Staff Info Sec AI Researcher

Sonatype
Hyderabad
Workplace: OnsiteFull timeFunction: Research & Scientific (R&D)Experience: 8+ yearsEducation: bachelorsSkills: ["Agile collaboration","Communication","Risk prioritization","Engineering collaboration"]

Use frontier AI and security tooling to discover, validate, and help remediate meaningful risks across codebases, products, infrastructure, and the software supply chain. Identify and prioritize high-impact vulnerabilities, assess exploitability and business impact, and collaborate with security research, product, application security, and engineering to turn findings into reusable AI-SDLC patterns, remediation guidance, and engineering-ready fix proposals.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Sonatype
Sonatype
2 months ago

Staff Info Sec AI Researcher

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 5 hours agoStatus: Live

Job Summary

Use frontier AI and security tooling to discover, validate, and help remediate meaningful risks across codebases, products, infrastructure, and the software supply chain. Identify and prioritize high-impact vulnerabilities, assess exploitability and business impact, and collaborate with security research, product, application security, and engineering to turn findings into reusable AI-SDLC patterns, remediation guidance, and engineering-ready fix proposals.
Location: Hyderabad
Workplace: Onsite
Employment Type: Full time
Job Function: Research & Scientific (R&D)
Seniority: Mid level

Key Responsibilities

  • •Identify and prioritize meaningful security risks across first-party code, services, infrastructure, build pipelines, and software supply chain components.
  • •Validate findings for exploitability, severity, affected products, business impact, and remediation priority.
  • •Collaborate with Security Research and Product to translate novel findings and emerging attack patterns into research-ready outputs and customer-facing intelligence.
  • •Work with Application Security and Engineering to move validated findings through remediation and reduce repeat vulnerability patterns.
  • •Champion AI-SDLC practices by translating vulnerability classes and remediation approaches into reusable guidance, detection logic, secure coding standards, and remediation playbooks; create fix proposals and pull requests where appropriate.

Pay and Benefits

Perks:Parental Leave

Key Requirements

  • •8+ years of professional software engineering experience, including 2+ years in a Staff Engineer or equivalent technical leadership role.
  • •Proven experience identifying, validating, and helping remediate vulnerabilities in production software, services, APIs, infrastructure, or software supply chain components.
  • •Strong ability to read, understand, and reason about complex codebases, preferably including Java, Kotlin, or other JVM-based backend systems.
  • •Hands-on application security testing experience with methods/tools such as SAST, DAST, SCA, secret scanning, threat modeling, secure code review, or vulnerability validation.
  • •Bachelor’s degree in Computer Science/Engineering (or equivalent practical experience).
Experience:8+ yearsDevSecOpsSoftware supply chain securityApplication securityOpen source security
Education:Bachelor's in Computer Science, Engineering
Skills:Agile collaborationCommunicationRisk prioritizationEngineering collaboration
Certifications:SANS GSECSANS GCIHSANS GCLDSANS GCIDSANS GMON(ISC)2 CISSP(ISC)2 CC(ISC)2 SSCP(ISC)2 CCSP(ISC)2 CAP(ISC)2 CSSL
Tech Stack:AIAI-SDLCSASTDASTSCASecret scanningThreat modelingSecure code reviewVulnerability validationCI/CDBuild pipelinesContainersDevOpsSBOMSoftware supply chainJavaKotlinJVM

Company Brief

Sonatype
Provides software supply chain automation and open-source governance solutions, including Nexus Repository, Nexus Lifecycle, and Nexus IQ, to help organizations manage, secure, and govern components across the software development lifecycle.
Industry: Cybersecurity
Company Size: Large (251 to 1,000 employees)
Growth: Established Company
Headquarters: Lexington, United States
Founded: 2008
WebsiteLinkedIn