Staff Info Sec AI Researcher

Sonatype

Hyderabad

On-site

INR 4,000,000 - 7,000,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Parental leave
Diversity and inclusion working groups
Flexible working practices

Job summary

Sonatype is seeking an AI Red Team Staff Software Engineer to shape a high‑impact security engineering capability at the intersection of frontier AI and software supply chain defense. You will use advanced AI models and tooling to discover, validate, and remediate meaningful risks across Sonatype’s products and codebases.

You will collaborate with Security Research, Product, and Engineering to translate findings into actionable guidance, detection opportunities, and customer‑facing intelligence.

Qualifications

  • 8+ years of professional software engineering experience, including 2+ years in a Staff Engineer or equivalent leadership role.
  • Proven experience identifying, validating, and helping remediate vulnerabilities in production software, services, or supply chain components.
  • Strong ability to read and reason about complex codebases, preferably Java/Kotlin or JVM‑based backend systems.
  • Hands‑on experience with security testing methods and tools such as SAST/DAST/SCA, secret scanning, threat modeling, and secure code review.
  • Experience using AI‑assisted engineering or automation to improve software quality outcomes.
  • Clear ability to translate security findings into remediation guidance and prioritized actions.
  • Bachelor’s degree in CS/Engineering or equivalent experience, plus strong collaboration across security and engineering teams.

Responsibilities

  • Identify and prioritize meaningful security risks across code, services, and supply chain.
  • Validate findings for exploitability, severity, and remediation priority.
  • Translate findings with product and security teams into actionable outputs and detection opportunities.
  • Collaborate with Engineering to move validated findings through remediation and reduce repeat vulnerabilities.
  • Champion AI‑SDLC practices by creating reusable guidance, detection logic, and remediation playbooks.
  • Create clear remediation guidance and engineering‑ready fix proposals.

Skills

Staff Engineer
Vulnerability remediation
Security analysis
Java/Kotlin backend
AI-assisted engineering

Education

Bachelor's degree in Computer Science or Engineering

Tools

SAST
DAST
SCA
Secret scanning
Threat modeling
Secure code review
Vulnerability validation

Job description

Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only enterprise grade SBOM management and the leading open source dependency management platform. This empowers enterprises to create and maintain secure, quality, and innovative software at scale.

As founders of Nexus Repository and stewards of Maven Central, the world’s largest repository of Java open‑source software, we are software pioneers and our open source expertise is unmatched. We empower innovation with an unparalleled commitment to building faster, safer software and harness AI and data intelligence to mitigate risk, maximize efficiencies, and drive powerful software development.

More than 2,000 organizations, including 70% of the Fortune 100 and 15 million software developers, rely on Sonatype to optimize their software supply chains.

At Sonatype, we empower developers with best‑in‑class tools to build secure, high‑quality software at scale. Our mission is to create a world where software is always secure and developers can innovate without fear. Trusted by thousands of organizations, including Fortune 500 companies, we are pioneers in software supply chain management, open‑source security, and DevSecOps.

As an AI Red Team Staff Software Engineer at Sonatype, you will help shape a high‑impact security engineering capability at the intersection of frontier AI, offensive application security, and software supply chain defense. You will use advanced AI models, techniques, and security tooling to discover, validate, and help remediate meaningful risks across Sonatype’s products, codebases, infrastructure, and dependencies.

What You’ll Do

Your work will turn security findings into durable defensive improvements, including remediation guidance, engineering‑ready fix proposals, reusable AI‑SDLC patterns, secure coding guidance, and product‑security insights that reduce exposure and raise the bar for secure engineering at Sonatype.

Key Responsibilities
  • Identify and prioritize meaningful security risks across first‑party code, services, infrastructure, build pipelines, and software supply chain components.
  • Validate findings for exploitability, severity, affected products, business impact, and remediation priority.
  • Collaborate with Security Research and Product to translate novel findings, malicious component discoveries, and emerging attack patterns into research‑ready outputs, product improvements, detection opportunities, and customer‑facing intelligence.
  • Work closely with Application Security and Engineering to move validated findings through remediation and reduce repeat vulnerability patterns.
  • Champion modern AI‑SDLC practices by translating recurring vulnerability classes, insecure coding patterns, and effective remediation approaches into reusable guidance, detection logic, secure coding standards, and remediation playbooks.
  • Create clear remediation guidance, engineering‑ready fix proposals, and pull requests where appropriate.
What We’re Looking For

We’re seeking an experienced engineer who thrives in an agile, collaborative environment and enjoys tackling technical challenges.

