Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only enterprise grade SBOM management and the leading open source dependency management platform. This empowers enterprises to create and maintain secure, quality, and innovative software at scale.
As founders of Nexus Repository and stewards of Maven Central, the world’s largest repository of Java open-source software, we are software pioneers and our open source expertise is unmatched. We empower innovation with an unparalleled commitment to build faster, safer software and harness AI and data intelligence to mitigate risk, maximize efficiencies, and drive powerful software development.
More than 2,000 organizations, including 70% of the Fortune 100 and 15 million software developers, rely on Sonatype to optimize their software supply chains.
About the Role
As an agentic-first Senior Software Engineer, you will design, build, and ship agentic-first features within Nexus Repository Manager. You'll own meaningful pieces of the product end-to-end, and long-running multi-agent development workflows will be your primary mode of work — you'll spend most of your time directing and verifying agents rather than hand-typing code. You'll partner with Staff and Principal engineers to deliver capabilities that help enterprises secure their software supply chains at massive scale.
Why You Will Want to Apply
Design & Deliver With Agents: Design and implement scalable, high-performance features across the stack by driving long-running, multi-agent development workflows end-to-end — decomposition, orchestration, implementation, testing, and review.
Own Your Work End-to-End: Take features from ambiguous requirements through design, implementation, rollout, and on-call operability, using agents to move faster without compromising quality.
Verification Over Generation: Spend your time on direction, review, evals, and testing rather than line-by-line coding. Build and use the harnesses and guardrails that let you trust what the agents output.
Advance the Practice: Contribute to internal playbooks, tooling, and rituals for how Sonatype engineers work with agents — sharing what's working, what isn't, and what we should try next.
Quality, Security & Reliability: Write and ship clean, well-tested, observable code. Apply software supply chain security best practices to everything you deliver.
Collaboration: Partner with Product, UX, and fellow engineers to translate customer needs into shippable solutions, and raise the quality bar through thoughtful code review and mentorship of earlier-career engineers.
At Sonatype, we value diversity and inclusivity. We offer perks such as parental leave, diversity and inclusion working groups, and flexible working practices to allow our employees to show up as their whole selves. We are an equal-opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you have a disability or special need that requires accommodation, please do not hesitate to let us know.

The Sonatype journey started 15 years ago, just as the concept of “open source” software development was gaining steam. From our humble beginning as core contributors to Apache Maven, to supporting the world’s largest repository of open source components (Central), to distributing the world's most popular repository manager (Sonatype Nexus Repository), we’ve played a meaningful role in helping the world embrace the power of open innovation.
Over time, we witnessed the staggering volume and variety of open source libraries that began flowing into every development environment in the world. We understood that when open source components are properly managed, they provide a tremendous energy for accelerating innovation. Conversely, when unmanaged, open source "gone wild" can lead directly to security vulnerabilities, licensing risks, enormous rework, and waste.
Our vision today is simple.
We are laser focused on helping organizations continuously harness all of the good that open source has to offer, without any of the risk. In order to do this, we have invested in knowing more about the quality of open source than anyone else in the world. This investment takes the form of machine learning, artificial intelligence, and human expertise, which in aggregate produces highly curated intelligence that is infused into every Sonatype product. Organizations equipped with Sonatype products make better decisions, innovate faster at scale, and rest comfortably knowing that their applications always consist of the highest quality open source components.