Trusted by 6M devs, Sonar helps you build quality code quickly & systematically with our Clean as You Code methodology.
Security Engineer
Location
New York + 8 moreAll locations: New York | Switzerland | United Kingdom | Singapore | Germany | United Arab Emirates | India | Japan | Australia
Posted
80 days ago
Salary
0
Seniority
Senior
Job Description
Security Engineer
Sonar
Title: Security Engineer Location: Bochum Type: Employee / Full-Time Workplace: onsite Category: IT Ops Job Description: Who is Sonar? Who is Sonar? Sonar helps prevent code quality and code security issues from reaching production, amplifies developers' productivity in concert with AI assistants, and improves the developer experience with streamlined workflows. Sonar analyzes all code, regardless of who writes it — your internal team, genAI, or third parties — resulting in more secure, reliable, and maintainable applications. Rooted in the open source community, Sonar’s solutions support over 30 programming languages, frameworks, and infrastructure technologies. Today, Sonar is used by +7M developers and 400K organizations worldwide, including the DoD, Microsoft, NASA, MasterCard, Siemens, and T-Mobile. We believe in developing great products that are supported by great internal teams and a strong culture. We are highly committed to and obsessed with the company, users, each other, and our open source community. We have high standards and hold each other accountable for acting with positivity, dedication, thoughtfulness, empathy, and passion daily. We are deliberate with our decisions with high clarity of intention. At the same time, we feel extreme urgency and move forward quickly. And lastly, we are highly effective and operationally efficient. We operate collectively as One Team to accomplish our goals. At Sonar, CODE is more than just an acronym – it's a mindset that defines daily operations. Why You Should Apply: At Sonar, we’re a group of brilliant, motivated, and driven professionals working hard to help supercharge developers to build better, faster. Sonar helps to continuously improve code quality and code security while reducing developer toil. This means that developers can focus on doing more of what they love and less of what they don’t. Our solutions don’t just solve symptoms of problems – we help fix issues at the source – for all code, whether it's developer-written, AI-generated, or from third parties. We have a dynamic culture with employees worldwide and hub offices in the USA, Switzerland, the UK, Singapore, and Germany. Team members should be able to come to work every day, work on a product they are proud of, love what they do, and feel energized by their peers. With our roots deep in the open source community, we’re all about the mission: supercharge developers to build better, faster. The Impact You Will Have: We are still at the beginning of our growth journey and are continuously introducing new processes, technologies, and tools. In this role, you will: - Be a pivotal engineering contributor to the design, implementation, and operation of security controls and automation across our identity platforms, endpoints, and core IT services. - Own key parts of our IdP and access automation stack (e.g., SSO, SCIM, group‑based access, JIT access), ensuring that users get the right access at the right time with strong controls and auditability. - Design and maintain security monitoring, alerting, and SIEM integrations that give us real‑time visibility into identity, endpoint, and SaaS risks. - Partner with IT Ops, Information Security, and Infrastructure Engineering to ensure security controls are deeply integrated into operations (incident management, change, and problem processes), not bolted on. - Use and champion AI tooling to make security operations more efficient — from alert triage and runbook execution to knowledge retrieval and reporting. - Help define and improve how we measure the reliability and effectiveness of our security controls (SLIs/SLOs, error budgets, and dashboards), making risk and performance visible and actionable to stakeholders. What You Will Do Daily: - Security Monitoring, Alerting & SIEM Ownership: Working with the Information Security team, design, implement, and maintain alerting rules, dashboards, and runbooks across our SIEM and logging platforms, with a focus on identity, access, and SaaS security signals. Continuously tune alerts to reduce noise, improve fidelity, and align with error budgets and SLOs for critical security and identity services. - Endpoint Defense In Depth: Architect and implement our multilayer endpoint defence systems (e.g. Crowdstrike, Cyberark, Cloudflare, secure browser policies), balancing risk against usability in coordination with the Information Security team. - Identity Platform & Access Automation: Build and maintain automation for our identity platforms (e.g., SSO, SCIM provisioning, group‑based access policies, lifecycle workflows) in partnership with Information Security. Implement guardrails and policy‑as‑code for identity, ensuring changes are reviewed, tested, and auditable before reaching production. - Infrastructure as Code & Security Controls as Code: Use IaC and configuration management (e.g., Terraform, Ansible, or similar) plus scripting languages (e.g., Python, Go) to deploy and manage security tooling, integrations, and