Full-Time

Financial Analyst

Posted on 9/9/2025

Sonar

Sonar

501-1,000 employees

Code quality and security analysis tools

No salary listed

No H1B Sponsorship

Austin, TX, USA

In Person

3 days in-office work per week.

Category
Finance & Banking (1)
Required Skills
NetSuite
Business Analytics
Financial Modeling
Requirements
  • Bachelors degree in Finance, Economics, or related field; MBA is a plus
  • 3+ years of experience in finance roles, preferably within a high-growth SaaS company
  • Expertise across various FP&A type work: corporate finance and strategic finance
  • Strong Financial modeling skills
  • Experience with planning software; experience with Netsuite, Bamboo is a plus
  • Proven communication and interpersonal skills, particularly as we interface heavily with business partners
  • Ability to thrive in a fast-paced, dynamic, and rapidly evolving environment
Responsibilities
  • Partner with budget owners to manage forecasts and support strategic projects
  • Manage long range planning processes, including for supported business partners, working cross-functionally to support financial targets
  • Monitor performance against the plan, and recommending actions to align to the plan
  • Actively manage monthly financial forecasting processes, ensuring accuracy, and contributing to topline and cash flow forecasts
  • Identify root causes of variances, developing remediation plans, while managing financial risks
  • Perform strategic analyses to provide insights to drive company performance and scaling
  • Build detailed financial models across various lines of the P&L
  • Build leadership-ready presentations, succinctly delivering key messages, and providing in-depth supporting details
  • Participate in various ad-hoc and business analytics buildouts, including digital transformation initiatives as we drive to enhance efficiency, automation, and data-driven capabilities within FP&A
Desired Qualifications
  • MBA is a plus
  • Experience with Netsuite, Bamboo is a plus

SonarSource provides tools to improve code quality and security across development teams. Its products include SonarLint (an IDE plugin that gives real-time feedback as code is written) and SonarQube (a self-managed code analysis platform) and SonarCloud (a cloud-based analysis service), which analyze code for bugs, vulnerabilities, and maintainability and present guidance and reports. The tools work by integrating into developers' workflows—from IDE feedback with SonarLint to repository-wide analysis with SonarQube or SonarCloud—delivering dashboards and trend reports. The company differentiates itself with an end-to-end, subscription-based suite that covers local IDE feedback through centralized governance, serving hundreds of thousands of organizations, with the goal of keeping code clean, secure, and reliable.

Company Size

501-1,000

Company Stage

Late Stage VC

Total Funding

$457.1M

Headquarters

Vernier, Switzerland

Founded

2008

Simplify Jobs

Simplify's Take

What believers are saying

  • Sonar Integration Program unifies governance across SDLC with 50+ partners including GitHub, GitLab, Datadog.
  • Customizable dashboards in SonarQube Cloud Enterprise provide zero-config health views for engineering leaders.
  • Jellyfish integration enables tracking code quality metrics alongside team performance and tech debt costs.

What critics are saying

  • GitHub Copilot's built-in scanning erodes SonarLint's IDE value as developers consolidate within GitHub ecosystem.
  • Wiz integration commoditizes Sonar's SAST insights, enabling Wiz to build proprietary cloud security alternatives.
  • Free AWS CodeGuru and Azure DevOps analysis capture enterprise market share from SonarCloud subscriptions.

What makes Sonar unique

  • Unified code-to-cloud visibility integrates SonarQube SAST findings into Wiz platform for prioritized remediation.
  • Native embedded MCP Server in SonarQube Cloud enables AI agents to verify code without local installation.
  • Foundation Agent tops SWE-bench at 79.2%, resolving code issues in 9 minutes for $1.90 via AutoCodeRover.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Flexible Work Hours

Hybrid Work Options

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

1%

2 year growth

0%
SonarSource
Mar 26th, 2026
Introducing Base Support: free resources to accelerate your code verification journey.

