HimalayasHimalayas logo
SonatypeSO

Staff Software Engineer - Agentic First

The Sonatype journey started 10 years ago, just as the concept of “open source” software development was gaining steam.

Sonatype

Employee count: 201-500

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only enterprise grade SBOM management and the leading open source dependency management platform. This empowers enterprises to create and maintain secure, quality, and innovative software at scale.
As founders of Nexus Repository and stewards of Maven Central, the world’s largest repository of Java open-source software, we are software pioneers and our open source expertise is unmatched. We empower innovation with an unparalleled commitment to build faster, safer software and harness AI and data intelligence to mitigate risk, maximize efficiencies, and drive powerful software development.
More than 2,000 organizations, including 70% of the Fortune 100 and 15 million software developers, rely on Sonatype to optimize their software supply chains.

About the Role

As an agentic-first Staff Software Engineer, you will lead the design and delivery of enterprise-grade, agentic-first capabilities within Nexus Repository Manager. You'll set technical direction for a major product area, orchestrate fleets of agents across parallel workstreams as your primary mode of work, and define the agentic engineering practices that other teams will learn from. You'll partner with Principal engineers on the hardest technical decisions and mentor Senior engineers to deliver capabilities that help enterprises secure their software supply chains at massive scale.

Why You Will Want to Apply

  • Own the architecture of agentic-first features in a product used by 15 million developers and 70% of the Fortune 100.
  • Practice a fundamentally new way of building software — long-running, multi-agent development — alongside Staff and Principal engineers who are defining the craft.
  • Work on the hardest problems at the intersection of AI, distributed systems, and software supply chain security — a space where the industry playbook is still being written.
  • Shape the technical roadmap for Nexus, set the engineering hiring bar, and mentor Senior engineers who will carry the craft forward.

What You Will do

    • Architect & Lead With Agents: Drive the technical design of major agentic-first subsystems — service architecture, data models, and agent/tool integrations — by running long-running, multi-agent workflows across decomposition, orchestration, implementation, testing, and review.
      • Own a Product Area: Take major initiatives from ambiguous problem statements through technical design, multi-team execution, rollout, and long-term operability.
        • Verification Over Generation, at Scale: Spend your time on direction, review, and taste rather than line-by-line coding. Define the evals, harnesses, guardrails, and review rituals that let your team confidently ship code no human typed.
          • Define the Practice: Set the bar for how Sonatype engineers work with agents. Shape internal playbooks, tooling, and rituals; train Senior engineers in the craft; and raise the ceiling on what's possible.
            • Architecture, Security & Reliability: Own non-functional requirements for your area — performance, reliability, and security — with particular attention to software supply chain threats (malicious packages, dependency confusion, provenance, SBOM accuracy).
              • Cross-functional Leadership: Partner with Product, Security Research, UX, and Support leaders to translate ambiguous customer needs into concrete, shippable technical plans; conduct deep design reviews; and raise the quality bar through thoughtful mentorship.

Who You Are

    • Long-running Agentic Developer: Multi-step, long-running agent workflows are your default way of building software — well beyond Copilot-style autocomplete. You routinely orchestrate fleets of agents in parallel across planning, coding, testing, and review, and your own time is spent on direction, verification, and taste rather than generation.
      • Multi-agent Orchestration at Depth: Hands-on experience designing, running, and scaling multi-agent systems (e.g., Claude Code, Codex, Cursor background agents, custom orchestrators, LangGraph-style graphs) — including MCP tooling, shared context and memory, agent handoffs, and robust eval harnesses. You've shipped production work this way and have strong opinions on what holds up at scale.
        • Verification-first Mindset: You've internalized that the new leverage point is human judgment over machine generation. You define the evals, test harnesses, observability, and review workflows that let a team confidently ship code no one personally typed.
          • Shapes Leading-edge Practice: You don't just adopt agentic workflows — you define them. You've led internal rollouts, published, open-sourced, or otherwise pushed the state of the art on how engineers work alongside agents, and have a clear point of view on where the craft is heading.
            • Product Engineering Mindset: Half product, half engineering. You make product decisions independently and drive scope, trade-offs, and sequencing without constant PM hand-holding.
              • Focused on What Matters: You want to build mission-critical products that drive revenue and transform how customers build software.
                • Staff-level Engineering Skills: 7+ years of professional software development, with a track record of leading multi-quarter technical initiatives that span multiple teams or services.
                  • Deep Technical Foundation: Strong experience with Java, Cloud (AWS / Azure / GCP), and large-scale distributed systems — including performance tuning, data-intensive services, and production operability at scale.
                    • DevSecOps & Supply Chain Depth: Working knowledge of software supply chain security — SBOM formats (CycloneDX, SPDX), SCA, SLSA provenance, Sigstore/cosign signing, vulnerability analysis (OSV, NVD), and common attack patterns against package ecosystems.
                      • Deeply Curious: You push agentic tools to their limits — probing where they work, where they break, and how to make them better. You're energized by being early in a fundamentally new way of building software.

