Sonar

Software Development

ApplicationSecurityResearcher

Bochum, Germany FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Mid+ candidates.

The Brief

“Application Security Researcher at Sonar. Skills: Application Security, Static Analysis, SAST. Build expertise on language ecosystems. Identify common vulnerabilities”

What You'll Achieve.

Provide the best SAST solution on the market

Industry & Context.

Software Development
Eligibility Requirements

Must be willing to be in Bochum

What They're Looking For.

Must Have

Mastering application security basics, Knowing the most common vulnerabilities, How to locate vulnerabilities in the code, How to exploit basic vulnerabilities, Having a developer mindset, Experience with coding lifecycle, Ability to produce secure code, Ability to do code reviews, Ability to jump into an unknown codebase, Ability to jump into an unknown language, Ability to jump into an unknown framework, Master at least one programming language, Master its development environment, Communication skills, Listening constructive ideas, Expressing constructive ideas, High level of autonomy, Accepting help from team members, Accepting feedback from team members, Ability to work with non-security experts, Ability to communicate with non-security experts

Nice to Have

Understanding of static analysis mechanisms, Ability to challenge rule implementation

What You'll Do.

Build expertise on language ecosystems

Identify common vulnerabilities

Investigate how vulnerabilities materialize

Define static analysis rules

Interact with user community

Clarify user feedback

Turn feedback into actions

Refine vulnerability detection rules

Improve taint-analyzer reports

Drive innovation for SAST engine

How You'll Work.

Team & Collaboration

Work and communicate with non-security experts; Accepting help and feedback from team members

Communication Scope

Communication skills; Listening constructive ideas; Expressing constructive ideas; Ability to communicate with non-security experts

Full Job Description

## Description Who is Sonar?   Sonar is driving the future of agent-centric software development. As the leader in AI code review and verification, we solve a critical problem: ensuring that software generated by AI-assisted developers or autonomous agents is reliable, secure, and maintainable. Integrating seamlessly with Claude Code, Codex, Cursor, GitHub Copilot, Gemini, and Devin, we help over 75% of the Fortune 100 build trusted, reliable, compliant software. Customers who use Sonar are 44% less likely to report an outage due to AI-generated code. We believe code verification is the critical missing link in the Agent-Centric Development Cycle (AC/DC). Industry giants like Nvidia, ServiceNow, Booking.com, Goldman Sachs, AstraZeneca, and Ford Motor Company.count on us to provide independent, explainable, consistent review and governance of their AI-generated code via products like: SonarQube: The world’s leading AI code review and verification platform. SonarQube Foundation Agent: Currently topping the leaderboards for agentic software repair. SonarSweep & Sonar Context Augmentation: Providing the enterprise-grade context and constraints agents need to be truly effective. Our team operates across global hubs in Austin, Bochum, Dubai, Geneva, London, Singapore, Tokyo, and Washington D.C. We move with a mindset we call CODE: Committed to our customers and community. Obsessed with quality. Deliberate in our decisions. Effective as one team. With over $400M in revenue and profitable, fast-paced growth, we are building the backbone of the AI software revolution. If you’re hungry to have an impact, want to build at a fast pace, and ready to work at the forefront of AI, we want to hear from you.   Position description   As an Application Security Researcher, you play a central role in realizing our ambition to provide the best SAST solution on the market. Like us, you believe that application security is not the responsibility of a few experts and that developers can hav

Free ATS check

Applying for this Application Security Researcher role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Lever

  • Lever uses a streamlined one-page form — apply in under 5 minutes.
  • LinkedIn import works well; review parsed data before submitting.
  • The cover letter field is optional but visible to reviewers — use it to differentiate.
  • Referral codes from employees can significantly boost visibility of your application.

ANONYMOUS · UNFILTERED

What do employees actually say about Sonar?

Real rants from real employees. Read before you apply.

Read Company Rants →