... secure, and maintainable. Integrating seamlessly with Claude Code, Codex, Cursor, GitHub Copilot ... The world's leading AI code review and verification platform. * SonarQube Foundation Agent:
... secure, and maintainable. Integrating seamlessly with Claude Code, Codex, Cursor, GitHub Copilot ... The world's leading AI code review and verification platform. * SonarQube Foundation Agent:
... secure, and maintainable. Integrating seamlessly with Claude Code, Codex, Cursor, GitHub Copilot ... The world's leading AI code review and verification platform. * SonarQube Foundation Agent:
... secure, and maintainable. Integrating seamlessly with Claude Code, Codex, Cursor, GitHub Copilot ... The world's leading AI code review and verification platform. * SonarQube Foundation Agent:
... secure, and maintainable. Integrating seamlessly with Claude Code, Codex, Cursor, GitHub Copilot ... The world's leading AI code review and verification platform. * SonarQube Foundation Agent:
Quick apply
... secure, and maintainable. Integrating seamlessly with Claude Code, Codex, Cursor, GitHub Copilot ... The world's leading AI code review and verification platform. * SonarQube Foundation Agent:
... secure, and maintainable. Integrating seamlessly with Claude Code, Codex, Cursor, GitHub Copilot ... The world's leading AI code review and verification platform. * SonarQube Foundation Agent:
... secure, and maintainable. Integrating seamlessly with Claude Code, Codex, Cursor, GitHub Copilot ... The world's leading AI code review and verification platform. * SonarQube Foundation Agent:
... secure, and maintainable. Integrating seamlessly with Claude Code, Codex, Cursor, GitHub Copilot ... The world's leading AI code review and verification platform. * SonarQube Foundation Agent:
... secure, and maintainable. Integrating seamlessly with Claude Code, Codex, Cursor, GitHub Copilot ... The world's leading AI code review and verification platform. * SonarQube Foundation Agent:
... secure, and maintainable. Integrating seamlessly with Claude Code, Codex, Cursor, GitHub Copilot ... The world's leading AI code review and verification platform. * SonarQube Foundation Agent:
Quick apply
... secure, and maintainable. Integrating seamlessly with Claude Code, Codex, Cursor, GitHub Copilot ... The world's leading AI code review and verification platform. * SonarQube Foundation Agent:
Sales Director, Agentic Code Review (Gitar.ai)
San Mateo, CA · On-site
$180 - $240/hr
... secure, and maintainable. Integrating seamlessly with Claude Code, Codex, Cursor, GitHub Copilot ... The world's leading AI code review and verification platform. * SonarQube Foundation Agent:
Sales Director, Agentic Code Review (Gitar.ai)
San Mateo, CA · On-site
$180 - $240/hr
... secure, and maintainable. Integrating seamlessly with Claude Code, Codex, Cursor, GitHub Copilot ... The world's leading AI code review and verification platform. * SonarQube Foundation Agent:
Pen Tester
San Francisco, CA · On-site
... Conduct secure code review trainings to developers - Understanding of OWASP, SANS, CWE standards, - Experience with enforcing application security in the SDLC of web applications - Develop ...
Pen Tester
San Francisco, CA · On-site
... Conduct secure code review trainings to developers - Understanding of OWASP, SANS, CWE standards, - Experience with enforcing application security in the SDLC of web applications - Develop ...
Pen Tester
San Francisco, CA · On-site
... Conduct secure code review trainings to developers - Understanding of OWASP, SANS, CWE standards, - Experience with enforcing application security in the SDLC of web applications - Develop ...
Pen Tester
San Francisco, CA · On-site
... Conduct secure code review trainings to developers - Understanding of OWASP, SANS, CWE standards, - Experience with enforcing application security in the SDLC of web applications - Develop ...
Senior Security Engineer
San Francisco, CA · On-site
$134K - $185K/yr
Required : • Have 5+ years of hands-on application security engineering experience • Expertise in secure software development practices, including threat modeling, secure code review, and ...
Senior Security Engineer
San Francisco, CA · On-site
$134K - $185K/yr
Required : • Have 5+ years of hands-on application security engineering experience • Expertise in secure software development practices, including threat modeling, secure code review, and ...
AI Software Engineer
San Francisco, CA · On-site
Review and refine AI-generated code to ensure compliance with secure coding standards (e.g., OWASP Top 10, secure SDLC practices). * Implement automated guardrails to detect insecure outputs, prompt ...
AI Software Engineer
San Francisco, CA · On-site
Review and refine AI-generated code to ensure compliance with secure coding standards (e.g., OWASP Top 10, secure SDLC practices). * Implement automated guardrails to detect insecure outputs, prompt ...
AI Software Engineer
San Francisco, CA · On-site
Review and refine AI-generated code to ensure compliance with secure coding standards (e.g., OWASP Top 10, secure SDLC practices). * Implement automated guardrails to detect insecure outputs, prompt ...
