Sonatype logo
Sonatype·

Staff Software Engineer - Sonatype

Fully remoteFull-timePrincipalUTC-6–-5NA#java#spark#awsParental leave

About Sonatype

Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining proactive protection against malicious open source, enterprise-grade SBOM management, and the leading open source dependency management platform.

As founders of Nexus Repository and stewards of Maven Central, the world’s largest repository of Java open-source software, we empower innovation with an unparalleled commitment to build faster, safer software and harness AI and data intelligence to mitigate risk.

What You'll Do

As a Staff Software Engineer on Data Identity, you'll set technical direction for the team's next generation. You'll be the senior technical voice on the team, partnering with the team lead and product on multi-quarter architectural bets, and serving as the go-to technical resource for package identity, coordinate modeling, and upstream data contracts.

Key Responsibilities

  • Own the identity data model: Drive coordinate schemas, cross-ecosystem mapping, name-based implications, deduplication, and re-discovery technical direction.
  • Architect streaming and batch pipelines: Lead migrations, reliability improvements, and infrastructure choices across our stack (Java, Spark/EMR, HBase, Databricks, AWS primitives).
  • Design downstream data contracts: Ensure schema stability, versioning, and seamless rollouts across dependent products.
  • Lead commercial vendor ingestion: Represent Sonatype in technical discussions with external vendors regarding third-party SBOM feeds (CycloneDX, VEX, SPDX).
  • Apply AI to data challenges: Explore AI/ML techniques for package deduplication, entity re-discovery, and data-quality signals.
  • Leverage AI-assisted engineering tools: Utilize Claude and modern AI developer tools daily for coding, code reviews, and investigations.
  • Raise the reliability floor: Drive alarm triage, SLO discipline, cost management, and incident response leadership.

What You Bring

  • 10+ years of professional software engineering experience, including 3+ years at Staff level or equivalent scope setting technical direction and owning systems end-to-end.
  • Deep experience with data-platform engineering at scale, including distributed storage, streaming/batch pipelines (Spark, HBase, Databricks, or comparable).
  • Strong Java proficiency or a robust systems-programming background.
  • Proven track record with cross-team data contracts, schema design, versioning, and backward compatibility.
  • AWS-native operating experience, including EMR, S3, SNS, and SQS with strong cost and performance optimization instincts.
  • Comfort with ambiguity and vendor-facing technical discussions.
  • Fluency with AI-assisted engineering tools (Claude or equivalent) in daily development workflows.
  • Sound architectural judgment on where AI/ML fits and does not fit in data pipelines.
  • Bachelor's degree in Computer Science, Engineering, or a related field, or equivalent practical experience.
  • Experience in agile environments collaborating with cross-functional teams.

Nice to Have

  • Deep knowledge of package ecosystems (Maven internals, npm, PyPI, Go modules, RPM/Debian).
  • Experience with SBOM standards like CycloneDX, VEX, or SPDX.
  • Background in entity resolution, deduplication, or record-linkage problems.
  • Open-source contributions in supply-chain or data-engineering projects.

Timezone overlap

UTC-6–-5

Open to

NA

Sign in to track applications and earn points.

More roles at Sonatype

Similar remote roles