Summary
Join Sonatype, the leading software supply chain security company, as a Security Researcher! This 100% remote position, based in Colombia, focuses on investigating and analyzing vulnerabilities in open-source software. You will review, isolate, analyze, and reverse engineer vulnerabilities, document attack capabilities, and provide detection and remediation guidance. Collaboration with team members is key to achieving shared product goals and improving Sonatype products with valuable security data. This role offers a valuable learning opportunity and growth potential in cybersecurity within a fast-paced, flexible, and fun environment.
Requirements
- Bachelor of Science Degree in Computer Science, Cybersecurity, Engineering, or related field
- 2+ years of experience in software development or application security
- Knowledge of Java, C#, or JavaScript
- Knowledge of application security such as the OWASP Top 10 or Sans 25
- Excellent oral and written communication skills
- Excellent organizational skills and detail oriented
- Ability to work independently and as part of a team
Responsibilities
- Review, isolate, analyze, and reverse engineer vulnerabilities in open-source software
- Document attack capabilities
- Provide detection and remediation guidance
- Aid in ideas and prototypes for new tooling
- Collaborate with other team members toward shared product goals
- Improve Sonatype products by providing valuable security data
- Work with technology and business team members to define and refine requirements in an agile development environment
Preferred Qualifications
- Knowledge of different languages such as Python, Ruby, and scripting is a plus
- Knowledge of different operating systems such as *NIX, Windows is a plus
- Application vulnerability assessment or penetration testing experience is a plus
- Knowledge of open source environments like GitHub is a plus
Benefits
- Company Wellness Week - We shut down company operations for a week to enable all employees to pursue personal growth and enjoy a much-needed and deserved rest
- Paid Volunteer Time Off (VTO)
- Parental leave
- Flexible working practices
Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.