar is driving the future of agent-centric software development.
Application process
- Extensive experience with application and cloud architectures, predominantly AWS, and a strong interest in how modern cloud patterns can strengthen or weaken security.
- Extensive experience conducting application security assessments, including code review and evaluation of authentication and authorization designs.
- Experience assessing and securing AI and agentic AI capabilities, with the curiosity to experiment, learn, and help define emerging best practices.
- Experience applying threat-modeling approaches, such as STRIDE, to improve design discussions and identify risks early. Security assurance and remediation
- Experience with penetration testing, red-team engagements, and bug-bounty programs, with an attacker mindset focused on protecting what matters most.
- Applications that are submitted through agencies or third party recruiters will not be considered.
Contacts
- If you need any accommodation, please reach out to us at [email protected] .
- All offers of employment at Sonar are contingent upon the results of a comprehensive background check and reference verification conducted before the start date.
Company and context
- Deliver high-impact initiatives from the strategic security plan, from evaluating new approaches to deploying modern security tools and capabilities across the organization.
- Plan and manage independent security assessments, penetration tests, and red-team exercises; translate findings into practical improvements and customer-facing trust artifacts.
- Investigate complex product and internal security findings, identify root causes, and help teams implement durable remediation.
- Strengthen customer trust and incident readiness
- Lead the investigation and resolution of customer security concerns with rigor and empathy, using each engagement to reinforce confidence in our security program.
- Serve as a security subject-matter expert during incidents, helping teams understand, contain, and learn from emerging threats.
- Occasional on-call participation may be required.
- Anticipate threats and scale the security program
- Monitor and interpret threat intelligence, turning changes in the threat landscape into prioritized risks and actionable recommendations.
- Continuously improve and automate security processes, increasing the quality, speed, and visibility of information that informs the security strategy. Experience and qualifications Secure product and cloud architecture
Additional details
- Our team operates across global hubs in Austin, Bochum, Dubai, Geneva, London, Singapore, Tokyo, and Washington D.C. We move with a mindset we call CODE:
- If you’re hungry to have an impact, want to build at a fast pace, and ready to work at the forefront of AI, we want to hear from you. Position description
- You will champion security by design, partnering with product, platform, and infrastructure engineering teams so that our products and cloud platforms are imagined, built, and operated to Sonar’s high security bar.
- Review product architectures and AWS environments, ensuring security requirements meaningfully inform technical decisions and final designs. Lead security assurance and improvement
- Continuously improve and automate security processes, increasing the quality, speed, and visibility of information that informs the security strategy. Experience and qualifications Secure product and cloud architecture
- Experience applying threat-modeling approaches, such as STRIDE, to improve design discussions and identify risks early. Security assurance and remediation
- Experience investigating and managing vulnerabilities, from triage and prioritization through to remediation and organizational learning. Threat awareness and security automation
- Familiarity with Azure, GCP, and Google Workspace is a plus, as is the appetite to learn new platforms and ecosystems as Sonar evolves. Additional comments
- We are unable to consider candidates unwilling to be in Geneva , but we are willing to relocate the right candidate. We value diversity, equity, and inclusion
Notes and original content
- Our team operates across global hubs in Austin, Bochum, Dubai, Geneva, London, Singapore, Tokyo, and Washington D.C.
- We move with a mindset we call CODE:
- If you’re hungry to have an impact, want to build at a fast pace, and ready to work at the forefront of AI, we want to hear from you.
- Position description
- What you will do
- Review product architectures and AWS environments, ensuring security requirements meaningfully inform technical decisions and final designs.
- Lead security assurance and improvement
- Continuously improve and automate security processes, increasing the quality, speed, and visibility of information that informs the security strategy.
- Experience and qualifications
- Secure product and cloud architecture
Questions about this listing
What salary does SonarSource (Sonar) offer for this role?
SonarSource (Sonar) lists CHF 71'000 - 107'500 gross per year for this position in Genève. This is the salary published in the original listing (or, when the employer omits a figure, a realistic estimate for the role and sector) — the calculator on this site converts it to your actual net take-home once cross-border tax and social contributions are applied.
Is this a full-time role, and what type of contract does SonarSource (Sonar) offer?
This listing is a full-time position. The contract type shown here comes directly from the employer's original posting; always confirm exact hours, notice period and probation length with SonarSource (Sonar) during the application process, since these details can vary by role even within the same contract category.
Do I need a cross-border work permit for a role in Geneva?
EU/EFTA residents living in the border zone of the country adjoining Canton Geneva can apply for a G permit; the Swiss employer files it with that canton's migration office after the contract is signed. Border-zone rules and processing times vary by neighbouring country and canton, so confirm the specifics with Geneva's cantonal migration office or with HR during the application.
How do I apply for this position at SonarSource (Sonar)?
Use the "Apply now" button on this page — it links directly to SonarSource (Sonar)'s original listing at jobs.lever.co, so your application goes straight to the employer's own applicant-tracking system. Frontaliere Ticino does not collect or forward applications itself.