2 months ago
Hyderābād, IndiaStaff+
Responsibilities
- Identify and prioritize security risks across code, services, infrastructure, build pipelines, and software supply chain components.
- Validate findings for exploitability, severity, affected products, business impact, and remediation priority.
- Collaborate with Security Research, Product, Application Security, and Engineering teams on findings, product improvements, detections, and remediation.
- Create remediation guidance, engineering-ready fix proposals, pull requests, secure coding standards, detection logic, and remediation playbooks.
- Use AI-assisted engineering, security analysis, and automation techniques to improve software quality and security outcomes.
Requirements
- 8+ years of professional software engineering experience, including 2+ years in a Staff Engineer or equivalent technical leadership role.
- Experience identifying, validating, and helping remediate vulnerabilities in production software, services, APIs, infrastructure, or software supply chain components.
- Ability to understand complex codebases, preferably including Java, Kotlin, or other JVM-based backend systems.
- Hands-on experience with application-security testing methods and tools, including SAST, DAST, SCA, secret scanning, threat modeling, secure code review, or vulnerability validation.
- Experience using AI-assisted engineering, security analysis, or automation techniques.
- Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent practical experience.
- Strong communication and collaboration skills across Application Security, Engineering, Product, or Security Research teams.
- Understanding of cloud-native architecture, CI/CD workflows, build pipelines, containers, and modern DevOps practices is preferred.
- Relevant security certifications such as GSEC, GCIH, GCLD, GCID, GMON, CISSP, CC, SSCP, CCSP, CAP, or CSSL are preferred.
Benefits
- Company Wellness Week, during which company operations shut down for a week.
- Paid Volunteer Time Off.
- Parental leave.
- Diversity and inclusion working groups.
- Flexible working practices.
- Expansion of Sonatype’s India Innovation Hub in Hyderabad.
