高级数据科学家
Senior Data Scientist
Sonatype 是一家软件供应链管理公司,是组件化软件开发的发明者,并率先开创了软件供应链这一领域。作为开源社区和 DevSecOps 行业的领导者,我们运营着全球最大的 Java 开源组件仓库——Maven Central。
我们突破性的全栈平台使客户能够快速创建、部署和维护创新软件,同时直接满足其业务需求。超过 2000 家组织——包括 70% 的财富 100 强企业——以及超过 1500 万名软件开发者都信任 Sonatype 的工具和指导,帮助他们交付卓越且安全的软件。
从发明现代构件管理(Nexus Repository)到推出世界上唯一能阻止恶意开源恶意软件的解决方案,我们致力于持续创新。我们利用 AI/ML 为客户提供、开发者和行业在软件质量、自动化和安全性方面提供全面信心。
了解更多请访问 www.sonatype.com
职位描述
我们正在寻找一位高级数据科学家加入我们不断壮大的 AI 与数据科学团队,帮助塑造 Sonatype 在整个组织中应用机器学习和生成式 AI 的方式。
在此职位中,你将对高影响力的 AI 项目提供技术领导,与产品、工程、安全、研究和数据团队合作,识别机会、定义方法,并将模糊的问题转化为实际的 AI 解决方案。你将帮助建立技术方向和最佳实践,同时保持深入的实战参与——探索数据、设计实验、构建模型,并引导解决方案进入生产环境。
你将在各种用例中工作,从我们在安全数据中的恶意行为和异常检测,到面向开发者和分析师的生成式 AI 体验,涉及 LLM、检索和代理系统。
这个职位适合一位兼具深厚技术专长和强大判断力与影响力的人——能够领导复杂的 AI 项目,指导其他从业者,并帮助团队在 AI 如何创造有意义影响的问题上做出深思熟虑的决策。
你将负责:
对 Sonatype 的应用 AI 和数据科学项目提供技术主导,帮助定义方法、架构、优先级和标准。
领导复杂的 AI 项目从概念到生产——将模糊的业务和技术问题转化为可衡量的实验和可扩展的解决方案。
查看英文原文
Sonatype is the software supply chain management company that invented componentized software development and pioneered the software supply chain category. As leaders in the open-source community and the DevSecOps industry, we run the world’s largest repository of Java open-source components—Maven Central.
Our groundbreaking, full-spectrum platform empowers customers to rapidly create, deploy, and maintain innovative software at scale, all while aligning directly to their business needs. Trusted by more than 2,000 organizations—including 70% of the Fortune 100—and over 15 million software developers, Sonatype’s tools and guidance help deliver exceptional, secure software.
From inventing modern artifact management with Nexus Repository to introducing the world’s only solution that halts malicious open-source malware in its tracks, we’re committed to constant innovation. We leverage AI/ML to give our clients, developers, and the industry complete confidence in the quality, automation, and security of their software.
Learn more at www.sonatype.com
The Role
We're looking for a Senior Data Scientist to join our growing AI & Data Science team and help shape how Sonatype applies machine learning and generative AI across the organization.
In this role, you'll provide technical leadership across high-impact AI initiatives, partnering with product, engineering, security, research, and data teams to identify opportunities, define approaches, and turn ambiguous problems into practical AI solutions. You'll help establish technical direction and best practices while remaining deeply hands-on—exploring data, designing experiments, building models, and guiding solutions into production.
You'll work across use cases ranging from malicious-behavior and anomaly detection in our security data to developer- and analyst-facing GenAI experiences involving LLMs, retrieval, and agentic systems.
This role is ideal for someone who combines deep technical expertise with strong judgment and influence—someone who can lead complex AI initiatives, mentor other practitioners, and help teams make thoughtful decisions about where and how AI can create meaningful impact.
What you'll do:
Provide technical ownership for applied AI and data science initiatives across Sonatype, helping define approaches, architecture, priorities, and standards.
Lead complex AI projects from concept to production—translating ambiguous business and technical problems into measurable experiments and scalable solutions.
Act as a senior internal AI consultant to product, engineering, security, and research teams, helping identify high-value opportunities and advising teams on ML and GenAI approaches.
Lead the research, development, and deployment of models for malicious behavior detection, anomaly detection, fraud analysis, and other security and product use cases.
Design and guide advanced GenAI solutions using LLMs, embeddings, retrieval-augmented generation, structured outputs, tool use, and agentic or multi-step workflows.
Establish strong experimentation and evaluation practices, including representative evaluation datasets, quality metrics, cross-validation, ground-truth evaluation, drift monitoring, and business-impact measurement.