What We Are Proud Of

    • 2025 Visionary in Gartner® Magic Quadrant™ for Application Security Testing!
    • 2025 AI Compliance Solution of the Year - AI Breakthrough Awards
    • 2025 DEVIES Award to our SBOM Manager for a new product for its innovation and impact in developer technology
    • 2024 Industry Leader in Forrester-Wave for Software Composition Analysis (2024 Q4 report)
    • Constellation AST Shortlist: Sonatype has been listed on the Constellation ShortList™ for Application Security Testing for 2024
    • Data Breakthrough Awards: Sonatype was announced as a 2024 winner in the "Open Source Data Solution of the Year."
    • SD Times: Best in Show Security
    • Fast Company Best Workplaces for Innovators 2024
    • The Herd Top 100 Private Software Companies 2024.
    • Diversity & Inclusion Working Groups
    • Parental Leave Policy
    • Paid Volunteer Time Off (VTO)
At Sonatype, we value diversity and inclusivity. We offer perks such as parental leave, diversity and inclusion working groups, and flexible working practices to allow our employees to show up as their whole selves. We are an equal-opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you have a disability or special need that requires accommodation, please do not hesitate to let us know.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Experience

7 years minimum

Location requirements

Hiring timezones

United States +/- 0 hours

About Sonatype

Learn more about Sonatype and their company culture.

View company profile

The Sonatype journey started 10 years ago, just as the concept of “open source” software development was gaining steam. From our humble beginning as core contributors to Apache Maven to supporting the world’s largest repository of open source components (Central) to distributing the world's most popular repository manager (Nexus), we’ve played a meaningful role in helping the world embrace the power of open innovation.

Over time, we witnessed the staggering volume and variety of open source libraries that began flowing into every development environment in the world. We understood that when open source components are properly managed, they provide tremendous energy for accelerating innovation. Conversely, when unmanaged, open-source "gone wild"​ can lead directly to security vulnerabilities, licensing risks, enormous rework, and waste.

Our vision today is simple.

We are laser-focused on helping organizations continuously harness all of the good that open source has to offer, without any of the risks. In order to do this, we have invested in knowing more about the quality of open source than anyone else in the world. This investment takes the form of machine learning, artificial intelligence, and human expertise, which in aggregate produces highly curated intelligence that is infused into every Nexus product. Organizations equipped with Nexus products make better decisions, innovate faster at scale, and rest comfortably knowing that their applications always consist of the highest quality open source components.

Employee benefits

Learn about the employee benefits and perks provided at Sonatype.

View benefits

Paid parental leave

Paid family leave for all parents to support you and your family.

Employee assistance program (EAP)

We offer an employee assistance program focused on mental health.

Stock options

Every employee gets equity, so you are rewarded for your best work.

Volunteer opportunities

Time off each year on us to volunteer at a non profit that matters to you.

View Sonatype's employee benefits
Claim this profileSonatype logoSO

Sonatype

Company size

201-500 employees

Founded in

2008

Chief executive officer

Wayne Jackson

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

7 remote jobs at Sonatype

Explore the variety of open remote roles at Sonatype, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Sonatype

Remote companies like Sonatype

Find your next opportunity by exploring profiles of companies that are similar to Sonatype. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan