Information Security Engineer (DevSecOps)

Sonatype · Remote

Company

Sonatype

Location

Remote

Type

Full Time

Job Description

Sonatype is the software supply chain management company. We're on a mission to change how the world innovates by making software development easier. From running the world's largest repository of Java open-source components (Maven Central) to inventing componentized software development and then software supply chain management to creating the only solution that stops malicious open-source malware in its tracks, we're constantly leading the industry while helping thousands of customers manage open source every day.


Already used by 15 million developers, we have lofty goals for our technology to be in the hands of every engineering team. And we need you to do that. Join us!


Learn more at www.sonatype.com.


https://www.sonatype.com/privacy-policy



The Information Security Engineer will secure the technical and operational aspects of Information Security for the organization, products and services; this person is essential to ensuring the ongoing protection of Sonatype’s critical role in the software supply chain. The role requires a solid understanding of Cloud security and experience with industry standard secure software development practices in order to contribute to the safe operation of cloud native solutions. This includes supervising and vulnerability management practices, incident response, reporting, and guide security improvements. As part of the Information Security team, you will be an Information Security partner and collaborate with technical teams and third-party vendors to integrate security controls and compliance proofing into our products, platforms, and processes. 

Primary job duties:

  • Perform vulnerability scans, review output, provide initial analysis and remediation
  • Perform information security incident response and issue resolution as needed
  • Protect digital assets from unauthorized access, mitigate risks before a data breach occurs and provide security to ensure critical information is thoroughly protected
  • Implement, configure and upgrade security tools and systems
  • Evaluate, integrate and configure security tooling
  • Collaborate with technical teams, product managers and third parties
  • Respond to cyber security alerts from a variety of systems throughout the enterprise.
  • Security event handling including InfoSec tickets, investigating log alerts & other security events via supervising tools, event to incident conversion, etc.
  • Perform technical risk assessments for software, products & services used anywhere inside Sonatype (OEMs, tools, algorithms, libraries etc.)
  • Identify flaws within the organization's infrastructure and make risk-based recommendations.

We are looking for consistent track record within the following areas:

  • 3 + years of Software development experience or security related engineering
  • 3 + years Development Operations (DevOps) experience
  • 3 + years of Incident management/handling and response methods/escalation
  • 3+ years Vulnerability management & scanning tools
  • Common security frameworks and protection methods
  • Technical risk assessment methods
  • DevSecOps processes
  • Cloud and infrastructure security

Additional skills of interest to us:

  • Be conversant in web application security, ex: OWASP top 10
  • Be familiar with the principles of security architecture
  • Have experience with SAST, DAST, SCA, or related security testing frameworks/tools
  • Have experience with threat modeling frameworks and related industry tools
  • Have performed security reviews of architecture, source code, infrastructure, and/or SDLC processes
  • Have deployed vulnerability scans, either automated or custom.
  • Hold any of the following SANS Certifications: GSEC, GCIH, GCLD, GCID, GMON
  • Hold any (ISC)² Certifications such as: CISSP, CC, SSCP, CCSP, CAP, CSSLP

Things that we are proud of:

  • 2023 Forrester Leader in SCA
  • #1 ranked SCA
  • 2022 Frost & Sullivan Technology Innovation Leader Award: Sonatype earned Frost & Sullivan’s 2022 Global Technology Innovation Leadership Award in Development and Operations (DevOps) Security.
  • NVTC 2022 Cyber Company of the Year: Sonatype was named Commercial Cyber Company of the Year and a Capital Cyber Award-winner by the Northern Virginia Technology Council (NVTC)
  • 2022 Annual Peer Award: Sonatype’s Nexus Lifecycle won a PeerSpot Silver Peer Award as a leading Enterprise Technology solution in the Software Composition Analysis category.
  • 2022 Best in Biz Award: Sonatype CEO Wayne Jackson was recognized as a Silver Winner in the Best in Biz Awards' Executive of the Year category.
  • Tech Ascension Awards: Sonatype was named the Best DevOps Security Solution for Nexus Lifecycle and Nexus Firewall (Software Composition Analysis).
  • BuiltIn Best Places to Work: Sonatype was named to the Washington DC 100 Best Places to Work list and Washington DC Best Midsize Places to Work list.
  • Company Wellness Week - We shut down company operations for a week to enable all employees to spend time pursuing personal growth and enjoying much needed and deserved rest.
  • Diversity & Inclusion Working Groups
  • Parental Leave Policy
  • Paid Volunteer Time Off (VTO)

#LI-Remote

LI-BS1


At Sonatype, we value diversity and inclusivity. We offer perks such as parental leave, diversity and inclusion working groups, and flexible working practices to allow our employees to show up as their whole selves. We are an equal-opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you have a disability or special need that requires accommodation, please do not hesitate to let us know.



#LI-Remote

Apply Now

Date Posted

07/08/2024

Views

5

Back to Job Listings Add To Job List Company Profile View Company Reviews
Positive
Subjectivity Score: 0.8

Similar Jobs

Senior Product Designer - Org & Security - Typeform

Views in the last 30 days - 0

This job description outlines a role in developing an intelligent contact management system with AI capabilities The position involves designing user ...

View Details

Software Engineer Networking Software and Services - xAI

Views in the last 30 days - 0

The text describes xAIs mission to develop AI systems for understanding the universe and advancing human knowledge It outlines a role involving networ...

View Details

Associate Technical Support Engineer - Recharge

Views in the last 30 days - 0

Recharge is a subscription platform for innovative brands offering customer retention solutions They seek Technical Support roles with 247 coverage em...

View Details

Full Stack Product Engineer - Jiga

Views in the last 30 days - 0

Jiga is a remotefriendly company focused on empowering engineers with trust autonomy and flexibility They emphasize simplicity ownership and impactful...

View Details

Senior Design Manager (Infrastructure) - Canonical

Views in the last 30 days - 0

Canonical a leading opensource provider seeks a Senior Design Manager to drive innovation in cloud and AI technologies The role offers remote work glo...

View Details

Executive Director Patient Advocacy - Kyverna Therapeutics

Views in the last 30 days - 0

Kyverna Therapeutics is seeking an Executive Director for Patient Advocacy to lead initiatives in autoimmune disease treatment The role involves build...

View Details