What You’ll Do
Lead applied AI projects from concept to impact — prototype, validate, and help teams deploy practical ML and GenAI solutions. Collaborate cross-functionally: Partner with product, engineering, and research teams to scope problems, identify opportunities, and co-develop solutions. Act as an internal consultant: Advise teams on ML/AI best practices, model evaluation, and productive use of generative technologies. Design robust experiments and establish evaluation pipelines for model reliability, accuracy, and business impact. Bridge research and production: Package research insights into usable APIs, tools, or workflows for other teams. Explore new techniques (e.g., LLMs, embeddings models, retrieval-augmented generation, agentic workflows) to enhance developer and security experiences. Share knowledge and mentor peers, helping elevate the organization’s AI literacy and capabilities.
What We’re Looking For
6+ years of experience in applied data science, machine learning, or AI research Strong Python skills and hands-on experience with ML/AI libraries and platforms such as Databricks, OpenAI API, and Scikit-learn Comfortable working with large, messy, or unstructured datasets — you know how to turn chaos into features, insights, and beautiful visualizations Deep familiarity with LLMs and GenAI ecosystems (e.g. OpenAI, Claude, Hugging Face): skilled in prompt engineering, parameter tuning, and evaluating model behavior against ground truth Experience taking ML or GenAI systems from prototype to production, even if small-scale or incremental Strong analytical thinking, experimentation skills, and appreciation for trustworthy, data-driven evaluation Proficiency with Git and collaborative code workflows (GitHub or similar) A balanced mindset — equally comfortable exploring research ideas and implementing production-ready systems Proactive and self-directed: you don’t wait for perfect specs; you find meaningful problems and drive them to completion
Bonus Points
Experience with AI-assisted coding tools (Copilot, Claude Code, Codex, etc.) Familiarity with agentic workflows, Model Context Protocol (MCP), and tool-use integrations Exposure to cybersecurity, anomaly detection, or code analysis Understanding of MLOps practices (MLflow, AWS SageMaker, model serving, or monitoring)
Things we are proud of
2025 AI Compliance Solution of the Year - AI Breakthrough Awards
2025 DEVIES Award to our SBOM Manager new product for its innovation and impact in developer technology
2024 Industry Leader in Forrester-Wave for Software Composition Analysis (2024 Q4 report)
2023 Fast Company Best Places for Innovators
2023 Gartner's Magic Quadrant
2023 Software Report's Top 100 Software Companies
2023 BuiltIn Best Places to Work
2022 Frost & Sullivan Technology Innovation Leader Award
2022 PeerSpot Silver Peer Award in Software Composition Analysis
2022 Tech Ascension Best DevOps Security Solution Award
2022 NVCT Cyber Company of the Year
Company Wellness Week - We shut down company operations for a week to enable all employees to pursue personal growth and enjoy a much-needed and deserved rest.
Paid Volunteer Time Off (VTO)
Expansion of Sonatype’s India Innovation Hub in Hyderabad, reflecting our continued growth, commitment to innovation, and investment in talent to advance AI-driven software security globally
Sonatype is the software supply chain management company. We're on a mission to change how the world innovates by making software development easier. From running the world's largest repository of Java open source components (Maven Central), to inventing componentized software development, and then software supply chain management, to creating the only solution that stops malicious open source malware in its tracks, we're constantly leading the industry, while helping thousands of customers manage open source every day.
Already used by 15 million developers, we have lofty goals for our technology to be in the hands of every engineering team. And, we need you to do that. Join us!