policies. Treat security controls (e.g., logging, scanning, hardening, secret management) as software artifacts that can be versioned, tested, and rolled back safely. - Observability & Integration with Core IT Operations: Ensure that logging, metrics, and tracing for security‑relevant systems (IdP, VPN, endpoint protection, critical SaaS) are robust, accurate, and integrated into our observability stack. Integrate security events and automations with ITSM and incident management workflows, enabling fast routing, triage, and resolution. - Incident Response & Post‑Incident Engineering: Participate in the on‑call rotation for relevant security and identity services. Lead or contribute to post‑incident reviews, turning root causes into preventative engineering changes (new alerts, automations, guardrails, or documentation) that reduce MTTR and recurrence. - AI‑Enabled Security Operations: Use AI tooling (e.g., LLM‑based assistants, automation platforms) to accelerate alert triage, enrichment, and investigation, while keeping humans in control of decisions. Identify opportunities to embed AI in security and IT operations workflows (e.g., threat intelligence and alert correlation) and help implement these safely and effectively. The Experience You Will Need: - Security Engineering & Operations Background: Significant hands‑on experience (4–7 years) in security engineering, security operations, or closely related roles in modern, fast‑paced environments (e.g., SaaS, enterprise IT, cloud‑native infrastructure). - Identity & Access Management Expertise: Practical experience operating IdPs and IAM systems at scale (e.g., Okta, Azure AD, or similar), including SSO, MFA, lifecycle management, and least‑privilege policies. Experience designing and implementing automated provisioning and deprovisioning (e.g., SCIM, HRIS integrations, group‑based and role‑based access models). - SIEM, Logging & Observability: Proven experience with SIEM and observability platforms (e.g., ELK/EFK, Splunk, Datadog, or similar), including writing and tuning detection rules, building dashboards, and working with large‑scale log ingestion. Comfort working with SLIs/SLOs and error budgets for critical services, and using these to guide priorities for hardening and automation. - Automation & Infrastructure as Code: Strong experience with IaC and configuration management tools (e.g., Terraform, CloudFormation, Ansible, or similar) and with scripting/programming languages (e.g., Python, Go, or equivalent) to automate security and operational tasks. Track record of converting manual, repetitive operational work into reliable automation and self‑service capabilities. - Security Controls Implementation: Experience implementing and operating security controls as code: vulnerability scanning, configuration baselines, secret management (e.g., HashiCorp Vault), key rotation, and certificate management. - Incident Management & Cross‑Functional Collaboration: Demonstrated experience participating in or leading incident response, root cause analysis, and post‑incident follow‑through in partnership with IT Ops, Security, and Engineering. Strong communication skills in English, able to explain complex security and operational topics to both technical and non‑technical audiences. - AI Fluency: Comfortable using modern AI tooling (e.g., LLM‑based assistants, automation frameworks) as part of daily work for analysis, content generation, and workflow automation. Ability to reason about where AI is and isn’t appropriate in security and operations, balancing speed with risk and control. Why You Will Love It Here: - Our culture and mission set us apart. We have a dynamic work culture that values respect and kindness and embraces the right to fail (and get right back up again!). - Great people make a great company. We value people skills as much as technical skills and strive to keep things friendly while still being passionate leaders in our domains. - We have a flexible work policy that includes 3 days in-office and 2 days work-from-home each week for those located near our office locations; some locations such as Dubai, India, Japan and Australia operate fully remotely. - We have a growth mindset. We love learning and believe continuous education is critical to our success. In an ever-changing industry, new skills are necessary, and we're happy to help our team acquire them. - As the leader in our field, our products and services are as strong as our internal team members. - We embrace transparency with regular meetings, cascading messages and updates on the growth and success of our organization. Benefits of Working with Sonar: - Pension Scheme: 1st Pillar (Unterstützungskasse): Automatic, financed by Sonar, 3% of gross salary, an additional benefit in addition to your salary. - Pension Scheme:2nd Pillar (bAV): Voluntary, 15% contribution by Sonar from social security savings. - We encourage usage of our robust time-off allocations with 28 PTO days for our employees based out of the Geneva region, plus additional days based on seniority and circumstances. - Sonar recognizes holidays on working calendar days. If the holiday date occurs on a Saturday, we will recognize the day on the preceding Friday. If the holiday date occurs on a Sunday, we will recognize the day on the following Monday. - Public transport reimbursement of 60% for