Minimum Qualifications
  • 8+ years of professional software engineering experience, including 2+ years in a Staff Engineer or equivalent technical leadership role.
  • Proven experience identifying, validating, and helping remediate vulnerabilities in production software, services, APIs, infrastructure, or software supply chain components.
  • Strong ability to read, understand, and reason about complex codebases, preferably including Java, Kotlin, or other JVM‑based backend systems.
  • Hands‑on experience with application security testing methods and tools, such as SAST, DAST, SCA, secret scanning, threat modeling, secure code review, or vulnerability validation.
  • Practical experience using AI‑assisted engineering, security analysis, or automation techniques to improve software quality outcomes.
  • Ability to translate security findings into clear remediation guidance, engineering‑ready recommendations, and practical risk‑based priorities.
  • Bachelor’s degree in Computer Science, Engineering, or a related field—or equivalent practical experience.
  • Strong communication and collaboration skills, with experience working across Application Security, Engineering, Product, or Security Research teams.
Nice‑to‑Have Skills
  • Solid understanding of cloud‑native architecture, CI/CD workflows, build pipelines, containers, and modern DevOps practices.
  • Passion for raising the security bar through technical leadership, mentoring, secure engineering practices, and continuous improvement.
  • Relevant certifications such as:
    • SANS Certifications: GSEC, GCIH, GCLD, GCID, GMON
    • (ISC)² Certifications: CISSP, CC, SSCP, CCSP, CAP, CSSL

At Sonatype, we value diversity and inclusivity. We offer perks such as parental leave, diversity and inclusion working groups, and flexible working practices to allow our employees to show up as their whole selves. We are an equal‑opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you have a disability or special need that requires accommodation, please do not hesitate to let us know.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Product Support Engineering
Manager, Product Support Engineering

Sonatype • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Parental leave
Diversity and inclusion groups
Flexible working
Senior Data Scientist
Senior Data Scientist

Sonatype • Hyderabad

On-site
INR 4,000,000 - 7,000,000
Parental leave
Diversity & inclusion groups
Flexible working
Staff Software Engineer - Agentic First
Staff Software Engineer - Agentic First

Sonatype Inc • Thiruvananthapuram

On-site
INR 3,000,000 - 5,400,000
Diversity & Inclusion Working Groups
Parental Leave Policy
Paid Volunteer Time Off (VTO)
Senior GCP DevOps Engineer
Senior GCP DevOps Engineer

Sonatype • Hyderabad

On-site
INR 4,000,000 - 7,000,000
Parental leave
Diversity & inclusion groups
Flexible working practices
Sales Engineer, Emea
Sales Engineer, Emea

Sonatype Inc • Hyderabad

On-site
INR 1,800,000 - 3,000,000
Parental leave
Diversity & inclusion
Flexible working
Associate Customer Success Manager
Associate Customer Success Manager

Sonatype • Hyderabad

On-site
INR 900,000 - 1,200,000
Parental leave
Diversity and inclusion groups
Flexible working practices
Product Manager - SBOM
Product Manager - SBOM

Sonatype Inc • Hyderabad

On-site
INR 1,500,000 - 2,100,000
Parental leave
Diversity & Inclusion groups
Flexible working practices
+1
Senior Azure DevOps Engineer
Senior Azure DevOps Engineer

Sonatype Inc • Hyderabad

On-site
INR 1,800,000 - 3,200,000
Parental leave
Flexible working
Senior GCP DevOps Engineer
Senior GCP DevOps Engineer

Sonatype Inc • Hyderabad

On-site
INR 1,500,000 - 2,100,000
Parental leave
Diversity and inclusion
Flexible working
Senior Azure DevOps Engineer
Senior Azure DevOps Engineer

Sonatype • Hyderabad

On-site
INR 3,000,000 - 4,200,000
Parental leave
Diversity and inclusion groups
Flexible working practices
+1