AI Software Engineer
San Francisco, CA · On-site
Review and refine AI-generated code to ensure compliance with secure coding standards (e.g., OWASP Top 10, secure SDLC practices). * Implement automated guardrails to detect insecure outputs, prompt ...
Review and refine AI-generated code to ensure compliance with secure coding standards (e.g., OWASP Top 10, secure SDLC practices). * Implement automated guardrails to detect insecure outputs, prompt ...
Review and refine AI-generated code to ensure compliance with secure coding standards (e.g., OWASP Top 10, secure SDLC practices). * Implement automated guardrails to detect insecure outputs, prompt ...
Application Security Engineer
San Francisco, CA · Hybrid
$145K - $180K/yr
Perform secure code reviews, validate false positive determinations, coach developers on effective remediation strategies, threat model our products and carry out essential parts of a secure SDLC.
Application Security Engineer
San Francisco, CA · Hybrid
$145K - $180K/yr
Perform secure code reviews, validate false positive determinations, coach developers on effective remediation strategies, threat model our products and carry out essential parts of a secure SDLC.
Senior Privacy Engineer (RED team) - TikTok PDPO
San Jose, CA · On-site
$212.80 - $387.60/hr
Strong manual secure code review skills, with an eye for privacy-specific bugs in addition to traditional appsec issues. * Comfortable working across heterogeneous stacks and unfamiliar codebases.
Senior Privacy Engineer (RED team) - TikTok PDPO
San Jose, CA · On-site
$212.80 - $387.60/hr
Strong manual secure code review skills, with an eye for privacy-specific bugs in addition to traditional appsec issues. * Comfortable working across heterogeneous stacks and unfamiliar codebases.
Senior Privacy Engineer (RED team) - TikTok PDPO
San Jose, CA · On-site
$212K - $387K/yr
... secure code review skills, with an eye for privacy-specific bugs in addition to traditional appsec issues. - Comfortable working across heterogeneous stacks and unfamiliar codebases. - Ability to ...
Senior Privacy Engineer (RED team) - TikTok PDPO
San Jose, CA · On-site
$212K - $387K/yr
... secure code review skills, with an eye for privacy-specific bugs in addition to traditional appsec issues. - Comfortable working across heterogeneous stacks and unfamiliar codebases. - Ability to ...
Sr. Application Security Engineer
San Francisco, CA · On-site
$69.25 - $92.50/hr
... Secure code review experience using automated toolsets Software Engineering career experience Following Certifications: CISSP, CEH, GWAPT, GPEN, OSCP Thorough understanding of software ...
Sr. Application Security Engineer
San Francisco, CA · On-site
$69.25 - $92.50/hr
... Secure code review experience using automated toolsets Software Engineering career experience Following Certifications: CISSP, CEH, GWAPT, GPEN, OSCP Thorough understanding of software ...
Senior Engineer, Security & Compliance (US)
San Francisco, CA · On-site
$110 - $150/hr
Partner with engineering teams to embed security into CI/CD pipelines -- vulnerability scanning, SAST/DAST tooling, dependency management, container security, and secure code review * Implement ...
New
Senior Engineer, Security & Compliance (US)
San Francisco, CA · On-site
$110 - $150/hr
Partner with engineering teams to embed security into CI/CD pipelines -- vulnerability scanning, SAST/DAST tooling, dependency management, container security, and secure code review * Implement ...
New
While your primary role is to build secure software in Python and modern web stacks, your expertise ... Perform security code reviews and penetration testing on our web applications and services.
While your primary role is to build secure software in Python and modern web stacks, your expertise ... Perform security code reviews and penetration testing on our web applications and services.
Sr. Application Security Engineer
San Francisco, CA · On-site
$69.25 - $92.50/hr
... • Secure code review experience using automated toolsets • Software Engineering career experience • Following Certifications: CISSP, CEH, GWAPT, GPEN, OSCP • Thorough understanding of ...
Sr. Application Security Engineer
San Francisco, CA · On-site
$69.25 - $92.50/hr
... • Secure code review experience using automated toolsets • Software Engineering career experience • Following Certifications: CISSP, CEH, GWAPT, GPEN, OSCP • Thorough understanding of ...
Secure Code Review information
What is secure code review?
What are the key skills and qualifications needed to thrive as a secure code reviewer?
What are some common challenges faced by professionals performing secure code reviews, and how can they be addressed?
What is the difference between Secure Code Review vs Static Application Security Testing (SAST)?
| Aspect | Secure Code Review | Static Application Security Testing (SAST) |
|---|---|---|
| Credentials | Knowledge of secure coding, programming languages, security standards | Security testing tools, programming knowledge, security certifications |
| Work Environment | Manual review, developer collaboration, code analysis | Automated scanning, integration with CI/CD pipelines |
| Industry Usage | Development teams, security analysts, code audits | Security teams, QA, DevOps, automated security testing |
Secure Code Review involves manual or semi-automated analysis of source code to identify security flaws, emphasizing developer collaboration. SAST uses automated tools to scan code for vulnerabilities during development, enabling faster detection. Both roles aim to improve code security but differ in approach: one is manual and detailed, the other automated and scalable.