annual subscription. - Generous discretionary Company Growth Bonus, paid annually. - Global workforce with employees in 20+ countries representing 35+ unique nationalities. - We have an annual kick-off somewhere in the world where we meet to build relationships and goals for the company. We Value Diversity, Equity, and Inclusion: At Sonar, we believe that our diversity is our strength. We are a global company that values and respects different backgrounds, perspectives, and cultures. We are committed to fostering a diverse and inclusive work environment where everyone feels valued and empowered to contribute their best. We are proud to be an equal opportunity employer and welcome all qualified applicants, regardless of race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. All offers of employment at Sonar are contingent upon the precise results of a comprehensive background check and reference verification conducted before the start date. We do not currently support visa candidates in the US. Applications that are submitted through agencies or third party recruiters will not be considered. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Establish long-term relationships within assigned accounts while developing an understanding of the client’s strategic goals and overall impact on business results. • Provide project leadership, coordination and architectural guidance for the customer’s Network Virtualization and major VMware initiatives. • Collaborate with multi-functional VMware project teams which could consist of VMware consultants, engineers, product management and support staff. • Map additional VMware solutions to the customer’s unique business and technical requirements. • Maintain a current knowledge of VMware’s load balancing and security solutions, along with a high-level technical knowledge of VMware’s product line and future product direction. • Lead and drive challenging requests across simultaneous client engagements. • Provide clear and constructive product feedback to VMware Product Management teams based on customer use-cases and requirements. • Understand the customer’s high-level business challenges while functioning as an advisory resource for “Best Practices” and driving adoption of VMware solutions within your accounts.
Security Design Architect
Control RisksThe global specialist risk consultancy - Helping organisations succeed in a volatile world
Role Description The Security Design Architect / Engineer role will be experienced in protective design, physical security, and/or civil construction to support the Client's Global Security Systems & Technology program. The individual will directly support the Design, Engineering, & Construction (DEC) team and will require a strong understanding of construction project life cycles, including pre-lease, design, and construction phases. In partnership with teammates, this individual will manage all aspects of project management and coordination of protective design requirements including: - Site hardening (barriers, fencing, lighting) - Structural hardening of the building perimeter (façades and doors) - Structural hardening of building interiors (lobbies, mailrooms, critical spaces) for new build and retrofit projects In addition, the position requires close coordination with operational and technological security teams as well as architects, engineers, manufacturers, and contractors across a variety of disciplines (Civil, Landscape, Architectural, and Structural). Responsibilities include, but are not limited to: - Lead daily operations and direct the implementation of guidelines and processes that ensures a cohesive, consistent, and uniformed global program. - Manage end-to-end protective design scope (pre-lease, planning, design, construction, quality assurance) ensuring on-time delivery while driving execution. - Partner with other project specialists responsible for similar processes to collaborate and consolidate project work. - Manage builds of existing and new construction and retrofits, protective design consultant selection, and third-party vendor recommendations. - Act as the liaison and point of contact for both internal and external cross-functional partners, third party vendors, and protective design consultants. - Foster strong cross-functional partnerships and provide clear, concise communication to both technical and non-technical stakeholders. - Meet regularly with stakeholders and project design teams to provide status updates and coordinate project specific requirements. - Provide ongoing communication of planning, project status, issues and risks in a timely fashion to internal global security team members and cross functional partners. - Support continual improvement efforts through evaluation of current practices; investigation of new products; development of presentation materials, forms, and guidance documents; coordination and execution of pilots for programs; and present recommendations and provide business justification to relevant partners. Qualifications - Bachelor’s degree in Architecture, Engineering (Architectural, Civil, Structural), and/or Construction Management with 3-5+ years of relevant work experience in design and construction supervision of offices. - Alternatively, 6+ years of experience in project management or design and construction of offices. - Knowledge of workplace