Full-Time

Senior Full Stack Software Engineer

Posted on 12/4/2025

Sonatype

Sonatype

501-1,000 employees

OSS governance and security platform

No salary listed

Hyderabad, Telangana, India

Hybrid

Category
Software Engineering (1)
Required Skills
Kubernetes
Microsoft Azure
JavaScript
React.js
MySQL
Java
Postgres
Docker
TypeScript
AWS
Terraform
Vue.js
Ansible
MongoDB
REST APIs
DevOps
AngularJS
Cassandra
Google Cloud Platform
Requirements
  • Five or more years of experience as a Full Stack Software Engineer, with a focus on scalable web applications.
  • Deep experience with backend development using Java.
  • Strong proficiency in JavaScript and TypeScript and front-end frameworks including React, Angular, or Vue.js.
  • Expertise in building RESTful APIs and event-driven architectures.
  • Hands-on experience with cloud platforms (Amazon Web Services, Google Cloud Platform, or Microsoft Azure) and serverless computing.
  • Strong knowledge of containerization (Docker, Kubernetes) and infrastructure as code (Terraform, Ansible).
  • Familiarity with secure coding practices and software supply chain security principles.
Responsibilities
  • Architect, develop, and optimize full-stack applications with modern web technologies.
  • Lead the design and implementation of scalable microservices, APIs, and cloud-based solutions.
  • Develop and maintain front-end applications using React, Angular, or Vue.js, ensuring a seamless user experience.
  • Build robust backend services using Java, integrating with databases and external systems.
  • Drive best practices in software engineering, including code reviews, design patterns, and scalable architectures.
  • Work with containerization (Docker, Kubernetes) and cloud platforms like AWS, GCP, or Azure.
  • Optimize database performance with relational (PostgreSQL, MySQL) and NoSQL (MongoDB, Cassandra) solutions.
  • Collaborate with cross-functional teams, including product managers, designers, and DevOps, to deliver high-quality software.
  • Mentor and guide junior engineers, fostering a culture of learning and innovation.
  • Ensure high availability, security, and performance of applications through proactive monitoring and testing.
  • Continuously improve CI/CD pipelines, development workflows, and automation strategies.
Desired Qualifications
  • A track record of technical leadership in driving projects and mentoring engineers.
  • Strong problem-solving skills and the ability to work in a remote-first, agile environment.
  • A passion for open-source technologies and a drive to stay ahead of industry trends.

Sonatype focuses on helping organizations manage and secure their use of open-source software. Its Nexus Platform automates DevOps workflows and governs open-source usage, covering the software supply chain from building and storing artifacts to checking for security defects across the SDLC. Its OSS Edition offers free artifact management, while paid offerings like Nexus Repository Manager Professional and Nexus Lifecycle add high-availability, security defect detection, and risk elimination features. The company differentiates itself by specializing in open-source governance and software security across the entire development lifecycle, serving IT leaders, developers, and industries such as healthcare. Its goal is to enable safe, efficient, and compliant use of open-source software to improve software quality and security.

Company Size

501-1,000

Company Stage

Growth Equity (Venture Capital)

Total Funding

$154.7M

Headquarters

Fulton, Missouri

Founded

2008

Simplify Jobs

Simplify's Take

What believers are saying

  • Sonatype Guide achieves 300% security improvement in AI-assisted development.
  • Nexus Repository Cloud launched October 2025 enables zero-maintenance SaaS scaling.
  • Vertosoft partnership expands public sector access via government contracts.

What critics are saying

  • Snyk erodes Fortune 100 share with faster AI vulnerability scanning now.
  • Trivy scanner gains 35% adoption, cannibalizing OSS Edition immediately.
  • CISA framework forces Nexus format migration for federal clients by 2027.

What makes Sonatype unique

  • Nexus Platform automates DevOps and governs open-source usage uniquely.
  • Sonatype Guide integrates with GitHub Copilot for secure AI coding.
  • Maintains Maven Central, pioneering open-source supply chain security since 2008.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Distributed Workforce - Walls don’t make a company great, people do — and we have the best. While we have offices in the US in Maryland and Virginia, and also in London and Sydney, our growing and talented team lives and works anywhere and everywhere.

Mission Driven - We’re helping software developers harness the power of open source, while making software safer. What does that mean for you? An opportunity to join a smart, mission-oriented team that is changing how software is made.

