Full-Time
Code quality and security analysis tools
No salary listed
San Mateo, CA, USA
In Person
Three anchor on-site days per week (Mondays, Tuesdays, Thursdays). Relocation is possible for the right candidate.
See people who can refer or advise you
SonarSource provides tools to improve code quality and security across development teams. Its products include SonarLint (an IDE plugin that gives real-time feedback as code is written) and SonarQube (a self-managed code analysis platform) and SonarCloud (a cloud-based analysis service), which analyze code for bugs, vulnerabilities, and maintainability and present guidance and reports. The tools work by integrating into developers' workflows—from IDE feedback with SonarLint to repository-wide analysis with SonarQube or SonarCloud—delivering dashboards and trend reports. The company differentiates itself with an end-to-end, subscription-based suite that covers local IDE feedback through centralized governance, serving hundreds of thousands of organizations, with the goal of keeping code clean, secure, and reliable.
Company Size
501-1,000
Company Stage
Late Stage VC
Total Funding
$457.1M
Headquarters
Vernier, Switzerland
Founded
2008
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Flexible Work Hours
Hybrid Work Options
Professional Development Budget
Building on strong commercial momentum, Sonar launches new products to improve agentic effectiveness. 02.07.2026 AI agents now assist in generating more than 40% of committed enterprise code. Sonar's new offerings improve quality of agentic output, decrease token usage by up to 36%, and autonomously burn down technical debt. The launch is backed by strong commercial traction. The company has surpassed USD 430 million in annual recurring revenue (ARR) with accelerated growth. Agents are limited by what they don't know. They fall down when they lack the context of architecture, security and quality standards, approved libraries, an organization's conventions, and so on. Left ungoverned, they produce code that works in isolation but often violates the rules of the system it's entering. And the fixes cost more with every passing sprint. Sonar's new offerings address these challenges on both sides of the agentic development loop: Sonar Vortex improves the effectiveness of agents building new code, while the SonarQube Remediation Agent stops the accumulation of technical debt in the existing codebase. Available today, the new products improve agentic development in three ways: * Ensure agents write conformant code from the start by injecting your project's standards before generation, and then verifies the agent-written code against your team's quality and security standards while it's being written * Cut LLM token consumption by up to 36% by delivering precise, governed context in a single call, eliminating the iterative file discovery that drives up cost * Autonomously burn down technical debt at scale, working asynchronously in the background to generate, verify, and raise ready-to-merge PRs without pulling developers away from new work "The industry conversation about AI slop, token efficiency, and compounding technical risk has been building for months, if not longer," said Tariq Shaukat, CEO of Sonar. "What's been missing is a way to address those three issues where they occur: inside the agentic loop. We're delivering AI and development leaders a solution they can trust to make their investments in AI more efficient, effective, and sustainable." The announcement is backed by the strongest financial position in Sonar's history. The company has surpassed $430 million in annual recurring revenue (ARR) with accelerated growth. More than 7 million developers use Sonar - 75% of the Fortune 100 rely on it, including 19 of the top 20 banks globally outside China, as well as leading organizations like Nvidia, AstraZeneca, and Mercedes-Benz. That scale reflects a market that considers verification mandatory. Organizations trust Sonar to analyze more than 750 billion lines of code daily. Teams using Sonar are 44% less likely to experience outages from AI-generated code. 0Comments. More news about.
Sonar has launched Sonar Vortex and the SonarQube Remediation Agent to improve AI agent code quality and efficiency. The company, which has surpassed $430 million in annual recurring revenue, reports that AI agents now assist in generating over 40% of committed enterprise code. Sonar Vortex guides AI agents with organisational standards before code generation and verifies output in real time, reducing large language model token consumption by up to 36% in testing. The SonarQube Remediation Agent autonomously addresses technical debt by generating verified, ready-to-merge pull requests without developer intervention. More than seven million developers use Sonar, including 75% of Fortune 100 companies. The platform analyses over 750 billion lines of code daily, and teams using it are 44% less likely to experience outages from AI-generated code.
