Jobs and Careers
SO
Information Security Engineer (DevSecOps)
SonatypeUnited States - Remote, United StatesRemotefull_timeVerifiedPosted 13 Jun 2024
About the role
Sonatype is the software supply chain management company. We're on a mission to change how the world innovates by making enterprise software development with open source and AI/ML easier and more secure. Sonatype created the software supply chain management category, is a pioneer in the open source community, and has a leadership position in the DevSecOps industry.
From running the world's largest repository of Java open source components (Maven Central), to inventing modern artifact management with Nexus Repository, and to introducing the world’s only solution that stops malicious open-source malware in its tracks, we're constantly innovating and serving thousands of organizations and over 15 million developers around the world.
We have lofty goals for our technology and intelligence to power all software engineering and security teams. And, we need you to do that.Join us!
Learn more at www.sonatype.com.
The Information Security Engineer will secure the technical and operational aspects of Information Security for the organization, products and services; this person is essential to ensuring the ongoing protection of Sonatype’s critical role in the software supply chain.
The role requires a solid understanding of Cloud security and experience with industry standard secure software development practices in order to contribute to the safe operation of cloud native solutions. This includes supervising and vulnerability management practices, incident response, reporting, and guide security improvements. As part of the Information Security team, you will be an Information Security partner and collaborate with technical teams and third-party vendors to integrate security controls and compliance proofing into our products, platforms, and processes.
From running the world's largest repository of Java open source components (Maven Central), to inventing modern artifact management with Nexus Repository, and to introducing the world’s only solution that stops malicious open-source malware in its tracks, we're constantly innovating and serving thousands of organizations and over 15 million developers around the world.
We have lofty goals for our technology and intelligence to power all software engineering and security teams. And, we need you to do that.Join us!
Learn more at www.sonatype.com.
The Information Security Engineer will secure the technical and operational aspects of Information Security for the organization, products and services; this person is essential to ensuring the ongoing protection of Sonatype’s critical role in the software supply chain.
The role requires a solid understanding of Cloud security and experience with industry standard secure software development practices in order to contribute to the safe operation of cloud native solutions. This includes supervising and vulnerability management practices, incident response, reporting, and guide security improvements. As part of the Information Security team, you will be an Information Security partner and collaborate with technical teams and third-party vendors to integrate security controls and compliance proofing into our products, platforms, and processes.
Primary job duties:
- Perform vulnerability scans, review output, provide initial analysis and remediation
- Perform information security incident response and issue resolution as needed
- Protect digital assets from unauthorized access, mitigate risks before a data breach occurs and provide security to ensure critical information is thoroughly protected
- Implement, configure and upgrade security tools and systems
- Evaluate, integrate and configure security tooling
- Collaborate with technical teams, product managers and third parties
- Respond to cyber security alerts from a variety of systems throughout the enterprise.
- Security event handling including InfoSec tickets, investigating log alerts & other security events via supervising tools, event to incident conversion, etc.
- Perform technical risk assessments for software, products & services used anywhere inside Sonatype (OEMs, tools, algorithms, libraries etc.)
- Identify flaws within the organization's infrastructure and make risk-based recommendations.
We are looking for consistent track record within the following areas:
- 3 + years of Software development experience or security related engineering
- 3 + years Development Operations (DevOps) experience
- 3 + years of Incident management/handling and response methods/escalation
- 3+ years Vulnerability management & scanning tools
- Common security frameworks and protection methods
- Technical risk assessment methods
- DevSecOps processes
- Cloud and infrastructure security
Additional skills of interest to us:
- Be conversant in web application security, ex: OWASP top 10
- Be familiar with the principles of security architecture
- Have experience with SAST, DAST, SCA, or related security testing frameworks/tools
- Have experience with threat modeling frameworks and related industry tools
- Have performed security reviews of architecture, source code, infrastructure, and/or SDLC processes
- Have deployed vulnerability scans, either automated or custom.
- Hold any of the following SANS Certifications: GSEC, GCIH, GCLD, GCID, GMON
- Hold any (ISC)² Certifications such as: CISSP, CC, SSCP, CCSP, CAP, CSSLP
Things that we are proud of:
- 2023 Forrester Leader in SCA
- #1 ranked SCA
- 2022 Frost & Sullivan Technology Innovation Leader Award: Sonatype earned Frost & Sullivan’s 2022 Global Technology Innovation Leadership Award in Development and Operations (DevOps) Security.
- NVTC 2022 Cyber Company of the Year: Sonatype was named Commercial Cyber Company of the Year and a Capital Cyber Award-winner by the Northern Virginia Technology Council (NVTC)
- 2022 Annual Peer Award: Sonatype’s Nexus Lifecycl
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
Senior Information Security Engineer
Wells Fargo
Westlake
Senior Engineer, Information Security
Cardinal Health
US-Nationwide-FIELD, United States
$182,385/yr
Public Information Officer (Communications & Customer Experience [CCX] Dept.) (Non-Civil Service)
City of Dallas
1500 MARILLA, United States
$70,583/yr