Staff Info Sec AI Researcher
Core
Shape a high-impact security engineering capability at the intersection of frontier AI, offensive application security, and software supply chain defense by using advanced AI models to discover, validate, and remediate risks across products, codebases, and infrastructure.
Role type
Staff IC security engineer (AI Red Team)
Builds
Security tooling, AI-SDLC patterns, detection logic, and remediation playbooks for Sonatype's software supply chain products
Domain
Software supply chain security, application security, AI/ML
Deliverable
production ML models | product features | dashboards & analysis
Required skills
software engineering, vulnerability identification and validation, complex codebase analysis (Java/Kotlin/JVM), application security testing (SAST/DAST/SCA), AI-assisted engineering, risk prioritization
Preferred skills
AI model development, offensive security techniques, secure coding standards
Technologies
Java, Kotlin, JVM, SAST, DAST, SCA, secret scanning
Responsibilities
Identify and prioritize security risks across code, services, infrastructure, and supply chain components; validate findings for exploitability and business impact; collaborate to translate findings into product improvements and detection opportunities; champion modern AI-SDLC practices by creating reusable guidance and playbooks; create engineering-ready fix proposals and pull requests
Seniority
Staff, hands-on IC with technical leadership