Sonar, a global leader in AI code verification, has acquired Gitar, an AI-native code review platform, to expand its verification capabilities for the agentic era. The acquisition will integrate Gitar's code review functionality with SonarQube, Sonar's verification engine used by over 75% of Fortune 100 companies and 7 million developers. Gitar's founders, Ali-Reza Adl-Tabatabai and Gautam Korlam, both veterans of Uber, Google and Meta, will join Sonar to lead platform development. Gitar will remain available as a standalone product whilst being offered alongside SonarQube. The combined platform will provide code verification from initial writing through to codebase integration. Sonar reports teams using its technology are 44% less likely to experience outages from AI-generated code, whilst cleaned codebases reduce AI agent token usage by up to 8%.
New AI debugging tool developed and tested by S'pore engineers aims to tackle rising risks. Sonar CEO Tariq Shaukat during the launch of the SonarQube Remediation Agent, on the sidelines of the ATxSummit on May 21. ST PHOTO: MARK CHEONG Published May 21, 2026, 05:44 PM Updated May 21, 2026, 09:40 PM SINGAPORE - An artificial intelligence debugging tool developed and tested in Singapore will be available to local businesses to help them mitigate the rising cybersecurity and operational risks introduced by AI-generated software codes. The SonarQube Remediation Agent automatically looks for flaws in codes that are AI-generated or written by humans, and applies fixes with developers' approval. The core technology, which helps to scan code bases and provide suggested fixes, came from National University of Singapore (NUS) researchers. In early 2025, the technology was acquired by Swiss software firm Sonar. The firm is now commercially rolling out the tool after having completed rigorous tests with the Infocomm Media Development Authority (IMDA) and local engineers. "As engineering teams move faster, it is important that code quality checks and remediation keep pace," said Dr Ong Chen Hui, assistant chief executive of IMDA's BizTech Group, on May 21 at the Asia Tech x Summit 2026 held at Capella Singapore. "Our partnership with Sonar helps address existing gaps in this area, equipping enterprise software teams with practical tools to build at speed, while maintaining quality, security and responsibility." The use of advanced AI tools means that large amounts of code can be generated quickly, but this also results in lots of errors in code that can lead to service outages, said Sonar chief executive Tariq Shaukat. AI tools have also multiplied the risks of cyberattacks as they can also autonomously look for software flaws and exploit them.
Sonar acquires Gitar, expanding code verification platform to include AI code review. Sonar has acquired Gitar, the AI-native code review platform. Now, Sonar will deliver industry-leading AI code review unified with the industry's most comprehensive verification engine, purpose-built for the agentic era. Sonar's AI code verification platform, SonarQube, will seamlessly integrate with Gitar to provide code review from the moment an agent starts writing code to the moment it lands in the codebase. More than 75% of the Fortune 100 and 7 million developers and their AI agents rely on SonarQube to ensure the quality, security, and architectural integrity of AI-generated code. SonarQube's results are measurable: teams that use Sonar are 44% less likely to experience outages caused by AI-generated code, and codebases cleaned by SonarQube reduce AI agent token usage by up to 8%. "Enterprise adoption of AI depends on strong verification of agentic output. Right now, every enterprise is asking the same question: 'How do we move fast with AI without breaking things?' Now, enterprises will have a unified platform that brings together the best of AI code review and the most comprehensive verification engine in the market, providing the highest level of assurance whether you're using Claude Code, Cursor, Codex, Devin, or GitHub Copilot," said Tariq Shaukat, CEO at Sonar. Gitar is led by Ali-Reza Adl-Tabatabai, a veteran of Uber, Google, and Meta, and Gautam Korlam, who together helped build Uber's centralized developer platform. Adl-Tabatabai and Korlam will join Sonar and lead the development of the Gitar platform. Gitar will continue to be available as a standalone product with no impact to existing customers. Gitar will also be available to purchase with SonarQube and SonarQube Advanced Security. "While the market chased AI code generation, we focused on the harder problem: validating it. We built