Lead the design and delivery of agentic-first capabilities in Nexus Repository. Responsible for architecture, mentoring, and defining engineering practices for secure software supply chains.
Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only enterprise grade SBOM management and the leading open source dependency management platform. This empowers enterprises to create and maintain secure, quality, and innovative software at scale.
As founders of Nexus Repository and stewards of Maven Central, the world’s largest repository of Java open-source software, we are software pioneers and our open source expertise is unmatched. We empower innovation with an unparalleled commitment to build faster, safer software and harness AI and data intelligence to mitigate risk, maximize efficiencies, and drive powerful software development.
More than 2,000 organizations, including 70% of the Fortune 100 and 15 million software developers, rely on Sonatype to optimize their software supply chains.
About the Role
As an agentic-first Staff Software Engineer, you will lead the design and delivery of enterprise-grade, agentic-first capabilities within Nexus Repository Manager. You'll set technical direction for a major product area, orchestrate fleets of agents across parallel workstreams as your primary mode of work, and define the agentic engineering practices that other teams will learn from. You'll partner with Principal engineers on the hardest technical decisions and mentor Senior engineers to deliver capabilities that help enterprises secure their software supply chains at massive scale.
Why You Will Want to Apply
- Own the architecture of agentic-first features in a product used by 15 million developers and 70% of the Fortune 100.
- Practice a fundamentally new way of building software — long-running, multi-agent development — alongside Staff and Principal engineers who are defining the craft.
- Work on the hardest problems at the intersection of AI, distributed systems, and software supply chain security — a space where the industry playbook is still being written.
- Shape the technical roadmap for Nexus, set the engineering hiring bar, and mentor Senior engineers who will carry the craft forward.
What You Will do
- Architect & Lead With Agents: Drive the technical design of major agentic-first subsystems — service architecture, data models, and agent/tool integrations — by running long-running, multi-agent workflows across decomposition, orchestration, implementation, testing, and review.
- Own a Product Area: Take major initiatives from ambiguous problem statements through technical design, multi-team execution, rollout, and long-term operability.
- Verification Over Generation, at Scale: Spend your time on direction, review, and taste rather than line-by-line coding. Define the evals, harnesses, guardrails, and review rituals that let your team confidently ship code no human typed.
- Define the Practice: Set the bar for how Sonatype engineers work with agents. Shape internal playbooks, tooling, and rituals; train Senior engineers in the craft; and raise the ceiling on what's possible.
- Architecture, Security & Reliability: Own non-functional requirements for your area — performance, reliability, and security — with particular attention to software supply chain threats (malicious packages, dependency confusion, provenance, SBOM accuracy).
- Cross-functional Leadership: Partner with Product, Security Research, UX, and Support leaders to translate ambiguous customer needs into concrete, shippable technical plans; conduct deep design reviews; and raise the quality bar through thoughtful mentorship.
Who You Are
- Long-running Agentic Developer: Multi-step, long-running agent workflows are your default way of building software — well beyond Copilot-style autocomplete. You routinely orchestrate fleets of agents in parallel across planning, coding, testing, and review, and your own time is spent on direction, verification, and taste rather than generation.
- Multi-agent Orchestration at Depth: Hands-on experience designing, running, and scaling multi-agent systems (e.g., Claude Code, Codex, Cursor background agents, custom orchestrators, LangGraph-style graphs) — including MCP tooling, shared context and memory, agent handoffs, and robust eval harnesses. You've shipped production work this way and have strong opinions on what holds up at scale.
- Verification-first Mindset: You've internalized that the new leverage point is human judgment over machine generation. You define the evals, test harnesses, observability, and review workflows that let a team confidently ship code no one personally typed.
- Shapes Leading-edge Practice: You don't just adopt agentic workflows — you define them. You've led internal rollouts, published, open-sourced, or otherwise pushed the state of the art on how engineers work alongside agents, and have a clear point of view on where the craft is heading.
- Product Engineering Mindset: Half product, half engineering. You make product decisions independently and drive scope, trade-offs, and sequencing without constant PM hand-holding.
- Focused on What Matters: You want to build mission-critical products that drive revenue and transform how customers build software.
- Staff-level Engineering Skills: 7+ years of professional software development, with a track record of leading multi-quarter technical initiatives that span multiple teams or services.
- Deep Technical Foundation: Strong experience with Java, Cloud (AWS / Azure / GCP), and large-scale distributed systems — including performance tuning, data-intensive services, and production operability at scale.
- DevSecOps & Supply Chain Depth: Working knowledge of software supply chain security — SBOM formats (CycloneDX, SPDX), SCA, SLSA provenance, Sigstore/cosign signing, vulnerability analysis (OSV, NVD), and common attack patterns against package ecosystems.
- Deeply Curious: You push agentic tools to their limits — probing where they work, where they break, and how to make them better. You're energized by being early in a fundamentally new way of building software.
What We Are Proud Of
- 2025 Visionary in Gartner® Magic Quadrant™ for Application Security Testing!
- 2025 AI Compliance Solution of the Year - AI Breakthrough Awards
- 2025 DEVIES Award to our SBOM Manager for a new product for its innovation and impact in developer technology
- 2024 Industry Leader in Forrester-Wave for Software Composition Analysis (2024 Q4 report)
- Constellation AST Shortlist: Sonatype has been listed on the Constellation ShortList™ for Application Security Testing for 2024
- Data Breakthrough Awards: Sonatype was announced as a 2024 winner in the "Open Source Data Solution of the Year."
- SD Times: Best in Show Security
- Fast Company Best Workplaces for Innovators 2024
- The Herd Top 100 Private Software Companies 2024.
- Diversity & Inclusion Working Groups
- Parental Leave Policy
- Paid Volunteer Time Off (VTO)
At Sonatype, we value diversity and inclusivity. We offer perks such as parental leave, diversity and inclusion working groups, and flexible working practices to allow our employees to show up as their whole selves. We are an equal-opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you have a disability or special need that requires accommodation, please do not hesitate to let us know.
Similar Jobs
Blockchain • Fintech • Payments • Financial Services • Cryptocurrency • Web3
Lead sourcing, onboarding, activation, and commercial management of Beneficiary Financial Institutions on Circle Payment Network (CPN) to drive TPV growth, expand corridors and use cases, and coordinate cross-functional teams for smooth partner launches and ongoing optimization.
Top Skills:
AmlClearing SystemsCross-Border PaymentsKyc/KybPayment NetworksPayment RailsStablecoin
Information Technology
The Operations Analyst manages service delivery, provides tier-1 support, analyzes operations for service improvement, and collaborates with stakeholders. They ensure compliance with SLAs and communicate effectively with customers and team members.
Top Skills:
AutomateIbm Power IMS OfficeNimsoft Unified ManagementSciencelogicServicenow
Information Technology
The Consulting Enterprise Strategist leads multi-practice engagements, advising executive stakeholders and aligning technology solutions with business objectives. They drive innovation, develop digital transformation strategies, and create financial impact models. This role requires engagement with clients, design of solutions, and guidance for teams on market trends.
Top Skills:
AIApplicationsCloudDataDevOpsInfrastructureSaas TechnologiesSecurity
What you need to know about the Boston Tech Scene
Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.
Key Facts About Boston Tech
- Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
- Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
- Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
- Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories


