SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Trust and Assurance Manager

SonarSource - Austin, TX, United States - In-office - posted 2026-10-02

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Sonar is the leader in AI code review and verification, helping over 75% of the Fortune 100 build trusted, reliable, and compliant software. The company integrates with Claude Code, Codex, Cursor, GitHub Copilot, Gemini, and Devin to ensure AI-generated code is secure and maintainable. As Security Trust and Assurance Manager based in Austin, you will lead the Security Governance and Customer Trust domains of Sonar's security risk management program, reporting to the CISO. This role bridges Information Security, Legal, Sales, Engineering, and Product teams to build customer trust through transparent security practices. Key Responsibilities: • Customer Interaction & Trust Center: Manage processes for answering security and technical questions from customers and internal users. Enhance and maintain the Trust Center as a proactive resource for customer security inquiries. • Engineering & Security Collaboration: Work closely with Engineering, Product, go-to-market, and Information Security teams to translate complex technical and architectural details into clear, accurate responses for customers. • Contract Review & Technical Feedback: Review customer contracts, MSAs, and DPAs. Partner with Legal and Sales teams to provide feedback, redlining, and negotiation support on security clauses, ensuring alignment with Sonar's capabilities and risk appetite. • Trust System Management: Maintain accuracy of customer trust systems and support a federated security approach across Sonar. Drive improvements and add new capabilities to security tooling. • AI Prompt Engineering: Develop and refine prompts and automated workflows using LLMs to keep security information systems current and valid. • Security Incident Support: Assist with security incidents as needed. Requirements: • Unwavering customer obsession: View security as an enabler for innovation and speed without compromising organizational or user safety. • Contract & Legal Acumen: Solid experience reviewing, redlining, and providing feedback on security clauses and technical language in customer contracts. Ability to bridge gaps between Legal, Sales, Engineering, and InfoSec. • Technical Diplomacy & Engineering Collaboration: Excellent communication skills. Ability to partner deeply with Engineering to validate technical details and translate complex security requirements into clear business terms for non-technical stakeholders. • Executive Presence: Comfortable working directly with senior leaders, especially a CISO. Ability to communicate strategy, report on trust metrics, and provide sound risk advice. • Extensive Multi-Domain InfoSec Expertise: Deep experience across several security domains (GRC, Cloud Security, IAM, Application Security). Familiarity with compliance frameworks including SOC 2, ISO 27001, and GDPR. • AI Proficiency: Proven ability to use AI tools and create complex prompts to solve security problems and automate governance tasks. • Autonomous Leadership & Organizational Acumen: Strong organizational skills to manage multiple high-stakes projects, audit reviews, and contract negotiations simultaneously with minimal supervision.

Similar roles