Competitive Salary & Benefits - We believe in taking care of our team. That means more than just interesting work — it's great benefits, competitive compensation packages, flexible schedules, and an endless opportunity to learn and grow.

Open, Transparent, Diverse - Our varied experiences, locations, ethnicities, genders, and sexual orientations, make us a better company. That's why we're committed to bringing different backgrounds and perspectives into our organization.

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

-1%

2 year growth

2%
Spring
Mar 18th, 2026
Spring Batch 6.0.3 and 5.2.5 available now.

Spring Batch 6.0.3 and 5.2.5 available now. On behalf of the team and all contributors, I am pleased to announce that Spring Batch 6.0.3 and 5.2.5 are available from Maven Central now. These releases come with a number of bug fixes, improvements and documentation updates. The release notes can be found on GitHub: 6.0.3, 5.2.5. These versions will be available respectively through Spring Boot 4.0.4 and 3.5.12. Get ahead. VMware offers training and certification to turbo-charge your progress. Get support. Tanzu Spring offers support and binaries for OpenJDK(TM), Spring, and Apache Tomcat(R) in one simple subscription.

SiliconANGLE Media
Dec 9th, 2025
Sonatype debuts guide to secure AI-assisted software development

Sonatype debuts guide to secure AI-assisted software development. Software supply chain management firm Sonatype Inc. today announced the launch of Sonatype Guide, a new developer tool that makes artificial intelligence-assisted software development faster, safer and more efficient. The service is designed to serve as an intelligent backbone that steers AI coding assistants toward secure, high-quality open-source components and autonomously maintains dependencies over time. The problem that Sonatype Guide is seeking to assist with is that AI models are trained on public data that may be months or years out of date. So AI coding assistants, intended to help developers move faster, frequently recommend vulnerable, low-quality or even imagined packages. According to a forthcoming study from Sonatype, leading generative AI large language models that power coding assistants hallucinate packages up to 27% of the time, meaning they attempt to update or develop modern software with nonexistent or malicious open-source components. That creates rework for development teams, slows delivery, burns LLM tokens and introduces unnecessary security risk. In pre-launch testing, enterprises using Sonatype Guide achieved more than a 300% improvement in security outcomes while reducing total security remediation. The service also improved dependency-upgrade costs by more than five compared to the leading competitive strategy, measured in both direct spend and developer hours. "Every organization wants to harness the productivity of AI, but they can't afford to compromise security or long-term maintainability," said Chief Executive Bhagwat Swaroop. "Guide brings discipline and intelligence to AI-assisted development. It empowers teams to move faster and safer by steering AI toward secure, reliable components and automating the tedious dependency work that slows teams down. This is a significant step forward for the industry and for our customers." Sonatype Guide works with popular AI coding assistants, including GitHub Copilot, Google Antigravity, Claude Code, Windsurf, IntelliJ with Junie, Kiro from Amazon Web Services Inc. and Cursor, to allow organizations to keep their existing workflows while upgrading the quality and security of the dependencies pulled in. Core features of Sonatype Guide include a Model Context Protocol Server for AI coding assistants, which intercepts package recommendations in real time to instantly guide developers to secure, reliable versions before code reaches the repo. The MCP server is complemented with enhanced open-source software search for instant decisions. It also has an enterprise-grade application programming interface that delivers complete, unrestricted and backward-compatible access to reliable data. Guide is built on Sonatype Intelligence, a source of real-time data on open-source quality, security and project health that can identify vulnerabilities, deprecations and malicious packages long before they spread. By embedding this intelligence directly into AI workflows, the company says, Guide ensures developers make safe, informed decisions from the start. Image: siliconangle/ideogram. A message from John Furrier, co-founder of SiliconANGLE: Support its mission to keep content open and free by engaging with theCUBE community. Join theCUBE's Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities. * 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more * 11.4k+ theCUBE alumni - Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network. SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios - with flagship locations in Silicon Valley and the New York Stock Exchange - SiliconANGLE Media operates at the intersection of media, technology and AI. Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Its new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