Introducing Base Support: free resources to accelerate your code verification journey. Ekaterina Okuneva Product Marketing Manager March 26, 2026 Building production-ready code is a journey, and having the right resources at your fingertips is essential. To help every software developer and organization succeed, SonarSource is introducing Base Support - a new, free support offering for all SonarQube users that's designed to provide instant access to the information you need, when you need it. Self-service expertise at no cost. Base Support provides a foundation for software development teams to independently manage their SonarQube implementation. This online-only offering gives you read-only access to its support portal, allowing you to browse through existing solutions and technical documentation. It is built for teams that want to maintain high standards of code health and security without the need for high-touch service. Accelerate your skills with the Sonar Learning Center. SonarSource believe in empowering developers to grow their expertise, which is why Base Support also grants access to the Sonar Learning Center. This is a customer-facing learning management system (LMS) that hosts educational content created by its customer education team. Its goal is to help you build the skills you'll need in order to use SonarQube to reduce technical debt, improve team productivity, and deliver more reliable software applications. The Learning Center offers over 20 hours of educational content across more than 40 courses, including: * Step-by-step onboarding: Courses designed to help you set up SonarQube and onboard your first projects quickly. * Short video tutorials: Concise lessons (under five minutes) for fast, actionable learning. * On-demand webinars: Deep dives into best practices and advanced features. * Foundational learning: Core concepts to help you build code that is secure, reliable, and maintainable. Streamline your setup with the customer onboarding hub. Beyond individual learning, Base Support connects you to the Sonar Onboarding Hub. This central resource is dedicated to helping you integrate SonarQube into your existing workflows seamlessly. By following its curated best practices, you can ensure your team is productive from day one while maintaining standards in the IDE. In an era where SonarSource must verify the output of AI tools at scale, having a strong foundation in code quality is more important than ever. By making these resources free and accessible to all users of SonarQube, SonarSource is helping every team build a culture of code quality that lasts. Get started with SonarQube today, and access the Base Support portal and the Learning Center to accelerate your journey.

SonarSource
Mar 18th, 2026
SonarQube insights now available in Wiz: unified visibility from code to cloud.

SonarQube insights now available in Wiz: unified visibility from code to cloud. Jeff Clawson Head of Technology Partnerships March 18, 2026 In the fast-paced world of modern software delivery, engineering leaders and platform engineers face a growing dilemma: the "Engineering Productivity Paradox." While automated tools and AI assistants allow teams to ship code faster than ever, they also introduce a higher volume of security vulnerabilities and bugs. Tracking these risks often feels like a game of whack-a-mole, with security findings scattered across disparate tools and development cycles. As the industry prepares to gather in San Francisco next week for the RSA Conference, the conversation has shifted from simply "finding" bugs to "unifying" the defense. Today, SonarSource is thrilled to announce a new integration between Sonar and Wiz. By bringing SonarQube's Static Application Security Testing (SAST) findings directly into the Wiz platform, SonarSource is giving organizations the unified visibility they need to secure their software from the first line of code to the production environment. If you plan to attend RSAC, then you can see the integration in action at the Sonar booth (#S-1727) and at the Wiz House (661 Howard St). Why this integration matters. The "before" state for most organizations is defined by silos. Developers live in their CI/CD pipelines and IDEs, focused on code quality and immediate bug fixes, while security teams operate across multiple tools to monitor risks across code, cloud, and runtime. Without a bridge between these worlds, it is incredibly difficult to track code health at scale in a microservices environment. A critical vulnerability found in a code scan might lack the cloud context to be properly prioritized, and a runtime risk might be hard to trace back to the specific source code repository or owner. SonarQube insights in your cloud security inventory. The integration between Sonar and Wiz eliminates these silos by creating a "code-to-cloud" feedback loop. Using the new connector, SonarQube metrics and findings are ingested and displayed within the Inventory > SAST Findings page on the Wiz platform. This technical flow is designed to be seamless. SonarQube performs automated systematic code analysis during your CI/CD pipeline, conducting both Pull Request (PR) analysis (on new code) and branch analysis (on regular, long-lived branches). Wiz pulls in these branch analysis results - supporting any branch, not just the default - and maps them to the corresponding assets in your cloud inventory. By enriching Wiz's Security Graph with SonarQube's specialized SAST data, security teams can see a high-fidelity view of risk that combines code-level flaws with real-world cloud context, such as network exposure and identity permissions. Key benefits for users. * Centralized visibility: Consolidate your application-level findings from SonarQube alongside other cloud risks within a single pane of glass in Wiz, ensuring nothing falls through the cracks. * Prioritized remediation: By enriching existing cloud assets with SonarQube's SAST findings, teams can identify "toxic combinations" - where a code-level vulnerability exists on a publicly exposed or highly privileged container. * Streamlined developer workflows: SonarQube automatically tracks findings across multiple project branches, and this integration ensures that the right data reaches the right people without requiring developers to leave their existing CI/CD environments. * Unified security posture: Strengthen your overall security governance by aligning code-level evidence with infrastructure risk, helping engineering leaders meet compliance requirements and maintain high standards across the SDLC. The partnership between Sonar and Wiz is a significant step toward a future where code quality and cloud security are no longer separate concerns. By interweaving Sonar's deep code analysis into the Wiz platform, SonarSource is empowering development and security teams to collaborate more effectively and build software that is secure by design. SonarSource share a vision of reducing developer toil and providing the actionable insights needed to innovate with confidence in an increasingly complex cloud landscape. Want to see this integration in action? If you're attending RSAC, find SonarSource at booth #S-1727 and at the Wiz House all week long, to learn more. Book a meeting with the team!

