Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only ente…
Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only ente…
Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only ente…
Sonatype is the software supply chain management company that invented componentized software development and pioneered the software supply chain category. As leaders in the open-source community and the DevSecOps indust…
Skills: Python, Machine learning, Generative AI, LLMs, Data science
Sonatype is the software supply chain management company that invented componentized software development and pioneered the software supply chain category. As leaders in the open-source community and the DevSecOps indust…
Skills: Python, Machine learning, Generative AI, LLMs, Data science
Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only ente…
Sonatype is the software supply chain security company. Sonatype is accelerating the future of agentic software development. As developers and AI agents build faster than ever, enterprises need a new level of control, vi…
Senior Software Engineer in Test (Automation Testing/API Testing/Java Programming - 7+ Years)
Hyderabad, Telangana, India · Hybrid
Senior$156M raised
Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only ente…
Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only ente…
Skills: People Analytics, HR Reporting, Workforce Planning, Business Intelligence, Executive Dashboarding
Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only ente…
Sonatype is the software supply chain security company. Sonatype is accelerating the future of agentic software development. As developers and AI agents build faster than ever, enterprises need a new level of control, vi…
Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only ente…
Skills: Azure DevOps, Terraform, Kubernetes, CI/CD, Azure Kubernetes Service (AKS)
Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only ente…
Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only ente…
Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only ente…
Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only ente…
Skills: Agentic Workflows, Multi-agent Orchestration, Java, Cloud Computing, Distributed Systems
Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only ente…
Skills: Agentic Software Engineering, Multi-agent Orchestration, Data Engineering, Software Supply Chain Security, Distributed Systems
Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only ente…
Skills: Demand Generation, Campaign Strategy, Marketing Automation, Digital Content Marketing, Social Media
Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only ente…
Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only ente…
Skills: AI Red Teaming, Application Security, Software Supply Chain Security, Vulnerability Validation, Java
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Full-time
Parental leave, Paid volunteer time off, Flexible working practices
Posted 20h ago
~40 hrs/week
Remote in United States
Responsibilities
You will design, automate, and scale the engineering platform and delivery systems on GCP while leading infrastructure and CI/CD modernization. Additionally, you will mentor engineering teams on platform engineering, DevOps best practices, and reliability engineering.
Requirements
The role requires strong hands-on experience with Google Cloud Platform, Infrastructure as Code (Terraform), and CI/CD pipeline design. Candidates must also possess proficiency in container orchestration, scripting, and cloud security practices.
Full job description
Sonatype is the software supply chain security company. We provide the world’s best end-to-end software supply chain security solution, combining the only proactive protection against malicious open source, the only enterprise grade SBOM management and the leading open source dependency management platform. This empowers enterprises to create and maintain secure, quality, and innovative software at scale.
As founders of Nexus Repository and stewards of Maven Central, the world’s largest repository of Java open-source software, we are software pioneers and our open source expertise is unmatched. We empower innovation with an unparalleled commitment to build faster, safer software and harness AI and data intelligence to mitigate risk, maximize efficiencies, and drive powerful software development.
More than 2,000 organizations, including 70% of the Fortune 100 and 15 million software developers, rely on Sonatype to optimize their software supply chains.
At Sonatype, we empower developers with best-in-class tools to build secure, high-quality software at scale. Our mission is to create a world where software is always secure and developers can innovate without fear. Trusted by thousands of organizations, including Fortune 500 companies, we are pioneers in software supply chain management, open-source security, and DevSecOps.
We are looking for a GCP DevOps Engineer to help us shape the future of secure software development. If you love solving complex problems, working with cloud-native platforms, and mentoring engineering teams, we would love to hear from you.
As a GCP DevOps Engineer, you will play a critical role in designing, automating, and scaling Sonatype's engineering platform and delivery systems on GCP. You will lead infrastructure and CI/CD modernization, improve reliability and security, and guide teams on platform engineering and DevOps best practices.
Why This Role Matters
This role helps create the engineering foundation that enables teams to ship securely, reliably, and quickly. You will influence how Sonatype scales its platform capabilities, improves developer experience, and advances its DevSecOps maturity on GCP.
You will work at the intersection of infrastructure, automation, security, and developer enablement, making a direct impact on product velocity and operational excellence.
\nKey Responsibilities
Design, implement, and evolve GCP-based infrastructure using Infrastructure as Code with Terraform and Google Cloud deployment automation patterns.
Build and maintain scalable CI/CD pipelines using Cloud Build, GitHub Actions, Jenkins, or equivalent platforms for application, infrastructure, and platform workloads.
Administer and optimize GCP delivery workflows including Cloud Build triggers, Artifact Registry, source integrations, deployment approvals, and service account access patterns.
Partner with engineering teams to improve build, release, and deployment workflows across microservices and cloud-native applications.
Implement robust observability across systems using Google Cloud Operations Suite, Cloud Logging, Cloud Monitoring, and related telemetry tooling.
Strengthen platform security by integrating secrets management, policy enforcement, vulnerability scanning, and least-privilege access contrrol.
Manage and optimize containerized environments using Kubernetes, Helm, and Google Kubernetes Engine (GKE).
Drive reliability engineering practices including incident response, root cause analysis, SLO thinking, and automated remediation where appropriate.
Standardize reusable templates, modules, and platform patterns that improve developer productivity and consistency.
Mentor engineers and provide technical leadership on GCP architecture, deployment automation, release governance, and DevSecOps practices.
What We Are Looking For
Strong experience in DevOps, platform engineering, or site reliability engineering roles supporting modern software delivery.
Deep hands-on expertise with Google Cloud Platform, including compute, networking, IAM, storage, monitoring, and security services.