DEVOPSdigest
Nov 19th, 2025
Red Hat Introduces Project Hummingbird

Red Hat introduces Project Hummingbird. Red Hat announced Project Hummingbird, an early access program for Red Hat subscription customers that provides a catalog of minimal, hardened container images. Project Hummingbird is designed to help IT organizations address the constantly growing demand for better software with minimal attack surfaces, delivered more swiftly without compromising production security. Project Hummingbird addresses the dueling needs of speed and risk mitigation with a catalog of tested, micro-sized container images stripped of non-essential components, including: By offering these leaner, production-ready images, Project Hummingbird intends to reduce the time and effort spent on package integration and vulnerability management, freeing up resources to focus on faster, more effective innovation. - "Zero-CVE" status, meaning that Project Hummingbird images are shipped free of known vulnerabilities with functionality testing already completed, confirming that the images are also genuinely useful and stable. - Full production support will be available to subscription customers when Project Hummingbird is released for general availability. This delivers the full extent of a Red Hat subscription, providing access to Red Hat's hardened, documented software supply chain and deep enterprise expertise. Additionally, unsupported Project Hummingbird images will be freely available and redistributable at general availability, alongside following a similar model to other Red Hat offerings including Red Hat Universal Base Image (UBI). Project Hummingbird is built using the open source development process, originating from Fedora Linux components. Fedora Linux serves as the upstream source for Red Hat Enterprise Linux development. Red Hat announced Project Hummingbird, an early access program for Red Hat subscription customers that provides a catalog of minimal, hardened container images. Sonatype announced the launch of Nexus One, a single, agentic software supply chain infrastructure unifying open source intelligence, governance, and automation across enterprise software development. Progress Software announced its SaaS Retrieval-Augmented Generation (RAG) platform, Progress(R) Agentic RAG, is now available in AWS Marketplace, a digital catalog that helps customers find, buy, deploy and manage software, data products and professional services from thousands of vendors. Parasoft(link is external) announced a significant leap forward in autonomous software quality with its latest 2025.2 releases of Jtest and dotTEST. CloudBees announced the launch of the Unify AI Design Partner (AIDP) program. noBGP announced the launch of pi GPT, a custom GPT for OpenAI's ChatGPT that allows users to bring their Raspberry Pi devices into the vibe coding ecosystem. Postman announced its acquisition of liblab, a platform for developers that automates the generation and maintenance of Software Development Kits (SDKs). JFrog announced an expansion of its AI governance capabilities within the JFrog Software Supply Chain Platform with the introduction of Shadow AI Detection. Red Hat introduced the general availability of Red Hat Enterprise Linux 10.1 and 9.7, building on the innovations of Red Hat Enterprise Linux 10 for a more intelligent and future-ready computing foundation. Solo.io announced the launch of agentregistry, a centralized, trusted, and curated open source registry for AI applications and artifacts. Red Hat announced the general availability of Red Hat OpenShift 4.20, the latest version of the hybrid cloud application platform powered by Kubernetes. The Cloud Native Computing Foundation(R)(CNCF(R), which builds sustainable ecosystems for cloud native software, announced a major new release of Helm, coinciding with the project's 10th anniversary. Mirantis announced the latest release of Mirantis k0rdent Enterprise, with Mirantis k0rdent Virtualization - enabling workloads to run with cloud-native applications and traditional virtualized workloads. Couchbase announced significant advancements to the Couchbase Mobile platform, which makes it possible to run AI-powered applications on devices operating at the disconnected edge. Legit Security announced VibeGuard, a solution designed to secure AI-generated code at the moment of creation and to secure coding agents.

ExecutiveBiz
Nov 11th, 2025
Sonatype Partners With Vertosoft to Strengthen Public Sector Software Supply Chain Security

