Associate Security Researcher

hace 2 semanas


Desde casa, Colombia Sonatype A tiempo completo

Sonatype is the software supply chain management company. We're on a mission to change how the world innovates by making software development easier. From running the world's largest repository of Java open-source components (Maven Central) to inventing componentized software development and then software supply chain management to creating the only solution that stops malicious open-source malware in its tracks, we're constantly leading the industry while helping thousands of customers manage open source every day.

Already used by 15 million developers, we have lofty goals for our technology to be in the hands of every engineering team. And we need you to do that. Join us

Sonatype’s mission is to enable organizations to better manage their software supply chain. We offer a series of products and services including the Sonatype Nexus Repository and Sonatype Lifecycle.

The Security Researcher will investigate and analyze vulnerabilities in open-source software.

Sonatype is looking for a passionate, driven and talented Security Researcher to provide high quality security data from researching software vulnerabilities. This high-quality security data ensures that our customers are getting maximum value out of our products making them feel like they are part of the Sonatype family. If you are a positive-thinker and problem-solver and believe that customer success and company success go hand-in-hand, this is a great job for you. This position will provide a valuable learning opportunity with great potential to grow your newly started career in cyber-security. Enjoy your job as you work in a fast-paced, flexible, and fun environment, with talented, diverse, and forward-thinking individuals.

**Responsibilities**:

- Review, isolate, analyze, and reverse engineer vulnerabilities in open-source software.
- Document attack capabilities.
- Provide detection and remediation guidance.
- Aid in ideas and prototypes for new tooling.
- Collaborate with other team members toward shared product goals.
- Improve Sonatype products by providing valuable security data.
- Work with technology and business team members to define and refine requirements in an agile development environment

**Required Qualifications**:

- Bachelor of Science Degree in Computer Science, Cybersecurity, Engineering, or related field; or at least 4 years of related work experience in lieu of a degree
- Basic knowledge of Java, C#, or JavaScript.

**Desired Qualifications**:

- Excellent oral and written communication skills.
- Excellent organizational skills and detail oriented.
- Ability to work independently and as part of a team

We support our remote employee experience. While we have offices in Fulton MD, Tyson's Corner VA, London UK, and Sydney AUS, we are remote first and always have been. We use a number of communication tools to connect across the company, keep information flowing day to day, and meet face-to-face on a targeted basis at organization and team meetups.

Thousands of organizations and millions of developers use our software. If you have a passion for improving how the world develops software, Sonatype is the right place for you.

At Sonatype, we value diversity and inclusivity. We offer perks such as parental leave, diversity and inclusion working groups, and flexible working practices to allow our employees to show up as their whole selves. We are an equal-opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you have a disability or special need that requires accommodation, please do not hesitate to let us know.

LI-Remote



  • Desde casa, Colombia Red Hat Software A tiempo completo

    About the job: The Red Hat Global Support Services team is adding an Associate Technical Support Engineer with a background in Linux system administration to join us remotely in Colombia. In this role, you will deliver an outstanding customer support experience by providing technical support and sustaining engineering services to enterprise subscription...


  • Desde casa, Colombia Sonatype A tiempo completo

    Sonatype is the software supply chain management company. We're on a mission to change how the world innovates by making software development easier. From running the world's largest repository of Java open-source components (Maven Central) to inventing componentized software development and then software supply chain management to creating the only solution...

  • Risk Analyst Ii

    hace 3 días


    Desde casa, Colombia CSG A tiempo completo

    Hi, I'm Laura Pérez, your Recruiter and guide to joining CSG. At CSG, you're more than your resume. We want your diverse perspective and unique background to help us enrich the work we do together. We believe that by channeling the power of all, we make ordinary customer and employee experiences extraordinary. Channel the power of YOU and begin the...