What you will do
1. Build expertise on various language ecosystems in order to identify the most common vulnerabilities that developers are facing.
2. Investigate how these vulnerabilities materialize within the code.
3. Define the static analysis rules that will detect these vulnerabilities.
4. Interact with our user community to clarify this invaluable feedback and turn it into actions/decisions, such as refining too noisy vulnerability detection rules or improving taint-analyzer vulnerability reports with contextual information.
5. Drive innovation to make our SAST engine even better.
6. Study competitors and provide gap analyses.
Experience and qualifications
Technical skills
7. Mastering application security basics, including knowing the most common vulnerabilities, how to locate vulnerabilities in the code, and how to exploit basic vulnerabilities. To be successful, you should be interested or involved in the application security ecosystem.
8. Having a developer mindset: experience with coding lifecycle, ability to produce secure code, to do code reviews, and to jump into an unknown codebase, language, and framework.
9. Master at least one programming language along with its development environment to understand end-users' context and expectations.
Soft skills
10. Strong communication skills, i.e. both listening and expressing constructive ideas.
11. High level of autonomy and still accepting help and feedback from team members.
12. Ability to work and communicate with non-security experts.
Nice to have
13. Understanding of static analysis mechanisms.
14. Ability to challenge rule implementation.
Additional comments
This role is based in Bochum. We are unable to consider candidates unwilling to be in Bochum, but we are willing to relocate the right candidate.
We value diversity, equity, and inclusion
At Sonar, we believe that our diversity is our strength. We are a global company that values and respects different backgrounds, perspectives, and cultures. We are committed to fostering a diverse and inclusive work environment where everyone feels valued and empowered to contribute their best. We are proud to be an equal opportunity employer and welcome all qualified applicants, regardless of race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.
If you need any accommodation, please reach out to us at.
All offers of employment at Sonar are contingent upon the results of a comprehensive background check and reference verification conducted before the start date.
We do not currently support visa candidates in the US.
Applications that are submitted through agencies or third party recruiters will not be considered.