Job Description
Who is Sonar?
Sonar is driving the future of agent-centric software development. As the leader in AI code review and verification, we solve a critical problem: ensuring that software generated by AI-assisted developers or autonomous agents is reliable, secure, and maintainable.
Integrating seamlessly with Claude Code, Codex, Cursor, GitHub Copilot, Gemini, and Devin, we help over 75% of the Fortune 100 build trusted, reliable, compliant software. Customers who use Sonar are 44% less likely to report an outage due to AI-generated code.
We believe code verification is the critical missing link in the Agent-Centric Development Cycle (AC/DC). Industry giants like Nvidia, ServiceNow, Booking.com, Goldman Sachs, AstraZeneca, and Ford Motor Company.count on us to provide independent, explainable, consistent review and governance of their AI-generated code via products like:
SonarQube: The world’s leading AI code review and verification platform.
SonarQube Foundation Agent: Currently topping the leaderboards for agentic software repair.
SonarSweep & Sonar Context Augmentation: Providing the enterprise-grade context and constraints agents need to be truly effective.
Our team operates across global hubs in Austin, Bochum, Dubai, Geneva, London, Singapore, Tokyo, and Washington D.C. We move with a mindset we call CODE:
Committed to our customers and community.
Obsessed with quality.
Deliberate in our decisions.
Effective as one team.
With over $400M in revenue and profitable, fast-paced growth, we are building the backbone of the AI software revolution. If you’re hungry to have an impact, want to build at a fast pace, and ready to work at the forefront of AI, we want to hear from you.
Position description
As an Application Security Researcher, you play a central role in realizing our ambition to provide the best SAST solution on the market. Like us, you believe that application security is not the responsibility of a few experts and that developers can have the biggest impact when they get the right information at the right time.
As a member of the Code Security team, you decide what security issues the product should detect and how they materialize in various language ecosystems. You work closely with static analysis developers to specify, clarify, communicate, and validate all functional aspects of the security rules.
You will be a trusted adviser of developers, able to provide meaningful code samples and specifications. This is a great way to have a direct impact on the product and, ultimately, on how millions of developers produce code.
🎯Stop Job Hunting. Start Job Matching.
Jessie's Underground Rolodex — personalized, Jessie-powered search
⚡ Most applicants are flying blind
Fire off a cold application and your resume vanishes into the ATS black hole—no fit score, no signal, no reply. Jessie matches your resume to roles from our network and shows you exactly where you're a strong fit before you apply.
Upload your resume once and get personalized job matches with exact fit scores—powered by Jessie's matching engine.
★Smart Matching
See your match percentage for every job. Only apply where you're 70%+ qualified.
★50 Personalized Searches
Full access for 120 days. Fresh roles from our network.
🚀 Try 3 Free Searches - Upload ResumeStart FREE • $9.99 CAD for 50 searches • Reloads $3.99 • 120-day access
✓ Fresh roles from our network • ✓ Your resume, your control