or office design project, protective design and construction management in NORAM region. - Experience with PlanGrid, or ability to learn quickly. - Experience documenting, managing, and executing scalable and repeatable processes. - Experience in cross-functional and multi-disciplinary coordination through planning, design, and construction project phases. - Experience communicating technical information to both technical and non-technical stakeholders. - Proficient with Excel, Outlook, Word, PowerPoint. - Strong verbal and written communication, attention to detail, and organization. - Highly motivated and able to work independently without overhead guidance. - Comfortable working in a fast-paced and demanding setting. - Travel within region required. - Direct experience with protective design products, systems, and/or projects. Benefits - Medical Benefits - Prescription Benefits - FSA - Dental Benefits - Vision Benefits - Life and AD&D - Voluntary Life and AD&D - Disability Benefits - Voluntary Benefits - 401 (K) Retirement - Nationwide Pet Insurance - Employee Assistance Program
Security Architect
ChainGPTRanked #1 for Web3-AI infrastructure! Unleash AI's power with our tools for crypto trading, NFT creation, smart contract
Role Description We are seeking an experienced Security Architect to lead the end-to-end security strategy and implementation for the blockchain-based AI platform. This role requires deep expertise across cloud security, blockchain, Kubernetes, AI workloads, and secure software development practices. The Security Architect will be responsible for designing a comprehensive security architecture that spans infrastructure, application, data, and operations – ensuring the platform achieves enterprise-grade security, compliance, and resilience. Responsibilities - Architect and implement security frameworks across blockchain platforms, AI workloads, Kubernetes, and cloud infrastructure. - Define and own the security roadmap, ensuring alignment with business objectives and regulatory requirements. - Establish identity and access management (IAM) strategies, including secrets management, VPN/identity solutions, and Zero Trust principles. - Establish trust boundaries and enforce appropriate controls, including workload isolation, access restrictions, and data protection measures. - Design and oversee cloud (AWS) security architecture and enforce least-privilege access. - Implement Kubernetes security controls, including Pod Security Standards, network segmentation, and workload isolation. - Lead the creation of incident response playbooks, monitoring dashboards, and alerting mechanisms for blockchain, AI, and cloud environments. - Conduct regular security assessments, penetration tests, and threat modeling to validate platform resilience. - Collaborate with blockchain architects, AI engineers, DevOps, and business teams to ensure security is embedded across all phases of development and operations. - Stay current with emerging security standards, technologies, and threats in blockchain, AI, and cloud ecosystems. Qualifications - Proven expertise in security architecture design for cloud, blockchain, AI/ML, and distributed systems. - Strong knowledge of cloud security (AWS, Azure, or GCP), including IAM, audit logging, monitoring, and least privilege enforcement. - Deep understanding of blockchain security principles, including validator/node protection, consensus mechanisms, and key management. - Solid understanding of cryptography, PKI, zero-knowledge proofs, and security best practices. - Extensive experience with Kubernetes and container security, including pod security standards, workload isolation, network segmentation, and admission controls. - Proven ability to secure CI/CD pipelines and the software supply chain, including vulnerability scanning, artifact signing, and code integrity enforcement. - Familiarity with monitoring, logging, and incident response frameworks such as Prometheus and Grafana. - Experience in securing AI/ML workloads, covering model integrity, data confidentiality, GPU resource isolation, and inference security. - Proficiency with automation and scripting in Python, Go, or Rust to build and integrate security controls. Educational Qualifications - Bachelor’s or Master’s degree in Computer Science, Cybersecurity, or Information Security. - Certifications such as CISSP, CISM, CKA/CKS, or Cloud Security Specialty are a strong plus. Key Attributes - Strategic thinker with ability to anticipate threats and design proactive defenses. - Strong leadership skills with ability to mentor engineering teams and enforce best practices. - Excellent communication and collaboration skills to align security with business goals. - Hands-on mindset with the ability to design, implement, and validate security controls. Benefits - Work alongside the ChainGPT core team on high-impact AI and Web3 products across our ecosystem. - Remote-first setup with flexible hours, focused on outcomes, trust, and ownership. - Competitive compensation, with performance-based upside where applicable to the role. - Fast-moving environment with direct collaboration across all team members, including senior management, and clear accountability with no micromanagement. - The support to do your best work, including the tools you need, structured onboarding, and clear room to grow.
