[Remote] Senior Product Manager at Sonatype

Colombia

Sonatype Logo
Not SpecifiedCompensation
Senior (5 to 8 years)Experience Level
Full TimeJob Type
UnknownVisa
Software Security, Cybersecurity, TechnologyIndustries

Requirements

  • Proven track record of leading product strategy and delivery for complex SaaS or developer-facing platforms
  • Experience working with technical domains such as application security, DevSecOps, or developer tooling
  • Strong analytical skills, with the ability to balance customer insight, business value, and technical feasibility
  • Excellent communication and collaboration skills — ability to rally teams around a shared vision and deliver results
  • Passion for improving how software is built, secured, and delivered

Responsibilities

  • Lead product strategy and execution for a core part of Sonatype’s software supply chain security portfolio
  • Define and deliver capabilities that help organizations identify and prevent open source malware and supply chain attacks before they impact production
  • Partner closely with engineering, data science, and design teams to translate vision into impactful, customer-focused outcomes
  • Collaborate with customers, field teams, and industry experts to deeply understand developer workflows and the evolving threat landscape
  • Shape the roadmap to improve how developers discover, evaluate, and secure open source components at scale
  • Use data and customer feedback to make informed decisions that drive product adoption, user satisfaction, and measurable security outcomes

Skills

Product Management
Product Strategy
Software Supply Chain Security
Open Source Security
SBOM Management
Malware Detection
Supply Chain Attacks
Developer Workflows
Roadmap Planning
Engineering Collaboration
Data Science
Customer Collaboration

Sonatype

Manages and secures open-source software usage

About Sonatype

Sonatype helps organizations manage and secure their use of open-source software, which is software that anyone can inspect and modify. Their main product, the Nexus Platform, automates DevOps processes and governs the usage of open-source software. This platform supports practices that combine software development and IT operations to speed up the development lifecycle and ensure high-quality software delivery. Sonatype serves a variety of clients, including IT leaders and developers across different industries, such as healthcare. Unlike many competitors, Sonatype offers both free and paid versions of their products, allowing users to manage software components effectively. Their goal is to provide tools that enhance software security and efficiency in development, generating revenue through subscriptions to their advanced features.

Fulton, MissouriHeadquarters
2008Year Founded
$150.5MTotal Funding
GROWTH_EQUITY_VCCompany Stage
Enterprise Software, CybersecurityIndustries
501-1,000Employees

Benefits

Distributed Workforce - Walls don’t make a company great, people do — and we have the best. While we have offices in the US in Maryland and Virginia, and also in London and Sydney, our growing and talented team lives and works anywhere and everywhere.
Mission Driven - We’re helping software developers harness the power of open source, while making software safer. What does that mean for you? An opportunity to join a smart, mission-oriented team that is changing how software is made.
Competitive Salary & Benefits - We believe in taking care of our team. That means more than just interesting work — it's great benefits, competitive compensation packages, flexible schedules, and an endless opportunity to learn and grow.
Open, Transparent, Diverse - Our varied experiences, locations, ethnicities, genders, and sexual orientations, make us a better company. That's why we're committed to bringing different backgrounds and perspectives into our organization.

Risks

Complex software supply chains pose challenges, with only 7% reviewing their risks.
Fixing critical vulnerabilities can take over 500 days, exposing clients to risks.
Partnership with Equifax may risk reputation if security improvements are not achieved.

Differentiation

Sonatype offers a full-spectrum software supply chain management platform.
The Nexus Platform automates DevOps processes and governs open-source software usage.
Sonatype's solutions are trusted by 15 million developers globally.

Upsides

Partnership with OpenText enhances vulnerability management for open-source and custom code.
Availability in AWS Marketplace expands customer base and streamlines platform management.
Recognition as a leader in Software Composition Analysis boosts credibility and client attraction.

Land your dream remote job 3x faster with AI