SonatypeSO

Security Researcher

The Sonatype journey started 10 years ago, just as the concept of “open source” software development was gaining steam.

Sonatype

Employee count: 201-500

Canada only
Apply now
Sonatype is the software supply chain management company. We're on a mission to change how the world innovates by making software development easier. From running the world's largest repository of Java open-source components (Maven Central) to inventing componentized software development and then software supply chain management to creating the only solution that stops malicious open-source malware in its tracks, we're constantly leading the industry while helping thousands of customers manage open source every day.
Already used by 15 million developers, we have lofty goals for our technology to be in the hands of every engineering team. And we need you to do that. Join us!
Learn more at www.sonatype.com.
Sonatype’s mission is to enable organizations to better manage their software supply chain. We offer a series of products and services including the Sonatype Nexus Repository and Sonatype Lifecycle.
**This position is 100% remote and candidates must currently live in Colombia.
The Security Researcher will investigate and analyze vulnerabilities in open-source software.
Sonatype is looking for a passionate, driven and talented Security Researcher to provide high quality security data from researching software vulnerabilities. This high-quality security data ensures that our customers are getting maximum value out of our products making them feel like they are part of the Sonatype family. If you are a positive-thinker and problem-solver and believe that customer success and company success go hand-in-hand, this is a great job for you. This position will provide a valuable learning opportunity with great potential to grow your newly started career in cyber-security. Enjoy your job as you work in a fast-paced, flexible, and fun environment, with talented, diverse, and forward-thinking individuals.

Responsibilities:

  • Review, isolate, analyze, and reverse engineer vulnerabilities in open-source software.
  • Document attack capabilities.
  • Provide detection and remediation guidance.
  • Aid in ideas and prototypes for new tooling.
  • Collaborate with other team members toward shared product goals.
  • Improve Sonatype products by providing valuable security data.
  • Work with technology and business team members to define and refine requirements in an agile development environment

Required Qualifications:

  • Bachelor of Science Degree in Computer Science, Cybersecurity, Engineering, or related field; or at least 4 years of related work experience in lieu of a degree.
  • 5 + years experience in software development or application security.
  • 3 + years of experience with Java, C#, or JavaScript.
  • Excellent oral and written communication skills

Desired Qualifications:

  • Knowledge of application security such as the OWASP Top 10 or Sans 25.
  • Excellent organizational skills and detail oriented.
  • Ability to work independently and as part of a team
We support our remote employee experience. While we have offices in Fulton MD, Tyson's Corner VA, London UK, and Sydney AUS, we are remote first and always have been. We use a number of communication tools to connect across the company, keep information flowing day to day, and meet face-to-face on a targeted basis at organization and team meetups.
Thousands of organizations and millions of developers use our software. If you have a passion for improving how the world develops software, Sonatype is the right place for you.
At Sonatype, we value diversity and inclusivity. We offer perks such as parental leave, diversity and inclusion working groups, and flexible working practices to allow our employees to show up as their whole selves. We are an equal-opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you have a disability or special need that requires accommodation, please do not hesitate to let us know.

Elevate your application

Let our AI craft your perfect cover letter and align your resume to this job's criteria.

By using our AI tools, you consent to sharing your profile with our AI partner for this purpose.

Apply now

Please let Sonatype know you found this job on Himalayas. This helps us grow!

Apply now

About the job

Apply before

May 23, 2024

Posted on

Mar 24, 2024

Job type

Full Time

Experience level

Mid-level

Location requirements

Hiring timezones

Canada +/- 0 hours

About Sonatype

Learn more about Sonatype and their company culture.

View company profile

The Sonatype journey started 10 years ago, just as the concept of “open source” software development was gaining steam. From our humble beginning as core contributors to Apache Maven to supporting the world’s largest repository of open source components (Central) to distributing the world's most popular repository manager (Nexus), we’ve played a meaningful role in helping the world embrace the power of open innovation.

Over time, we witnessed the staggering volume and variety of open source libraries that began flowing into every development environment in the world. We understood that when open source components are properly managed, they provide tremendous energy for accelerating innovation. Conversely, when unmanaged, open-source "gone wild"​ can lead directly to security vulnerabilities, licensing risks, enormous rework, and waste.

Our vision today is simple.

We are laser-focused on helping organizations continuously harness all of the good that open source has to offer, without any of the risks. In order to do this, we have invested in knowing more about the quality of open source than anyone else in the world. This investment takes the form of machine learning, artificial intelligence, and human expertise, which in aggregate produces highly curated intelligence that is infused into every Nexus product. Organizations equipped with Nexus products make better decisions, innovate faster at scale, and rest comfortably knowing that their applications always consist of the highest quality open source components.

Employee benefits

Learn about the employee benefits and perks provided at Sonatype.

View benefits

Paid parental leave

Paid family leave for all parents to support you and your family.

Employee assistance program (EAP)

We offer an employee assistance program focused on mental health.

Stock options

Every employee gets equity, so you are rewarded for your best work.

Volunteer opportunities

Time off each year on us to volunteer at a non profit that matters to you.

View Sonatype's employee benefits
Claim this profileSonatype logoSO

Sonatype

View company profileVisit sonatype.com

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

15 remote jobs at Sonatype

Explore the variety of open remote roles at Sonatype, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Sonatype

Remote companies like Sonatype

Find your next opportunity by exploring profiles of companies that are similar to Sonatype. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join thousands of other remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan