Security Researcher

at Sonatype
🇨🇴 Colombia - Remote
🔒 Cybersecurity🔵 Mid-level

Job description

Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only enterprise grade SBOM management and the leading open source dependency management platform. This empowers enterprises to create and maintain secure, quality, and innovative software at scale.

As founders of Nexus Repository and stewards of Maven Central, the world’s largest repository of Java open-source software, we are software pioneers and our open source expertise is unmatched. We empower innovation with an unparalleled commitment to build faster, safer software and harness AI and data intelligence to mitigate risk, maximize efficiencies, and drive powerful software development.

More than 2,000 organizations, including 70% of the Fortune 100 and 15 million software developers, rely on Sonatype to optimize their software supply chains.

Sonatype’s mission is to enable organizations to better manage their software supply chain.  We offer a series of products and services including the Sonatype Nexus Repository and Sonatype Lifecycle.

**This position is 100% remote and candidates must currently live in Colombia**

The Security Researcher will investigate and analyze vulnerabilities in open-source software.

Sonatype is looking for a passionate, driven and talented Security Researcher to provide high quality security data from researching software vulnerabilities.  This high-quality security data ensures that our customers are getting maximum value out of our products making them feel like they are part of the Sonatype family.  If you are a positive-thinker and problem-solver and believe that customer success and company success go hand-in-hand, this is a great job for you.  This position will provide a valuable learning opportunity with great potential to grow your newly started career in cyber-security.  Enjoy your job as you work in a fast-paced, flexible, and fun environment, with talented, diverse, and forward-thinking individuals.

What you’ll do:

  • Review, isolate, analyze, and reverse engineer vulnerabilities in open-source software
  • Document attack capabilities
  • Provide detection and remediation guidance
  • Aid in ideas and prototypes for new tooling
  • Collaborate with other team members toward shared product goals
  • Improve Sonatype products by providing valuable security data
  • Work with technology and business team members to define and refine requirements in an agile development environment

What you bring:

  • Bachelor of Science Degree in Computer Science, Cybersecurity, Engineering, or related field.
  • 2+ years of experience in software development or application security
  • Knowledge of Java, C#, or JavaScript
  • Knowledge of application security such as the OWASP Top 10 or Sans 25
  • Excellent oral and written communication skills
  • Excellent organizational skills and detail oriented
  • Ability to work independently and as part of a team

It’d be great if you also had:

  • Knowledge of different languages such as Python, Ruby, and scripting is a plus
  • Knowledge of different operating systems such as *NIX, Windows is a plus
  • Application vulnerability assessment or penetration testing experience is a plus
  • Knowledge of open source environments like GitHub is a plus

Things that we are proud of

  • 2025 AI Compliance Solution of the Year - AI Breakthrough Awards
  • 2025 DEVIES Award to our SBOM Manager new product for its innovation and impact in developer technology
  • 2024 Industry Leader in Forrester-Wave for Software Composition Analysis (2024 Q4 report)
  • 2023 Fast Company Best Places for Innovators
  • 2023 Gartner’s Magic Quadrant
  • 2023 Software Report’s Top 100 Software Companies
  • 2023 BuiltIn Best Places to Work
  • 2022 Frost & Sullivan Technology Innovation Leader Award
  • 2022 PeerSpot Silver Peer Award in Software Composition Analysis
  • 2022 Tech Ascension Best DevOps Security Solution Award
  • 2022 NVCT Cyber Company of the Year
  • Company Wellness Week - We shut down company operations for a week to enable all employees to pursue personal growth and enjoy a much-needed and deserved rest.
  • Paid Volunteer Time Off (VTO)

We are Sonatype, and we have assembled a world class team of employees, investors, and partners. We are proud to be recognized as a Deloitte Technology Fast 500 company for 2016. With more than 120,000 installations and counting, Nexus products are helping modern development organizations intelligently source, manage, assemble, and maintain open source and third-party components, so they can improve the quality, security, and speed of their software supply chains.

We are curious and constantly innovating without fear of failure. We are attacking a huge and emerging market and seeking remarkably talented individuals to join us on our journey.

Sonatype is proud to be an equal opportunity workplace and an affirmative action employer that is committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. If you have a disability or special need that requires accommodation, please do not hesitate to let us know.

At Sonatype, we value diversity and inclusivity. We offer perks such as parental leave, diversity and inclusion working groups, and flexible working practices to allow our employees to show up as their whole selves. We are an equal-opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you have a disability or special need that requires accommodation, please do not hesitate to let us know.

Share this job:
Please let Sonatype know you found this job on Remote First Jobs 🙏

Similar Remote Jobs

Benefits of using Remote First Jobs

Discover Hidden Jobs

Unique jobs you won't find on other job boards.

Advanced Filters

Filter by category, benefits, seniority, and more.

Priority Job Alerts

Get timely alerts for new job openings every day.

Manage Your Job Hunt

Save jobs you like and keep a simple list of your applications.

Search remote, work from home, 100% online jobs

We help you connect with top remote-first companies.

Search jobs

Hiring remote talent? Post a job

Frequently Asked Questions

What makes Remote First Jobs different from other job boards?

Unlike other job boards that only show jobs from companies that pay to post, we actively scan over 20,000 companies to find remote positions. This means you get access to thousands more jobs, including ones from companies that don't typically post on traditional job boards. Our platform is dedicated to fully remote positions, focusing on companies that have adopted remote work as their standard practice.

How often are new jobs added?

New jobs are constantly being added as our system checks company websites every day. We process thousands of jobs daily to ensure you have access to the most up-to-date remote job listings. Our algorithms scan over 20,000 different sources daily, adding jobs to the board the moment they appear.

Can I trust the job listings on Remote First Jobs?

Yes! We verify all job listings and companies to ensure they're legitimate. Our system automatically filters out spam, junk, and fake jobs to ensure you only see real remote opportunities.

Can I suggest companies to be added to your search?

Yes! We're always looking to expand our listings and appreciate suggestions from our community. If you know of companies offering remote positions that should be included in our search, please let us know. We actively work to increase our coverage of remote job opportunities.

How do I apply for jobs?

When you find a job you're interested in, simply click the 'Apply Now' button on the job listing. This will take you directly to the company's application page. We kindly ask you to mention that you found the position through Remote First Jobs when applying, as it helps us grow and improve our service 🙏

Apply