Staff Info Sec AI Researcher
TLDR
Drive AI-enabled security engineering to identify and remediate risks across products, codebases, infrastructure, and dependencies.
Your work will turn security findings into durable defensive improvements, including remediation guidance, engineering-ready fix proposals, reusable AI-SDLC patterns, secure coding guidance, and product-security insights that reduce exposure and raise the bar for secure engineering at Sonatype.
Key Responsibilities:
-
Identify and prioritize meaningful security risks across first-party code, services, infrastructure, build pipelines, and software supply chain components.
-
Validate findings for exploitability, severity, affected products, business impact, and remediation priority.
-
Collaborate with Security Research and Product to translate novel findings, malicious component discoveries, and emerging attack patterns into research-ready outputs, product improvements, detection opportunities, and customer-facing intelligence.
-
Work closely with Application Security and Engineering to move validated findings through remediation and reduce repeat vulnerability patterns.
-
Champion modern AI-SDLC practices by translating recurring vulnerability classes, insecure coding patterns, and effective remediation approaches into reusable guidance, detection logic, secure coding standards, and remediation playbooks.
-
Create clear remediation guidance, engineering-ready fix proposals, and pull requests where appropriate.
We’re seeking an experienced engineer who thrives in an agile, collaborative environment and enjoys tackling technical challenges.
Minimum Qualifications:
-
8+ years of professional software engineering experience, including 2+ years in a Staff Engineer or equivalent technical leadership role.
-
Proven experience identifying, validating, and helping remediate vulnerabilities in production software, services, APIs, infrastructure, or software supply chain components.
-
Strong ability to read, understand, and reason about complex codebases, preferably including Java, Kotlin, or other JVM-based backend systems.
-
Hands-on experience with application security testing methods and tools, such as SAST, DAST, SCA, secret scanning, threat modeling, secure code review, or vulnerability validation.
-
Practical experience using AI-assisted engineering, security analysis, or automation techniques to improve software quality outcomes.
-
Ability to translate security findings into clear remediation guidance, engineering-ready recommendations, and practical risk-based priorities.
-
Bachelor’s degree in Computer Science, Engineering, or a related field—or equivalent practical experience.
-
Strong communication and collaboration skills, with experience working across Application Security, Engineering, Product, or Security Research teams.
-
Solid understanding of cloud-native architecture, CI/CD workflows, build pipelines, containers, and modern DevOps practices.
-
Passion for raising the security bar through technical leadership, mentoring, secure engineering practices, and continuous improvement.
-
Relevant certifications such as:
-
SANS Certifications: GSEC, GCIH, GCLD, GCID, GMON
-
(ISC)² Certifications: CISSP, CC, SSCP, CCSP, CAP, CSSL
-
2025 DEVIES Award to our SBOM Manager new product for its innovation and impact in developer technology
2024 Industry Leader in Forrester-Wave for Software Composition Analysis (2024 Q4 report)
2023 Fast Company Best Places for Innovators
2023 Gartner's Magic Quadrant
2023 Software Report's Top 100 Software Companies
2023 BuiltIn Best Places to Work
2022 Frost & Sullivan Technology Innovation Leader Award
2022 PeerSpot Silver Peer Award in Software Composition Analysis
2022 Tech Ascension Best DevOps Security Solution Award
2022 NVCT Cyber Company of the Year
Company Wellness Week - We shut down company operations for a week to enable all employees to pursue personal growth and enjoy a much-needed and deserved rest.
Paid Volunteer Time Off (VTO)
Expansion of Sonatype’s India Innovation Hub in Hyderabad, reflecting our continued growth, commitment to innovation, and investment in talent to advance AI-driven software security globally
Benefits
Flexible Work Hours
Flexible working practices
Company expansion and innovation investment
Expansion of Sonatype’s India Innovation Hub in Hyderabad, reflecting our continued growth, commitment to innovation, and investment in talent to advance AI-driven software security globally
Paid Parental Leave
Parental leave
Volunteer Time Off
Paid Volunteer Time Off (VTO)
Wellness Stipend
Company Wellness Week
Sonatype provides comprehensive software supply chain security solutions, empowering over 2,000 organizations to create and maintain secure software. Our distinctive approach combines proactive protection against malicious open source, enterprise-grade SBOM management, and a leading dependency management platform, making us a trusted partner for enterprises looking to innovate securely and efficiently.
- Founded
- Founded 2008
- Employees
- 201-500 employees
- Industry
- Internet Software & Services
- Total raised
- $150M raised