Full-time
Re-posted 12 days ago
Job description
Sonar is driving the future of agent-centric software development. As the leader in AI code verification and governance, we solve a critical problem: ensuring that software generated by AI-assisted developers or autonomous agents is reliable, secure, and maintainable.
Integrating seamlessly with Claude Code, Codex, Cursor, GitHub Copilot, Gemini, and Devin, we help over 75% of the Fortune 100 build trusted, reliable, compliant software. Customers who use Sonar are 44% less likely to report an outage due to AI-generated code.
We believe code verification is the critical missing link in the Agent-Centric Development Cycle (AC/DC). Industry giants like Nvidia, ServiceNow, Booking.com, Goldman Sachs, AstraZeneca, and Ford Motor Company count on us to provide independent, explainable, consistent review and governance of their AI-generated code via products like:
- SonarQube: The world's leading AI code review and verification platform.
- SonarQube Foundation Agent: Currently topping the leaderboards for agentic software repair.
- SonarSweep & Sonar Context Augmentation: Providing the enterprise-grade context and constraints agents need to be truly effective.
Our team operates across global hubs in Austin, Bochum, Dubai, Geneva, London, Singapore, Tokyo, and Washington D.C. We move with a mindset we call CODE:
- Committed to our customers and community.
- Obsessed with quality.
- Deliberate in our decisions.
- Effective as one team.
With over $400M in revenue and profitable, fast-paced growth, we are building the backbone of the AI software revolution. If you're hungry to have an impact, want to build at a fast pace, and ready to work at the forefront of AI, we want to hear from you.
Gitar.ai is an AI-native code review platform that uses AI agents to support pull request validation and CI workflows by reviewing code, diagnosing failures, proposing fixes, and adding tests and validations directly within existing development processes. Gitar automatically makes every change production-ready, approves and merges routine changes, involves humans only in exception cases, and learns from each exception to improve over time. In that model, humans oversee the end-to-end process rather than manually reviewing every change.
What you will do
You will be one of the founding members of the Gitar.ai go-to-market team. You will be responsible for Gitar.ai inbound and outbound sales, building pipeline, running evaluations and proofs-of-concept, and closing deals with CIOs, CTOs, VPs of Engineering, and Heads of Platform Engineering.
This is a full-cycle, high-velocity role inside a category-defining platform. You will own the entire sales cycle, bringing deep technical understanding and business value orientation to potential customers. You'll also play a critical role in building our go-to-market team and capabilities from the ground up, working directly with the founders of Gitar.ai and the broader Sonar marketing, sales, and customer success teams.
- Own the entire revenue cycle for standalone AI code review deals: prospecting, technical discovery, multi-threaded developer and executive engagement, proof-of-value management, commercial negotiation, and close.
Focus on identifying prospective customers within our target ICPs, execute outbound campaigns , and build sales demand with the goal of driving closed-won business and customer success.
Become a product expert in both Gitar.ai and the broader Sonar product portfolio, so that you can manage the entire sales cycle including product demos and proofs of concept.
Continuously build pipeline while progressing active customer engagements and providing input to product teams as they deliver their roadmap.
Maintain rigorous sales process hygiene, leveraging our sales methodologies, including Command of the Message and MEDDPICC, and our GTM tooling including Clari, Outreach, and Salesforce, to deliver high velocity sales cycles with enthusiastic customers.
The ideal candidate will
- Have 5+ years of full-cycle, quota-carrying SaaS sales experience, including 3+ years selling technical products to IT, DevOps, platform engineering, or security buyers.
- Demonstrate a track record of consistent overperformance against quota.
- Possess technical competency to be able to learn Gitar.ai and Sonar's software solutions and engage with technical buyers as well as executive stakeholders. This should include having a strong familiarity with modern software development - Git, CI/CD, code review workflows, SDLC tooling.
- Have high levels of customer empathy and a passion for customer success.
- Be energized about working in a startup environment, with a strong work ethic, embrace of ambiguity, and enthusiasm for constant learning and development.
- Be based in the San Francisco Bay Area and excited to work out in person with the team in our San Mateo office.
We're intentional about this. We believe the best teams are built in the room together. Three anchor days - Mondays, Tuesdays, and Thursdays - create the collaboration rhythm that makes a hub office worth having.
Candidates need to be genuinely based in the location the role is posted - if that's not where you are today, we're happy to support relocation for the right person.
We value diversity, equity, and inclusionAt Sonar, we believe that our diversity is our strength. We are a global company that values and respects different backgrounds, perspectives, and cultures. We are committed to fostering a diverse and inclusive work environment where everyone feels valued and empowered to contribute their best. We are proud to be an equal opportunity employer and welcome all qualified applicants, regardless of race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.
If you need any accommodation, please reach out to us at [email protected].
All offers of employment at Sonar are contingent upon the results of a comprehensive background check and reference verification conducted before the start date.
Applications that are submitted through agencies or third party recruiters will not be considered.