Simplify Logo

Full-Time

Information Security Engineer

Devsecops

Posted on 6/27/2024

Sonatype

Sonatype

501-1,000 employees

Manages and secures open-source software usage

Consulting
Enterprise Software
Cybersecurity
AI & Machine Learning

Mid

Remote in USA

Category
Cybersecurity
IT & Security
Required Skills
Development Operations (DevOps)
Requirements
  • 3+ years of Software development experience or security related engineering
  • 3+ years Development Operations (DevOps) experience
  • 3+ years of Incident management/handling and response methods/escalation
  • 3+ years Vulnerability management & scanning tools
  • Common security frameworks and protection methods
  • Technical risk assessment methods
  • DevSecOps processes
  • Cloud and infrastructure security
  • Be conversant in web application security, ex: OWASP top 10
  • Be familiar with the principles of security architecture
  • Have experience with SAST, DAST, SCA, or related security testing frameworks/tools
  • Have experience with threat modeling frameworks and related industry tools
  • Have performed security reviews of architecture, source code, infrastructure, and/or SDLC processes
  • Have deployed vulnerability scans, either automated or custom
  • Hold any of the following SANS Certifications: GSEC, GCIH, GCLD, GCID, GMON
  • Hold any (ISC)² Certifications such as: CISSP, CC, SSCP, CCSP, CAP, CSSLP
Responsibilities
  • Perform vulnerability scans, review output, provide initial analysis and remediation
  • Perform information security incident response and issue resolution as needed
  • Protect digital assets from unauthorized access, mitigate risks before a data breach occurs and provide security to ensure critical information is thoroughly protected
  • Implement, configure and upgrade security tools and systems
  • Evaluate, integrate and configure security tooling
  • Collaborate with technical teams, product managers and third parties
  • Respond to cyber security alerts from a variety of systems throughout the enterprise
  • Security event handling including InfoSec tickets, investigating log alerts & other security events via supervising tools, event to incident conversion, etc.
  • Perform technical risk assessments for software, products & services used anywhere inside Sonatype (OEMs, tools, algorithms, libraries etc.)
  • Identify flaws within the organization's infrastructure and make risk-based recommendations

Sonatype helps organizations manage and secure their use of open-source software, which is software that anyone can inspect and modify. Their main product, the Nexus Platform, automates DevOps processes and governs the usage of open-source software. This platform supports practices that combine software development and IT operations to speed up the development lifecycle and ensure high-quality software delivery. Sonatype serves a variety of clients, including IT leaders and developers across different industries, such as healthcare. Unlike many competitors, Sonatype offers both free and paid versions of their products, allowing users to manage software components effectively. Their goal is to provide tools that enhance software security and efficiency in development, generating revenue through subscriptions to their advanced features.

Company Stage

Series A

Total Funding

$171.3M

Headquarters

Fulton, Missouri

Founded

2008

Simplify Jobs

Simplify's Take

What believers are saying

  • The launch of Sonatype Learn demonstrates the company's commitment to continuous education and skill development for its users.
  • Sonatype's partnerships with global policymakers and enterprises for SBOM management highlight its leadership in software supply chain security.
  • The introduction of AI/ML component detection in Sonatype Lifecycle enhances the platform's ability to identify and mitigate risks, making it a cutting-edge tool in the market.

What critics are saying

  • The rapidly evolving landscape of software security requires constant innovation, which could strain Sonatype's resources and focus.
  • The increasing number of software supply chain attacks may outpace Sonatype's ability to provide timely solutions, potentially impacting client trust.

What makes Sonatype unique

  • Sonatype's Nexus Platform uniquely integrates open-source governance with DevOps automation, setting it apart from competitors who may focus on only one aspect.
  • Their SBOM Manager is an industry-first solution that turns static inventory lists into actionable assets, providing unparalleled security and efficiency in software supply chains.
  • Sonatype's AI/ML component detection capabilities offer advanced security defect identification, a feature not commonly found in other open-source management tools.

Benefits

Distributed Workforce - Walls don’t make a company great, people do — and we have the best. While we have offices in the US in Maryland and Virginia, and also in London and Sydney, our growing and talented team lives and works anywhere and everywhere.

Mission Driven - We’re helping software developers harness the power of open source, while making software safer. What does that mean for you? An opportunity to join a smart, mission-oriented team that is changing how software is made.

Competitive Salary & Benefits - We believe in taking care of our team. That means more than just interesting work — it's great benefits, competitive compensation packages, flexible schedules, and an endless opportunity to learn and grow.

Open, Transparent, Diverse - Our varied experiences, locations, ethnicities, genders, and sexual orientations, make us a better company. That's why we're committed to bringing different backgrounds and perspectives into our organization.

INACTIVE