Sonatype partners with Vertosoft to strengthen public sector software supply chain security. Sonatype has named Vertosoft its new value-added distributor to expand public sector access to secure software development and supply chain management tools through Vertosoft's government contract portfolio and partner network. The partnership comes amid the artificial intelligence era, where the technology becomes central to software engineering, according to a Vertosoft press release. The growing focus on responsible and secure AI adoption will take center stage at the Potomac Officers Club's 2026 Artificial Intelligence Summit on March 19, where federal and industry leaders will discuss how machine learning, automation and software assurance are transforming government operations. The event will bring together practitioners from across defense, civilian and tech sectors to explore practical strategies for building trustworthy AI systems and resilient digital supply chains. Register now to join the discussion shaping the future of AI in the public sector. "AI is redefining how agencies build, test, and deploy software," said Antoine Harden, regional vice president of federal sales at Sonatype. "Together, Sonatype and Vertosoft are enabling government developers to harness AI responsibly - embedding automation, security, and compliance directly into the software development lifecycle." What does the Sonatype Vertosoft partnership cover? Vertosoft will distribute Sonatype's full product suite, including its software bill of materials management platform, open-source malware detection tools and dependency governance tools. These capabilities are tailored to meet federal compliance and security requirements and to address rising threats within open-source ecosystems. "Our partnership with Sonatype marks a pivotal step in strengthening software supply chain security across the public sector," said Josh Slattery, vice president of technology sales at Vertosoft. "By combining Sonatype's industry-leading platform with Vertosoft's deep public sector expertise, we're enabling agencies to proactively manage risk, ensure compliance, and accelerate innovation with confidence."

Sonatype
Oct 8th, 2025
Sonatype Launches Nexus Repository Cloud for the Gen AI Era

Sonatype launches nexus repository cloud for the gen AI era. World's most trusted binary artifact manager now available as a cloud-native, fully managed saas offering with built-in malware protection. Fulton, md. - october 8, 2025 - sonatype(r), the leader in ai-centric devsecops, today announced the launch of nexus repository available in the cloud, the fully managed saas version of its industry-leading artifact repository manager. Built for modern software delivery and the speed of the gen ai-powered SDLC, nexus repository cloud empowers developers and devops teams to build, release, and deploy applications at enterprise scale - with zero maintenance and built-in protection against malicious open source. Trusted by 70% of the fortune 100 and more than 15 million developers worldwide, nexus repository has long been the backbone of enterprise software development. As more enterprises implement AI into their development processes, the need for reliable, scalable, and secure artifact management in the cloud has never been greater. Sonatype research estimates 50% of unprotected repositories have already cached open source malware, putting enterprises at risk when developers pull dependencies directly into production pipelines. "In today's gen AI era, enterprises need more than just another cloud repository - they need one that's inherently intelligent and secure," said mitchell johnson, chief product development officer at sonatype. "Because sonatype uniquely combines deep open source intelligence with artifact management, nexus repository is the industry's first and only secure binary artifact repository. With the launch of nexus repository cloud, enterprises can now choose a fully managed saas option to run at enterprise speed and scale, without ever trading off security for productivity." Nexus repository cloud brings all the power of the industry's most trusted repository into a cloud-native, fully managed service with: * enterprise speed and scale: cloud-native elasticity ensures performance never becomes a bottleneck. * zero maintenance: fully managed saas eliminates upgrades, patches, and downtime overhead. * ai-era artifact management: A central system of record for modern artifacts, from open source packages to AI/ML models. * malware protection: powered by sonatype's unmatched open source intelligence and repository firewall, automatically blocking open source malware. * developer-first experience: fast performance, simple onboarding, and the same trusted workflows developers already use. "As we accelerate our cloud-first strategy at sonatype, i'm excited to see our flagship nexus repository solution move to the cloud - a key step as we continue to shape the future of secure software development," said bhagwat swaroop, chief executive officer at sonatype. "By delivering our most trusted repository manager as a fully managed service, we're helping enterprises scale with confidence, simplify operations, and give developers the modern foundation they need to thrive in the AI era." Available on the sonatype website or on AWS marketplace, nexus repository gives teams the flexibility to build and scale globally. For more information on sonatype nexus repository, visit www.sonatype.com/products/sonatype-nexus-repository. About sonatype sonatype is the leader in ai-centric devsecops. As the maintainers of maven central and creators of nexus repository, sonatype has spent two decades pioneering how the world manages and secures open source software - making sonatype the trusted authority for modern software supply chains. With unmatched open source visibility and a unified product suite built for modern software development, sonatype gives enterprises the intelligence and automated governance they need to harness the full potential of open source and AI. Sonatype handles the complexity behind the scenes: guiding component and model selection, blocking harmful malicious code, automating dependency and vulnerability management, and ensuring faster, more reliable builds - so developers spend more time on innovation and less time on remediation and rework. Trusted by more than 15 million developers, sonatype helps power secure, modern software development at nearly 2,000 global organizations including 70% of the fortune 100. To learn more about sonatype, please visit www.sonatype.com.

INACTIVE