An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Sonatype is seeking an AI Red Team Staff Software Engineer to shape a high‑impact security engineering capability at the intersection of frontier AI and software supply chain defense. You will use advanced AI models and tooling to discover, validate, and remediate meaningful risks across Sonatype’s products and codebases.
You will collaborate with Security Research, Product, and Engineering to translate findings into actionable guidance, detection opportunities, and customer‑facing intelligence.
Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only enterprise grade SBOM management and the leading open source dependency management platform. This empowers enterprises to create and maintain secure, quality, and innovative software at scale.
As founders of Nexus Repository and stewards of Maven Central, the world’s largest repository of Java open‑source software, we are software pioneers and our open source expertise is unmatched. We empower innovation with an unparalleled commitment to building faster, safer software and harness AI and data intelligence to mitigate risk, maximize efficiencies, and drive powerful software development.
More than 2,000 organizations, including 70% of the Fortune 100 and 15 million software developers, rely on Sonatype to optimize their software supply chains.
At Sonatype, we empower developers with best‑in‑class tools to build secure, high‑quality software at scale. Our mission is to create a world where software is always secure and developers can innovate without fear. Trusted by thousands of organizations, including Fortune 500 companies, we are pioneers in software supply chain management, open‑source security, and DevSecOps.
As an AI Red Team Staff Software Engineer at Sonatype, you will help shape a high‑impact security engineering capability at the intersection of frontier AI, offensive application security, and software supply chain defense. You will use advanced AI models, techniques, and security tooling to discover, validate, and help remediate meaningful risks across Sonatype’s products, codebases, infrastructure, and dependencies.
Your work will turn security findings into durable defensive improvements, including remediation guidance, engineering‑ready fix proposals, reusable AI‑SDLC patterns, secure coding guidance, and product‑security insights that reduce exposure and raise the bar for secure engineering at Sonatype.
We’re seeking an experienced engineer who thrives in an agile, collaborative environment and enjoys tackling technical challenges.
At Sonatype, we value diversity and inclusivity. We offer perks such as parental leave, diversity and inclusion working groups, and flexible working practices to allow our employees to show up as their whole selves. We are an equal‑opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you have a disability or special need that requires accommodation, please do not hesitate to let us know.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.