SonarSource
Mar 17th, 2026
Announcing native MCP Server in SonarQube Cloud.

Announcing native MCP Server in SonarQube Cloud. Andrew Osborne Product Marketing Manager March 17, 2026 The rise of AI-assisted software development has introduced a new bottleneck: code verification. While AI can generate code at unprecedented speeds, manually verifying that code for quality and security often breaks a software developer's flow. To solve this, Sonar launched the SonarQube MCP Server, bridging the gap between AI agents and trusted SonarQube insights. Today, SonarSource is evolving this integration. While the SonarQube MCP server remains available as a local Docker container, SonarSource has now launched an embedded version directly within SonarQube Cloud. Now natively available, with no installation required, this update removes the "Docker barrier" and transforms the integration into a fully managed, enterprise-ready service. Cloud-native integration. The cloud-native option is designed for environments where centralized management is preferred or where local installation restrictions are in place. For many software engineering teams, especially those in regulated industries like finance or healthcare, local installations are not allowed, and this created significant friction. The SonarQube embedded MCP server solves these issues by moving the logic into SonarQube Cloud. It provides a centralized, managed endpoint that is always on, always updated, and accessible without any local software installation. Beyond analysis: conversational code intelligence. By embedding the SonarQube MCP server, SonarSource is enabling AI agents to autonomously verify the AI code they produce against your organization's specific quality gates. When connected to the embedded MCP server, your AI assistants (such as Claude Desktop, GitHub Copilot, or custom LLM agents) can perform high-value tasks directly within the conversational flow: * Natural language queries: Ask your AI, "My quality gate is failing for my project. Can you help me understand why and fix the most critical issues?" or "I want to reduce technical debt in my project. What are the top issues I should prioritize?" * Actionable issue management: Interactively update an issue's status or mark a finding as a false positive directly from your AI assistant without switching to the SonarQube UI. * Dependency risk detection: Leverage SonarQube Advanced Security insights to identify and remediate vulnerable security dependencies in real-time. * Quality at the source: Ensure AI-generated code adheres to your standards before it ever reaches a Pull Request. How to connect to the embedded MCP server. Switching to the embedded version requires a simple update to your MCP configuration (e.g., your mcp.json file). This configuration replaces the previous Docker-based image or command blocks with a direct cloud-native connection. Example for Cursor or Antigravity: Setup requirements: * User token: Generate a personal access token in your SonarQube Cloud security settings. * Organization key: Provide the unique key for your SonarQube Cloud organization. Empowering the modern AI stack. The embedded MCP server is designed for the future of "vibe coding" and agentic workflows. By providing AI agents with direct, secure access to SonarQube Cloud's 7,000+ distinct issues that can be detected SonarSource ensure that velocity never comes at the expense of code health. Deployment options Users can now choose between two methods to connect their AI tools to SonarQube: * Local deployment: Running a Docker container on a workstation to bridge the IDE and SonarQube. * Cloud native: Using the embedded endpoint in SonarQube Cloud for centralized access without local software installation. Whether you are using Amazon Q Developer, Claude Code, or building custom autonomous agents, the embedded SonarQube MCP server provides the standardized, scalable, and secure foundation needed to automate code quality and security at scale. To learn more about SonarQube MCP Server, visit its Documentation or join the discussion in the Sonar Community.