Set technical direction for reliable and maintainable AI systems, balancing experimentation with production quality, security, scalability, and responsible AI practices.
Bridge research and production by designing scalable APIs, services, tools, and workflows that allow AI capabilities to be adopted across products and internal teams.
Evaluate emerging AI technologies and frameworks and make recommendations on when and how Sonatype should adopt them.
Partner closely with engineering and MLOps teams on deployment, observability, model lifecycle management, performance, and reliability.
Mentor data scientists and other technical contributors, review technical approaches, and help elevate AI engineering and data science practices across the organization.
Communicate AI strategy, technical tradeoffs, experimental findings, and recommendations clearly to technical and non-technical stakeholders.
Partner with data governance, security, and legal stakeholders to ensure appropriate privacy, security, ethical, and responsible-AI practices.
What you bring:
7+ years of hands-on experience in applied data science, machine learning, AI engineering, or AI research.
Computer Science or equivalent technical degree strongly preferred
Strong Python skills and practical experience with data and AI libraries/platforms such as Databricks, and LLM APIs, scikit-learn
Experience building and shipping ML or GenAI applications—from early prototype through usable internal or customer-facing workflows.
Deep familiarity with modern LLM ecosystems, including OpenAI, Anthropic/Claude, Hugging Face, and open-weight models.
Ability to select models and design effective LLM applications using prompting, context management, structured outputs, retrieval, and tool use.
Experience building agentic or multi-step AI workflows with LangGraph, LangChain, Semantic Kernel, or similar orchestration frameworks.
Strong evaluation mindset: defining useful quality metrics, building representative evaluation datasets, assessing reliability, and making data-driven tradeoffs.
Comfortable working with large, messy, structured, and unstructured data to produce features, insights, and clear visualizations.
Proficiency with Git, testing, code review, and collaborative software-development practices.
Practical, balanced judgment: comfortable exploring emerging AI capabilities while building maintainable, secure, dependable systems.
Proactive and accountable, with strong written and verbal communication skills across technical and non-technical partners.
It'd be great if you had:
Deep MLOps experience, including MLflow or comparable tooling, experiment tracking, reproducible pipelines, model/application versioning, CI/CD, serving, and production monitoring.
Experience designing or operating ML and GenAI platforms or systems at scale, including observability, tracing, incident response, and data or model-drift detection.
Experience with Databricks ML, AWS SageMaker, Azure ML, or similar managed ML platforms.
Experience defining AI architecture, technical standards, or reusable patterns adopted across multiple teams.
Familiarity with MCP, agent-tool integrations, LLM guardrails, AI security, and production safety practices.
Experience with AI-assisted development tools such as Copilot, Claude Code, or Codex.
Experience applying ML or AI to cybersecurity, fraud detection, anomaly detection, code analysis, threat intelligence, or software supply-chain security.
Experience with PySpark and large-scale production data pipelines.
Experience working within a software product company and partnering closely with product and engineering leadership.
Experience mentoring technical contributors or acting as a technical lead across multiple AI or data science initiatives.
Things we're proud of:
2026 Gartner® Magic Quadrant™ Leader for Software Supply Chain Security
2026 Celebrating 15 Years of Sonatype Research Labs – Industry-leading software supply chain and open source security research
2026 Founding Member of the Linux Foundation Initiative for Open Source Sustainability
2026 State of the Software Supply Chain® Report – Continuing industry leadership in software supply chain security and AI security research
2025 Visionary in Gartner® Magic Quadrant™ for Application Security Testing!
2025 AI Compliance Solution of the Year - AI Breakthrough Awards
2025 DEVIES Award to our SBOM Manager for a new product for its innovation and impact in developer technology
2024 Industry Leader in Forrester-Wave for Software Composition Analysis (2024 Q4 report)
Constellation AST Shortlist: Sonatype has been listed on the Constellation ShortList™ for Application Security Testing for 2024
Data Breakthrough Awards: Sonatype was announced as a 2024 winner in the "Open Source Data Solution of the Year."
SD Times: Best in Show Security
Fast Company Best Workplaces for Innovators 2024
The Herd Top 100 Private Software Companies 2024
Diversity & Inclusion Working Groups
Parental Leave Policy
Paid Volunteer Time Off (VTO)
At Sonatype, we value diversity and inclusivity. We offer perks such as parental leave, diversity and inclusion working groups, and flexible working practices to allow our employees to show up as their whole selves. We are an equal-opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you have a disability or special need that requires accommodation, please do not hesitate to let us know.