Strong experience with GCP-native or integrated CI/CD pipeline design for multiple application stacks and deployment patterns.
Experience with Infrastructure as Code using Terraform, Deployment Manager alternatives, or equivalent automation frameworks.
Proficiency with containers and orchestration platforms such as Docker and Kubernetes, preferably with GKE experience.
Experience with scripting and automation using Python, Bash, PowerShell, or similar languages.
Solid understanding of source control workflows, package management, artifact promotion, and release strategies.
Experience implementing observability, logging, alerting, and operational dashboards for production systems.
Strong understanding of cloud security, IAM, secrets management, compliance controls, and secure software delivery practices.
Excellent collaboration and communication skills, with the ability to influence technical direction across teams.
What Would Be Nice to Have
Experience with GitHub, SonarQube, Nexus Repository, or software supply chain security tooling.
Familiarity with multi-cloud environments and migration patterns from AWS or on-premises platforms
Exposure to policy-as-code, platform engineering, developer portals, or internal developer platform concepts.
Experience supporting regulated or enterprise-scale environments with strong governance requirements.
Things That We Are Proud Of
2025 Visionary in Gartner® Magic Quadrant™ for Application Security Testing!
2025 AI Compliance Solution of the Year - AI Breakthrough Awards
2025 DEVIES Award to our SBOM Manager for a new product for its innovation and impact in developer technology
2024 Industry Leader in Forrester-Wave for Software Composition Analysis (2024 Q4 report)
Constellation AST Shortlist: Sonatype has been listed on the Constellation ShortList™ for Application Security Testing for 2024
Data Breakthrough Awards: Sonatype was announced as a 2024 winner in the "Open Source Data Solution of the Year."
SD Times: Best in Show Security
Fast Company Best Workplaces for Innovators 2024
The Herd Top 100 Private Software Companies 2024.
Diversity & Inclusion Working Groups
Parental Leave Policy
Paid Volunteer Time Off (VTO)
\n
At Sonatype, we value diversity and inclusivity. We offer perks such as parental leave, diversity and inclusion working groups, and flexible working practices to allow our employees to show up as their whole selves. We are an equal-opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you have a disability or special need that requires accommodation, please do not hesitate to let us know.
Related keywords
GCPDevOpsTerraformKubernetesGKECI/CDCloud BuildPythonBashPowerShellInfrastructure as CodeObservabilityGoogle Cloud Operations SuiteIAMSecurityPlatform Engineering
The Sonatype journey started 15 years ago, just as the concept of “open source” software development was gaining steam. From our humble beginning as core contributors to Apache Maven, to supporting the world’s largest repository of open source components (Central), to distributing the world's most popular repository manager (Sonatype Nexus Repository), we’ve played a meaningful role in helping the world embrace the power of open innovation.
Over time, we witnessed the staggering volume and variety of open source libraries that began flowing into every development environment in the world. We understood that when open source components are properly managed, they provide a tremendous energy for accelerating innovation. Conversely, when unmanaged, open source "gone wild" can lead directly to security vulnerabilities, licensing risks, enormous rework, and waste.
Our vision today is simple.
We are laser focused on helping organizations continuously harness all of the good that open source has to offer, without any of the risk. In order to do this, we have invested in knowing more about the quality of open source than anyone else in the world. This investment takes the form of machine learning, artificial intelligence, and human expertise, which in aggregate produces highly curated intelligence that is infused into every Sonatype product. Organizations equipped with Sonatype products make better decisions, innovate faster at scale, and rest comfortably knowing that their applications always consist of the highest quality open source components.
Offices: 8161 Maple Lawn Blvd, Suite 250, Fulton, MD 20759, US · 168 Shoreditch High Street, London, England E1 6HU, GB · Auro Orbit, Tower 1, 4th Floor, HITEC City, Hyderabad, Telangana 500081, IN
Open SourceOpen Source GovernanceManagement and ComplianceRepository ManagementDevOpsDevSecOpsSoftware Supply ChainContinuous DeliveryContinuous IntegrationOpen Source Security
The Sonatype journey started 15 years ago, just as the concept of “open source” software development was gaining steam. From our humble beginning as core contributors to Apache Maven, to supporting the world’s largest repository of open source components (Central), to distributing the world's most popular repository manager (Sonatype Nexus Repository), we’ve played a meaningful role in helping the world embrace the power of open innovation.
Over time, we witnessed the staggering volume and variety of open source libraries that began flowing into every development environment in the world. We understood that when open source components are properly managed, they provide a tremendous energy for accelerating innovation. Conversely, when unmanaged, open source "gone wild" can lead directly to security vulnerabilities, licensing risks, enormous rework, and waste.
Our vision today is simple.
We are laser focused on helping organizations continuously harness all of the good that open source has to offer, without any of the risk. In order to do this, we have invested in knowing more about the quality of open source than anyone else in the world. This investment takes the form of machine learning, artificial intelligence, and human expertise, which in aggregate produces highly curated intelligence that is infused into every Sonatype product. Organizations equipped with Sonatype products make better decisions, innovate faster at scale, and rest comfortably knowing that their applications always consist of the highest quality open source components.
Offices: 8161 Maple Lawn Blvd, Suite 250, Fulton, MD 20759, US · 168 Shoreditch High Street, London, England E1 6HU, GB · Auro Orbit, Tower 1, 4th Floor, HITEC City, Hyderabad, Telangana 500081, IN
Open SourceOpen Source GovernanceManagement and ComplianceRepository ManagementDevOpsDevSecOpsSoftware Supply ChainContinuous DeliveryContinuous IntegrationOpen Source Security