PR Newswire
Mar 11th, 2026
Sonar's AI agent tops SWE-bench with 79.2% score, resolves code issues in 9 minutes for $1.9

Sonar has claimed the top position on the SWE-bench leaderboard with its Foundation Agent, achieving a 79.2% success rate on SWE-bench Verified and 52.62% on SWE-bench Full. The agent, powered by Anthropic's Claude Opus 4.5, resolved issues in an average of nine minutes at a cost of $1.90 per issue. Built on AutoCodeRover technology, the agent uses advanced tool-calling, thinking model integration and test-driven remediation to navigate codebases and generate functional patches. SWE-bench evaluates AI agents on real-world software engineering tasks using GitHub issues and corresponding fixes. The Geneva and Austin-based company, which analyses over 750 billion lines of code daily, currently offers the technology in beta through Sonar Autofix. The Foundation Agent remains a research innovation and is not commercially available.

SonarSource
Mar 2nd, 2026
Code architecture management general availability in SonarQube

Code architecture management general availability in SonarQube. Robert Curlee Product Marketing Manager March 2, 2026 In a world that operates on software, your code is your single most valuable asset. Software architecture is essential in defining how your software should function and evolve. Yet, despite being the cornerstone of a healthy application, maintaining software architecture is frequently overlooked. As developers, SonarSource know that neglecting software architecture leads directly to stale architectural documentation and structural technical debt. Over time, this debt manifests as accumulated complexity from misplaced logic, duplicated code, and misaligned dependencies. As architectural debt accumulates, making code changes becomes a risky, slow process. If left unchecked, this structural erosion eventually stalls innovation and forces costly application rewrites. Great architecture is the secret to developer productivity. Well-designed, modular software ensures that developers can make effective code changes without worrying about unpredictable ripple effects. Today, SonarSource is thrilled to announce the general availability of architecture management in SonarQube Cloud, designed to bring software architecture back under your control to promote a healthy codebase and enable highly performant teams. The AI multiplier: why code architecture matters now more than ever. The rapid adoption of generative AI coding assistants has fundamentally changed how SonarSource write code. Software developers are now leveraging AI-native IDEs and agents to generate code at unprecedented speeds that often bypasses traditional architectural planning. Furthermore, AI coding tools don't have the context needed to provide effective coded solutions leading to "slop." While the new AI-native SDLC accelerates output, it also acts as a multiplier for architectural drift. AI-generated code can easily become a structural black box, making complex systems rapidly diverge from their intended design. To maintain the speed of modern development, you need an automatic, dependable way to ensure architectural integrity. How code architecture in SonarQube works. SonarQube helps you manage your software architecture through four essential stages: discover, formalize, prioritize, and fix. * Discover: As part of the normal scan, SonarQube automatically reverse-engineers your codebase to create an always-current, living visual representation of its actual current architecture, no additional setup is needed. It provides a real-time, navigable view of component relationships that is instantly available to all development stakeholders, including AI agents. * Formalize: Building your intended architecture is a snap. Using a graphical interface, you can start light and evolve it over time to suit your needs. * Prioritize: You maintain control by deciding when and how to enforce architecture violations in the code. * Fix: Developers gain a clear understanding of expectations for writing code that aligns with the intended architecture. This enables them to resolve architectural issues immediately to pass the quality gate. Teams also get instant notifications when AI generated code violates the architecture, allowing for timely, in-workflow fixes. Value across your engineering teams. Bringing architecture into your continuous codebase inspection delivers immediate benefits across your organization: For developers: * Improved productivity: Gain a clear picture of interdependencies through live documentation of the current architecture, eliminating guesswork and providing full context awareness. * In-workflow resolution: Build a clear understanding of expectations and resolve architectural issues within your standard developer workflow as you are developing. Other tools treat architectural integrity as a separate event, taking you out of band from your daily routine. For architects and project owners: * Architectural integrity: Maintain complete control by deciding when and how to enforce architecture violations. You can start light and evolve your intended architecture over time to suit your project's needs. * AI Governance: Instantly detect when AI-generated code violates your architecture, allowing for timely fixes. Plus, you can enable LLMs to leverage your intended and current architectures as context to generate better, more structurally sound results. Get started today. To use these new architecture capabilities in SonarQube Cloud, you'll find a new "Architecture" tab under every project. If you don't see the visual structure map of your current architecture, it will appear after your next scan. You'll need administration privilege in your organization to create the intended architecture and prioritize disallowed relationships such as tangles. Here are some great resources for further details: * Visit its Community post that has several demo videos * Explore your current architecture including advanced features * Dig into architecture details in SonarQube Cloud docs It is time to align the speed of AI development with the dependability of strong architectural governance. Stop reacting to structural debt, and start architecting for the future.

INACTIVE