Senior Director of Security Architecture and Engineering (Public Sector)
Lumen TechnologiesLumen Technologies is self-described as a global company of 40,000+ professionals empowering businesses, government, and communities to “produce amazing things.” Driven by the
About Lumen Lumen connects the world. We are igniting business growth by connecting people, data and applications – quickly, securely, and effortlessly. Together, we are building a culture and company from the people up – committed to teamwork, trust and transparency. People power progress. We’re looking for top-tier talent and offer the flexibility you need to thrive and deliver lasting impact. Join us as we digitally connect the world and shape the future. The Role The Senior Director of Security Architecture & Engineering leads cybersecurity architecture and engineering for Lumen’s Public Sector portfolio. This role owns the strategy and technical roadmap for federal security services, ensuring compliance with FISMA, FedRAMP High, NIST 800‑53, TIC 3.0, CMMC, and related requirements. You will guide cloud and network security architecture, secure design practices, and ongoing modernization efforts while partnering with executives, government stakeholders, and cross‑functional teams. This Senior Director role is a critical executive position that ensures Lumen’s public sector security services remain highly secure, compliant, and technically superior in a rapidly evolving landscape. The ideal candidate is a visionary leader who can marry deep technical expertise with strategic business insight – someone who can chart a course for the future of security solutions and galvanize teams to turn that vision into reality. If you are excited by the challenge of protecting government networks with state-of-the-art architectures and leading a talented team in delivering on that mission, we encourage you to apply. Location This is a remote position open to candidates based anywhere in the U.S. The Main Responsibilities - Set the vision and multi‑year roadmap for public‑sector security architecture and secure service delivery. - Provide executive oversight of network, cloud, identity, and data‑protection architectures aligned to FedRAMP and federal standards. - Lead compliance strategy across FISMA, RMF, FedRAMP ATOs, and continuous monitoring. - Represent Lumen as a senior technical SME with government CIO/CISO stakeholders and internal executives. - Drive modernization of security platforms, cloud migration, automation, and SOC/SIEM evolution. - Lead and develop a high‑performing team of security architects and engineers. - Partner closely with Product, Operations, Program Management, and Compliance to deliver secure, reliable, and compliant solutions. What We Look For in a Candidate - 15+ years in cybersecurity or network engineering; 5–7+ years leading security architecture for mission‑critical or regulated environments. - Deep expertise in federal compliance frameworks (FISMA, NIST RMF, FedRAMP, TIC 3.0, CMMC). - Broad technical mastery across cloud security, network architecture, identity, SIEM/SOC design, automation, and modern security platforms. - Strong executive communication and stakeholder‑management skills. - Proven ability to define strategy, build roadmaps, and drive cross‑functional execution. - Master’s degree required; CISSP/CISM preferred. U.S. citizenship and federal fuitability clearance required. Secret+ clearance preferred. - Financial acumen in budgeting, cost modeling, and investment planning. Compensation This information reflects the anticipated base salary range for this position based on current national data. Minimums and maximums may vary based on location. Individual pay is based on skills, experience and other relevant factors. Location Based Pay Ranges: $171,447 - $228,596 in these states: AL, AR, AZ, FL, GA, IA, ID, IN, KS, KY, LA, ME, MO, MS, MT, ND, NE, NM, OH, OK, PA, SC, SD, TN, UT, VT, WI, WV, and WY. $180,020 - $240,026 in these states: CO, HI, MI, MN, NC, NH, NV, OR, and RI. $188,592 - $251,456 in these states: AK, CA, CT, DC, DE, IL, MA, MD, NJ, NY, TX, VA, and WA. Lumen offers a comprehensive package featuring a broad range of Health, Life, Voluntary Lifestyle benefits and other perks that enhance your physical, mental, emotional and financial wellbeing. We're able to answer any additional questions you may have about our bonus structure (short-term incentives, long-term incentives and/or sales compensation) as you move through the selection process. Learn more about Lumen's: - Benefits - Bonus Structure #LI-Remote Requisition #: 341138 Background Screening If you are selected for a position, there will be a background screen, which may include checks for criminal records and/or motor vehicle reports and/or drug screening, depending on the position requirements. For more information on these checks, please refer to the Post Offer section of our FAQ page. Job-related concerns identified during the background screening may disqualify you from the new position or your current role. Background results will be evaluated on a case-by-case basis. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. Equal Employment Opportunities We are committed to providing equal employment opportunities to all persons regardless of race, color, ancestry, citizenship, national origin, religion, veteran status, disability, genetic characteristic or information, age, gender, sexual orientation, gender identity, gender expression, marital status, family status, pregnancy, or other legally protected status (collectively, “protected statuses”). We do not tolerate unlawful discrimination in any employment decisions, including recruiting, hiring, compensation, promotion, benefits, discipline, termination, job assignments or training. Disclaimer The job responsibilities described above indicate the general nature and level of work performed by employees within this classification. It is not intended to include a comprehensive inventory of all duties and responsibilities for this job. Job duties and responsibilities are subject to change based on evolving business needs and conditions. In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information. Please be advised that Lumen does not require any form of payment from job applicants during the recruitment process. All legitimate job openings will be posted on our official website or communicated through official company email addresses. If you encounter any job offers that request payment in exchange for employment at Lumen, they are not for employment with us, but may relate to another company with a similar name.