Gitar because we saw firsthand what happens when development velocity outpaces code quality. AI has made that problem an order of magnitude bigger. We're deeply proud of what we've built at Gitar, and excited to bring that work into Sonar. Together, we'll deliver the greatest, unbeatable verification platform for the agentic era," said Ali-Reza Adl-Tabatabai, CEO at Gitar. With this acquisition, Sonar customers will be able to analyze the syntax, data flows, logic flows, control flows, architectures, and dependencies in their codebase; set and enforce their own standards in a highly accurate, consistent, repeatable, transparent, and auditable manner; agentically fix identified issues; and do all of this as the agents are writing code and in their CI workflows. Sonar's offering moves organizations away from noisy signals and complex operational overhead to clear, actionable outcomes that improve software quality, increase delivery confidence, and reduce agentic coding time and token costs. Sonar innovation in the agentic development era. The acquisition of Gitar demonstrates a deepened commitment to delivering value across the Agent Centric Development Cycle (AC/DC), Sonar's methodology for ensuring AI agents are operating in a trustworthy, consistent, and transparent way. Over the last 12 months, Sonar has expanded its offering to include the following new products and features: * SonarQube Advanced Security extends verification to your software supply chain, with dependency-aware advanced static application security testing (SAST) and software composition analysis (SCA). * SonarQube Agentic Analysis brings the power of SonarQube to agentic self-verification, enabling AI agents to check their own work against an organization's quality standards in real time, preventing issues from compounding through subsequent reasoning tasks. * SonarQube Architecture enforces rigorous architectural standards for both agents and developers, ensuring AI-generated code integrates cleanly with existing systems rather than introducing structural fragility. * SonarQube MCP Server connects AI agents to SonarQube's analysis engine in real time, enabling tools like Claude Code, GitHub Copilot, Cursor, and Devin to assess code quality and security issues without leaving their workflows. * SonarQube CLI is a command-line interface for agentic environments, scanning every code snippet an AI agent produces in real time and automatically intercepting session tokens, API keys, and other sensitive credentials before they reach an LLM provider. * SonarQube Plugin for Claude Code brings Sonar's full code verification analysis into Anthropic's Claude Code as a single installable unit, bundling the SonarQube CLI, MCP Server, hooks, slash commands, and secrets scanning. * SonarQube Remediation Agent delivers verified fixes for identified issues, closing the loop from detection to solution. * Sonar Context Augmentation equips AI agents with the right context, guardrails, and organizational standards - even before a line of code is written - building in quality from the start and significantly improving test pass rates. * SonarSweep embeds enterprise context directly into fine-tuned models, reducing security vulnerabilities in LLM outputs by up to 67%, correcting code at the source before verification is even needed. David Marshall has been involved in the technology industry for over 30 years, and he's been working with virtualization software since 1999. He became a pioneer in the virtualization and cloud computing field - one of the few people in the industry allowed to work with Alpha stage server virtualization software from industry leaders: VMware (ESX Server), Connectix and Microsoft (Virtual Server).Through the years, he has invented, marketed and helped launch a number of successful software companies and products. David holds a BS degree in Finance, an Information Technology Certification, and a number of vendor certifications. He's also co-authored two published books: "VMware ESX Essentials in the Virtual Data Center" and "Advanced Server Virtualization: VMware and Microsoft Platforms in the Virtual Data Center" and was the technical editor for two popular Virtualization "For Dummies" books. With his remaining spare time, David founded and operates one of the oldest independent modern data center publications, VMblog.com. And co-founded CloudCow.com, a publication dedicated to Cloud Computing. Since 2009, and each year thereafter, David has been honored with the vExpert distinction by VMware by Broadcom for his evangelism.Connect on LinkedIn: https://www.linkedin.com/in/davidmarshall/