Staff Software Engineer

🏒 Sonatype · all Sonatype jobs
πŸ“ Canada
πŸ“… Posted 2026-08-19 Β· via Himalayas
🏷 Software-Engineer,Data-Engineering,Data-Platform-Engineering,Software-Supply-Chain-Security,Engineering-R&D,Staff-Software-Developer,Staff-Software-Engineering
Apply on original site β†—

Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only enterprise grade SBOM management and the leading open source dependency management platform. This empowers enterprises to create and maintain secure, quality, and innovative software at scale.

As founders of Nexus Repository and stewards of Maven Central , the world’s largest repository of Java open-source software, we are software pioneers and our open source expertise is unmatched. We empower innovation with an unparalleled commitment to build faster, safer software and harness AI and data intelligence to mitigate risk, maximize efficiencies, and drive powerful software development.

More than 2,000 organizations, including 70% of the Fortune 100 and 15 million software developers, rely on Sonatype to optimize their software supply chains.

What you'll do:

As a Staff Software Engineer on Data Identity, you'll set technical direction for the team's next generation. You'll be the senior technical voice on the team, partnering with the team lead and product on multi-quarter architectural bets, and the person other Staff engineers reach for when questions about package identity, coordinate modeling, or upstream data contracts land on their desk.

This is a high-leverage seat. Data Identity is small β€” about five engineers β€” but the blast radius of our decisions is wide.

Key Responsibilities:

-
Own the identity data model. Coordinate schemas, cross-ecosystem mapping, name-based implications, deduplication, and re-discovery are the recurring technical themes of this team. You'll set direction on how they evolve.

-
Architect the streaming and batch pipelines. Our stack sits on Java, Spark/EMR, HBase, Databricks , and AWS data primitives. You'll drive migrations, cost and reliability improvements, and the underlying infrastructure choices.

-
Design the data contracts that downstream teams consume. Schema stability, versioning, and rollout are as much of the job as the pipeline internals β€” because breaking a contract means breaking a downstream product.

-
Lead commercial vendor ingestion. Data Identity is Sonatype 's front door for third-party SBOM feeds (CycloneDX, VEX, SPDX). You'll represent us in technical conversations with vendor engineering teams, negotiate spec, and translate what they can produce into what our platform can consume.

-
Apply AI where it earns its place in the data. We have real work in identity re-discovery, package deduplication, and data-quality signals where AI/ML techniques should be explored further to measure how viable it may be. This is AI applied to the data itself, not AI as developer tooling.

-
Work with AI-assisted engineering tools every day. Claude and equivalent tools are standard equipment on this team β€” for coding, code review, investigation, and data exploration. You're expected to use them well and keep growing your fluency with them as the tooling evolves.

-
Raise the reliability floor. Alarm triage, SLO discipline, cost management (compute isn't cheap at our scale), and incident-response leadership are part of the seat.

What you bring:

We're seeking an experienced engineer who thrives in an agile, collaborative environment and enjoys tackling technical challenges at architectural scale.

-
10+ years of professional software engineering experience , including 3+ years at Staff level or with equivalent scope: setting technical direction for a team, owning a system end-to-end across multiple release cycles, and influencing peer teams without direct authority.

-
Deep experience with data-platform engineering at scale. Streaming and batch pipelines, distributed storage, and the operational realities of running them in production. Spark, HBase, Databricks, or comparable systems.

-
Strong Java proficiency , or a systems-programming background that w

← All remote jobs