数据科学家
Data Scientist
Sonatype 是一家软件供应链管理公司,开创了组件化软件开发并率先定义了软件供应链类别。作为开源社区和 DevSecOps 行业的领导者,我们运营着全球最大的 Java 开源组件仓库——Maven Central。
我们突破性的全栈平台使客户能够快速创建、部署和维护创新软件,同时直接满足其业务需求。超过 2000 家组织——包括 70% 的财富 100 强企业——以及超过 1500 万名软件开发者信赖 Sonatype 的工具和指导,以交付卓越且安全的软件。
从发明现代构件管理(Nexus Repository)到推出世界上唯一能阻止恶意开源恶意软件的解决方案,我们致力于持续创新。我们利用 AI/ML 为我们的客户、开发者和行业提供对软件质量、自动化和安全性的完全信心。
了解更多请访问 www.sonatype.com
职位描述
我们正在寻找一名数据科学家加入不断壮大的 AI 与数据科学团队。你将作为内部 AI 顾问和技术负责人,帮助 Sonatype 各个团队应用机器学习和生成式 AI 解决实际问题——从我们在安全数据中的恶意行为和异常检测,到面向开发者和分析师的生成式 AI 体验。
你将探索复杂的数据集,设计实验,构建和验证模型,并与产品、工程和安全专家紧密合作,将研究想法转化为实用且可扩展的解决方案。我们拥有成熟的数仓团队,因此你可以专注于你最擅长的事情——构建和部署模型。
这个职位适合那些在自主性中茁壮成长的人,他们喜欢将模糊的想法转化为工作系统,并享受跨领域协作而非局限于单一产品线。
你将负责:
从概念到影响领导应用 AI 项目——原型设计、验证,并帮助团队部署实用的 ML 和生成式 AI 解决方案。
作为产品、工程、安全和研究团队的内部顾问:界定问题、评估方法,并就 ML/AI 最佳实践和生成式技术的高效使用提供建议。
领导用于恶意行为检测、异常检测和欺诈分析等用例的模型研究、开发和部署——使用从分类到深度学习的各种技术。
查看英文原文
Sonatype is the software supply chain management company that invented componentized software development and pioneered the software supply chain category. As leaders in the open-source community and the DevSecOps industry, we run the world’s largest repository of Java open-source components—Maven Central.
Our groundbreaking, full-spectrum platform empowers customers to rapidly create, deploy, and maintain innovative software at scale, all while aligning directly to their business needs. Trusted by more than 2,000 organizations—including 70% of the Fortune 100—and over 15 million software developers, Sonatype’s tools and guidance help deliver exceptional, secure software.
From inventing modern artifact management with Nexus Repository to introducing the world’s only solution that halts malicious open-source malware in its tracks, we’re committed to constant innovation. We leverage AI/ML to give our clients, developers, and the industry complete confidence in the quality, automation, and security of their software.
Learn more at www.sonatype.com
The Role
We're looking for a Data Scientist to join our growing AI & Data Science team. You'll operate as an internal AI consultant and technical lead, helping multiple teams across Sonatype apply machine learning and generative AI to real-world problems — from malicious-behavior and anomaly detection in our security data, to developer- and analyst-facing GenAI experiences.
You'll explore complex datasets, design experiments, build and validate models, and collaborate closely with product, engineering, and security experts to turn research ideas into practical, scalable solutions. We have a mature data engineering team, so you can focus on doing what you do best — building and shipping models.
This role is ideal for someone who thrives on autonomy, loves translating ambiguous ideas into working systems, and enjoys working across boundaries rather than staying in a single product lane.
What you'll do:
Lead applied AI projects from concept to impact — prototype, validate, and help teams deploy practical ML and GenAI solutions.
Act as an internal consultant across product, engineering, security, and research teams: scope problems, evaluate approaches, and advise on ML/AI best practices and productive use of generative technologies.
Lead the research, development, and deployment of models for use cases such as malicious behavior detection, anomaly detection, and fraud analysis — using techniques ranging from classical ML to LLMs, embeddings, retrieval-augmented generation, and agentic workflows.
