技术项目经理
Technical Project Manager
Sonatype 是软件供应链安全公司。我们提供全球最完善的端到端软件供应链安全解决方案,结合针对恶意开源代码的唯一主动防护、唯一的企业级 SBOM 管理以及领先的开源依赖管理平台。这使企业能够大规模地创建和维护安全、高质量且具有创新性的软件。
作为 Nexus Repository 的创始人和 Maven Central 的管理者,世界上最大的 Java 开源软件仓库,我们是软件先驱,我们的开源专业知识无可匹敌。我们以无与伦比的承诺,致力于构建更快、更安全的软件,并利用人工智能和数据智能来降低风险、提高效率并推动强大的软件开发。
超过 2000 家组织,包括 70% 的财富 100 强企业和 1500 万名软件开发者,依靠 Sonatype 来优化他们的软件供应链。
作为 Sonatype 的技术项目经理,你将负责关键安全和 IT 项目的规划、执行和交付。你将与应用安全、工程、产品、安全研究、法律、人力资源、财务和领导团队进行跨职能协作,将复杂的业务需求转化为可执行的项目计划。你将确保项目按时、按范围完成,并与业务目标保持一致,同时在所有利益相关者之间保持清晰的沟通。
你将负责安全和 IT 项目的全流程交付,将业务需求转化为可执行的计划,并通过结构化的项目管理实践确保成功的结果。
你将负责的工作内容
项目执行与责任:从规划到完成,负责分配的项目。为多个同时进行的技术项目建立并维护详细的项目计划,确保里程碑、负责人、依赖关系、风险和交付物保持在正轨上。
风险与依赖管理:主动识别、跟踪和缓解项目风险和跨团队依赖。明确负责人、缓解计划和升级路径,防止交付延迟。
跨职能协调:协调多个部门和团队——包括 IT、安全、工程、财务、人力资源、销售、市场和法律——对齐交付成果并解决跨部门依赖。
项目健康与报告:保持对项目里程碑、状态、风险和依赖的清晰可见性。
查看英文原文
Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only enterprise-grade SBOM management, and the leading open source dependency management platform. This empowers enterprises to create and maintain secure, quality, and innovative software at scale.
As founders of Nexus Repository and stewards of Maven Central, the world’s largest repository of Java open-source software, we are software pioneers, and our open-source expertise is unmatched. We empower innovation with an unparalleled commitment to build faster, safer software and harness AI and data intelligence to mitigate risk, maximize efficiencies, and drive powerful software development.
More than 2,000 organizations, including 70% of the Fortune 100 and 15 million software developers, rely on Sonatype to optimize their software supply chains.
As a Technical Project Manager at Sonatype, you will drive the planning, execution, and delivery of critical security and IT initiatives. You will work cross-functionally with Application Security, Engineering, Product, Security Research, Legal, HR, Finance, and leadership teams to turn complex technical requirements into actionable project plans. You will ensure projects are delivered on time, within scope, and aligned with business objectives while maintaining clear communication across all stakeholders.
You will lead end-to-end project delivery for security and IT initiatives, transforming business needs into executable plans and ensuring successful outcomes through structured project management practices.
What You Will do
Project Execution & Ownership: Own assigned projects from planning through completion. Build and maintain detailed project plans across multiple concurrent, technology initiatives, ensuring milestones, owners, dependencies, risks, and deliverables remain on track.
Risk & Dependency Management: Proactively identify, track, and mitigate project risks and cross-team dependencies. Establish clear owners, mitigation plans, and escalation paths to prevent delivery delays.
Cross-Functional Alignment: Coordinate across multiple segments and teams—including IT, Security, Engineering, Finance, HR, Sales, Marketing and Legal—to align deliverables and resolve cross-segment dependencies.
Project Health & Reporting: Maintain clear visibility into project milestones, status, risks, dependencies, decisions, and changes to scope or timelines. Provide concise and actionable updates to key stakeholders.
Obstacle Removal & Stakeholder Touchpoints: Host regular syncs, manage ongoing communications, and proactively step in to clear blockers for the teams.
Decision & Escalation Management: Drive timely resolution of cross-functional decisions by identifying decision owners, documenting outcomes, and escalating unresolved issues when necessary.
Process Automation & Efficiency: Leverage AI and automation tools to streamline workflows, eliminate manual administrative overhead, and optimize operational efficiency.
Vendor and Tool Coordination: Coordinate vendor relationships, including procurement steps, renewals, and contract management
What You Bring
Experience: 5+ years of experience in technical Project Management within SaaS or technology companies.
Complex Deliverables: Proven track record of managing complex, cross-functional tech and data projects with multiple dependencies
Technical Fluency: Comfortable working with Security, IT, and Business teams and understanding technical concepts such as APIs, integrations, data flows, architecture dependencies, and software delivery processes at a project-management level.
Planning Through Ambiguity: Demonstrated ability to take ambiguous or loosely defined initiatives and turn them into structured execution plans with clear milestones, owners, dependencies, risks, and measurable outcomes.
Communication & Collaboration : Ability to synthesize complex project information into concise, actionable updates for senior leadership, including clearly communicating risks, tradeoffs, and decisions needed.
AI & Automation Mindset: Active user of AI tools and automation strategies to optimize day-to-day project workflows.
Project Management Tools: Experience using modern project and collaboration tools such as Jira, Confluence, Slack, and Google Workspace or equivalent platforms.
Location: Must be comfortable working effectively in a distributed, remote environment.
Certifications (Bonus): PMP certification is desired, but not mandatory.
Nice-to-Have Skills
Project Management Professional (PMP) or Agile certifications (CSM, SAFe)
Experience with security frameworks and compliance standards (SOC 2, ISO 27001, ISO 42001, NIST, GDPR)
Any background with IT and cybersecurity initiatives
Experience with identity and access management (IAM), SSO, MFA implementations
Familiarity with cloud platforms (AWS, Azure, GCP) and security tooling
Experience with ITSM frameworks and service management practices
Background in vendor management and procurement processes
Experience facilitating audits and compliance evidence collection.
Things That We Are Proud Of
2026 Gartner® Magic Quadrant™ Leader for Software Supply Chain Security
2026 Celebrating 15 Years of Sonatype Research Labs – Industry-leading software supply chain and open source security research
2026 Founding Member of the Linux Foundation Initiative for Open Source Sustainability
2026 State of the Software Supply Chain® Report – Continuing industry leadership in software supply chain security and AI security research
2025 Visionary in Gartner® Magic Quadrant™ for Application Security Testing!
2025 AI Compliance Solution of the Year - AI Breakthrough Awards
2025 DEVIES Award to our SBOM Manager for a new product for its innovation and impact in developer technology
2024 Industry Leader in Forrester-Wave for Software Composition Analysis (2024 Q4 report)
Constellation AST Shortlist: Sonatype has been listed on the Constellation ShortList™ for Application Security Testing for 2024
Data Breakthrough Awards: Sonatype was announced as a 2024 winner in the "Open Source Data Solution of the Year."
SD Times: Best in Show Security
Fast Company Best Workplaces for Innovators 2024
The Herd Top 100 Private Software Companies 2024
Diversity & Inclusion Working Groups
Parental Leave Policy
Paid Volunteer Time Off (VTO)
At Sonatype, we value diversity and inclusivity. We offer perks such as parental leave, diversity and inclusion working groups, and flexible working practices to allow our employees to show up as their whole selves. We are an equal-opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you have a disability or special need that requires accommodation, please do not hesitate to let us know.