Sonatype

Senior DevOps Engineer

Colombia

Not SpecifiedCompensation
Senior (5 to 8 years)Experience Level
Full TimeJob Type
UnknownVisa
Cybersecurity, Software Development, DevOpsIndustries

Job Description

Employment Type: Full-Time

Position Overview

Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining proactive protection against malicious open source, enterprise-grade SBOM management, and the leading open-source dependency management platform. This empowers enterprises to create and maintain secure, quality, and innovative software at scale. As founders of Nexus Repository and stewards of Maven Central, the world’s largest repository of Java open-source software, we are software pioneers with unmatched open-source expertise. We empower innovation with an unparalleled commitment to build faster, safer software and harness AI and data intelligence to mitigate risk, maximize efficiencies, and drive powerful software development. More than 2,000 organizations, including 70% of the Fortune 100 and 15 million software developers, rely on Sonatype to optimize their software supply chains.

We are looking for team members who want to help us change the way the world innovates through software. The Sonatype team has already done this through its contributions to the Maven build system, the Nexus Repository Manager and Nexus Lifecycle, and most recently with Sonatype SBOM manager – literally changing the way the world creates and delivers software across thousands of organizations and millions of developers. That was just the beginning. We need your help so that we can do it again. If you are interested in delivering value across nearly every decision made in the world of software development, to help companies create better and safer software faster, to transform innovation through software, read on.

Who You Are and What You'll Do

You are an engineer with 4+ years of experience running high availability systems and supporting infrastructure in customer-facing production environments. You are motivated by the opportunity to define repeatable practices for service delivery via modular, reusable automation and a developer platform that enables self-service delivery of services. You will also participate in the governance controls that reduce risk and promote standardization across the organization.

You will be a member of the Sonatype Developer Experience team, which has a wide range of responsibilities to drive service delivery excellence for Sonatype products and services that are customer-facing and customer-adjacent. You will refine a set of high-level enablement practices – for instance, design review, service launch coordination, production readiness assessment, service level objective definition/review, incident management, and cost awareness – to support delivery teams at various phases of their service lifecycle and maturity. You will collaborate closely with Sonatype delivery teams to define product-specific metrics and remediations through system analysis, testing, and fault troubleshooting.

What You Need

  • Proficiency with a high-level programming language (e.g., Python, Go), bash scripting, and Linux.
  • Proficiency in modern technical operating practices.
  • System architecture & design experience.
  • Continuous integration / continuous delivery (Jenkins, FluxCD, and GitHub Actions).
  • Infrastructure as Code (Terraform).
  • Cloud services (AWS) and Kubernetes.
  • SRE principles & practices.
  • Experience with specific AWS offerings, including many of: ECS/EKS/ECR, EC2, S3, RDS, VPCs, IAM Policy Docs, Policies, Roles, and Instance Profiles, Cloudwatch Logs.
  • Docker Containers and orchestration (ECS, EKS).
  • Terraform and the use of Terraform modules.
  • Kubernetes cluster concepts and design.
  • Experience improving service observability: monitoring agents, metrics, logging, and dashboards. Knowledge of OpenTelemetry and Prometheus and observability platforms similar to DataDog, Splunk, Dynatrace, or Observe.
  • Comfortable participating in an on-call rotation with teammates to respond and triage production issue escalations during off-hours.

Skills

High-availability systems
Infrastructure support
Production environment management
DevOps practices
Automation
Cloud platforms

Sonatype

Manages and secures open-source software usage

About Sonatype

Sonatype helps organizations manage and secure their use of open-source software, which is software that anyone can inspect and modify. Their main product, the Nexus Platform, automates DevOps processes and governs the usage of open-source software. This platform supports practices that combine software development and IT operations to speed up the development lifecycle and ensure high-quality software delivery. Sonatype serves a variety of clients, including IT leaders and developers across different industries, such as healthcare. Unlike many competitors, Sonatype offers both free and paid versions of their products, allowing users to manage software components effectively. Their goal is to provide tools that enhance software security and efficiency in development, generating revenue through subscriptions to their advanced features.

Fulton, MissouriHeadquarters
2008Year Founded
$150.5MTotal Funding
GROWTH_EQUITY_VCCompany Stage
Enterprise Software, CybersecurityIndustries
501-1,000Employees

Benefits

Distributed Workforce - Walls don’t make a company great, people do — and we have the best. While we have offices in the US in Maryland and Virginia, and also in London and Sydney, our growing and talented team lives and works anywhere and everywhere.
Mission Driven - We’re helping software developers harness the power of open source, while making software safer. What does that mean for you? An opportunity to join a smart, mission-oriented team that is changing how software is made.
Competitive Salary & Benefits - We believe in taking care of our team. That means more than just interesting work — it's great benefits, competitive compensation packages, flexible schedules, and an endless opportunity to learn and grow.
Open, Transparent, Diverse - Our varied experiences, locations, ethnicities, genders, and sexual orientations, make us a better company. That's why we're committed to bringing different backgrounds and perspectives into our organization.

Risks

Complex software supply chains pose challenges, with only 7% reviewing their risks.
Fixing critical vulnerabilities can take over 500 days, exposing clients to risks.
Partnership with Equifax may risk reputation if security improvements are not achieved.

Differentiation

Sonatype offers a full-spectrum software supply chain management platform.
The Nexus Platform automates DevOps processes and governs open-source software usage.
Sonatype's solutions are trusted by 15 million developers globally.

Upsides

Partnership with OpenText enhances vulnerability management for open-source and custom code.
Availability in AWS Marketplace expands customer base and streamlines platform management.
Recognition as a leader in Software Composition Analysis boosts credibility and client attraction.

Land your dream remote job 3x faster with AI