Design robust experiments and establish evaluation pipelines for model reliability, accuracy, and business impact (cross-validation, drift monitoring, ground-truth evaluation).
Bridge research and production: translate research insights into scalable APIs, tools, or workflows that enable other teams to adopt AI effectively.
Explore new techniques (LLMs, embeddings models, RAG, agentic workflows) to enhance developer and security experiences.
Communicate technical concepts, tradeoffs, and recommendations clearly to both technical and non-technical stakeholders through presentations, documentation, and collaboration; mentor peers and help elevate the organization's AI literacy and capabilities.
Partner with our data governance team to ensure compliance with data-privacy regulations and ethical considerations when working with customer data.
What you bring:
5+ years of hands-on experience in applied data science, machine learning, AI engineering, or AI research.
Computer Science or equivalent technical degree strongly preferred
Strong Python skills and practical experience with data and AI libraries/platforms such as Databricks, and LLM APIs, scikit-learn
Experience building and shipping ML or GenAI applications—from early prototype through usable internal or customer-facing workflows.
Deep familiarity with modern LLM ecosystems, including OpenAI, Anthropic/Claude, Hugging Face, and open-weight models.
Ability to select models and design effective LLM applications using prompting, context management, structured outputs, retrieval, and tool use.
Experience building agentic or multi-step AI workflows with LangGraph, LangChain, Semantic Kernel, or similar orchestration frameworks.
Strong evaluation mindset: defining useful quality metrics, building representative evaluation datasets, assessing reliability, and making data-driven tradeoffs.
Comfortable working with large, messy, structured, and unstructured data to produce features, insights, and clear visualizations.
Proficiency with Git, testing, code review, and collaborative software-development practices.
Practical, balanced judgment: comfortable exploring emerging AI capabilities while building maintainable, secure, dependable systems.
Proactive and accountable, with strong written and verbal communication skills across technical and non-technical partners.
It'd be great if you had:
Strong MLOps experience, including MLflow or comparable tooling, experiment tracking, reproducible pipelines, model/application versioning, CI/CD, serving, and production monitoring.
Experience operating ML or GenAI systems at scale, including observability, tracing, incident response, and data or model-drift detection.
Experience with Databricks ML, AWS SageMaker, Azure ML, or similar managed ML platforms.
Familiarity with MCP, agent-tool integrations, LLM guardrails, and production safety practices.
Experience with AI-assisted development tools such as Copilot, Claude Code, or Codex.
Exposure to cybersecurity, fraud detection, anomaly detection, code analysis, or software supply-chain security.
Experience with PySpark and production data pipelines.
Experience working within a software product company or SaaS.
Things we're proud of:
2026 Gartner® Magic Quadrant™ Leader for Software Supply Chain Security
2026 Celebrating 15 Years of Sonatype Research Labs – Industry-leading software supply chain and open source security research
2026 Founding Member of the Linux Foundation Initiative for Open Source Sustainability
2026 State of the Software Supply Chain® Report – Continuing industry leadership in software supply chain security and AI security research
2025 Visionary in Gartner® Magic Quadrant™ for Application Security Testing!
2025 AI Compliance Solution of the Year - AI Breakthrough Awards
2025 DEVIES Award to our SBOM Manager for a new product for its innovation and impact in developer technology
2024 Industry Leader in Forrester-Wave for Software Composition Analysis (2024 Q4 report)
Constellation AST Shortlist: Sonatype has been listed on the Constellation ShortList™ for Application Security Testing for 2024
Data Breakthrough Awards: Sonatype was announced as a 2024 winner in the "Open Source Data Solution of the Year."
SD Times: Best in Show Security
Fast Company Best Workplaces for Innovators 2024
The Herd Top 100 Private Software Companies 2024
Diversity & Inclusion Working Groups
Parental Leave Policy
Paid Volunteer Time Off (VTO)
At Sonatype, we value diversity and inclusivity. We offer perks such as parental leave, diversity and inclusion working groups, and flexible working practices to allow our employees to show up as their whole selves. We are an equal-opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you have a disability or special need that requires accommodation, please do not hesitate to let us know.