Application Security Researcher (f/m/d)

Sonar

Deutschland

Vor Ort

EUR 60.000 - 80.000

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

Sonar is seeking an Application Security Researcher to enhance their SAST solution. This role involves identifying common vulnerabilities, defining detection rules, and collaborating with developers to improve security measures in coding.

Located in Bochum, this position favors candidates eager to make a significant impact in the realm of AI-driven software development.

Join us in our commitment to quality, diversity, and innovation—shaping the future of code security.

Qualifikationen

  • Mastering application security including common vulnerabilities and their exploitation.
  • Experience with coding lifecycle and secure code production.
  • Master at least one programming language and its development environment.

Aufgaben

  • Build expertise on various language ecosystems and common vulnerabilities.
  • Investigate how vulnerabilities materialize in code.
  • Define static analysis rules for vulnerability detection.
  • Interact with user community for feedback on vulnerability rules.
  • Drive innovation for the SAST engine.
  • Study competitors and provide gap analyses.

Kenntnisse

Application security basics
Developer mindset
Strong communication skills
Ability to work autonomously

Jobbeschreibung

Overview

Who is Sonar?

Sonar is driving the future of agent-centric software development. As the leader in AI code review and verification, we solve a critical problem: ensuring that software generated by AI-assisted developers or autonomous agents is reliable, secure, and maintainable.

Integrating seamlessly with Claude Code, Codex, Cursor, GitHub Copilot, Gemini, and Devin, we help over 75% of the Fortune 100 build trusted, reliable, compliant software. Customers who use Sonar are 44% less likely to report an outage due to AI-generated code.

We believe code verification is the critical missing link in the Agent-Centric Development Cycle (AC/DC). Industry giants like Nvidia, ServiceNow, Booking.com, Goldman Sachs, AstraZeneca, and Ford Motor Company.count on us to provide independent, explainable, consistent review and governance of their AI-generated code via products like:

  • SonarQube: The world's leading AI code review and verification platform.
  • SonarQube Foundation Agent: Currently topping the leaderboards for agentic software repair.
  • SonarSweep & Sonar Context Augmentation: Providing the enterprise-grade context and constraints agents need to be truly effective.

Our team operates across global hubs in Austin, Bochum, Dubai, Geneva, London, Singapore, Tokyo, and Washington D.C. We move with a mindset we call CODE:

  • Committed to our customers and community.
  • Obsessed with quality.
  • Deliberate in our decisions.
  • Effective as one team.

With over $400M in revenue and profitable, fast-paced growth, we are building the backbone of the AI software revolution. If you're hungry to have an impact, want to build at a fast pace, and ready to work at the forefront of AI, we want to hear from you.

Position description

As an Application Security Researcher, you play a central role in realizing our ambition to provide the best SAST solution on the market. Like us, you believe that application security is not the responsibility of a few experts and that developers can have the biggest impact when they get the right information at the right time.

As a member of the Code Security team, you decide what security issues the product should detect and how they materialize in various language ecosystems. You work closely with static analysis developers to specify, clarify, communicate, and validate all functional aspects of the security rules.

You will be a trusted adviser of developers, able to provide meaningful code samples and specifications. This is a great way to have a direct impact on the product and, ultimately, on how millions of developers produce code.

What you will do
  • Build expertise on various language ecosystems in order to identify the most common vulnerabilities that developers are facing.
  • Investigate how these vulnerabilities materialize within the code.
  • Define the static analysis rules that will detect these vulnerabilities.
  • Interact with our user community to clarify this invaluable feedback and turn it into actions/decisions, such as refining too noisy vulnerability detection rules or improving taint-analyzer vulnerability reports with contextual information.
  • Drive innovation to make our SAST engine even better.
  • Study competitors and provide gap analyses.
Experience and qualifications
Technical skills
  • Mastering application security basics, including knowing the most common vulnerabilities, how to locate vulnerabilities in the code, and how to exploit basic vulnerabilities. To be successful, you should be interested or involved in the application security ecosystem.
  • Having a developer mindset: experience with coding lifecycle, ability to produce secure code, to do code reviews, and to jump into an unknown codebase, language, and framework.
  • Master at least one programming language along with its development environment to understand end-users\' context and expectations.
Soft skills
  • Strong communication skills, i.e. both listening and expressing constructive ideas.
  • High level of autonomy and still accepting help and feedback from team members.
  • Ability to work and communicate with non-security experts.
Nice to have
  • Understanding of static analysis mechanisms.
  • Ability to challenge rule implementation.
Additional comments

This role is based in Bochum. We are unable to consider candidates unwilling to be in Bochum, but we are willing to relocate the right candidate.

We value diversity, equity, and inclusion

At Sonar, we believe that our diversity is our strength. We are a global company that values and respects different backgrounds, perspectives, and cultures. We are committed to fostering a diverse and inclusive work environment where everyone feels valued and empowered to contribute their best. We are proud to be an equal opportunity employer and welcome all qualified applicants, regardless of race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.

If you need any accommodation, please reach out to us at [email protected].

All offers of employment at Sonar are contingent upon the results of a comprehensive background check and reference verification conducted before the start date.

We do not currently support visa candidates in the US.

Applications that are submitted through agencies or third party recruiters will not be considered.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Major Incident Manager (f/m/d)
Major Incident Manager (f/m/d)

Sonar • Bochum

Vor Ort
EUR 68.000 - 102.000
Relocation assistance
Competitive salary
Site Reliability Engineering Lead (f/m/d)
Site Reliability Engineering Lead (f/m/d)

Sonar • Bochum

Vor Ort
EUR 105.000 - 160.000
Pension scheme 1st pillar
Pension scheme 2nd pillar
28 PTO days (Geneva region)
+4
AI Researcher - Post-Training (f/m/d)
AI Researcher - Post-Training (f/m/d)

Sonar • Bochum

Vor Ort
EUR 90.000 - 167.000
Major Account Manager - DACH
Major Account Manager - DACH

Sonarsource • Bochum

Vor Ort
EUR 110.000 - 190.000
Agentic Software Engineer (f/m/d)
Agentic Software Engineer (f/m/d)

Sonarsource • Bochum

Vor Ort
EUR 90.000 - 130.000
Pension Scheme: 1st Pillar (Unterstütz
Pension Scheme: 2nd Pillar (bAV)
28 PTO days (Geneva region)
+3
Agentic Software Engineer (f/m/d)
Agentic Software Engineer (f/m/d)

United States Digital Space LLC • Bochum

Vor Ort
EUR 90.000 - 120.000
Pension 1st Pillar
Pension 2nd Pillar
28 PTO days
+2
Engineering Manager - Cloud Platform & Operations (f/m/d)
Engineering Manager - Cloud Platform & Operations (f/m/d)

Jackalope Digital LLC • Bochum

Hybrid
EUR 90.000 - 135.000
Pension Scheme: 1st Pillar
Pension Scheme: 2nd Pillar
28 PTO days (Geneva region)
+3
Site Reliability Engineering Lead (f/m/d)
Site Reliability Engineering Lead (f/m/d)

Sonarsource • Bochum

Vor Ort
EUR 120.000 - 180.000
Pension (1st Pillar)
Pension (2nd Pillar)
28 PTO days (Geneva region)
+2
Engineering Manager - Cloud Platform & Operations (f/m/d)
Engineering Manager - Cloud Platform & Operations (f/m/d)

United States Digital Space LLC • Bochum

Vor Ort
EUR 90.000 - 140.000
Pension Scheme 1st Pillar
Pension Scheme 2nd Pillar
28 PTO days (Geneva region)
+2
Agentic Software Engineer
Agentic Software Engineer

Sonar • Bochum

Vor Ort
EUR 80.000 - 110.000
Pension scheme 1st pillar
Pension scheme 2nd pillar
28 PTO days
+4