All remote jobs
Open role
Remote opportunity atSonatype

Data Scientist

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Published
18Listing views
2Application actions
29 Sep 2026Apply before
Opportunity details

About this role.

AI Summary

Sonatype is seeking a senior Data Scientist to lead applied machine-learning and generative-AI initiatives across product, engineering, security, and research. The role covers the full lifecycle from ambiguous problem definition and experimentation through model evaluation, deployment enablement, and production reliability. Core work includes anomaly, malicious-behavior, and fraud detection, as well as LLM, RAG, embedding, and agentic-workflow applications. The candidate will act as an internal AI consultant, translating technical tradeoffs for varied stakeholders and helping improve organizational AI capability. Strong Python, ML engineering, LLM application design, evaluation, and collaborative software-development practices are required.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

5/5
EasyHard

Pace & Pressure

4/5
RelaxedFast-paced

Autonomy Level

5/5
GuidedFull ownership

Communication Load

5/5
IndependentCollaborative
AI insightThis is a senior, cross-functional technical-lead role requiring 5+ years of applied AI experience and the ability to deliver reliable ML and GenAI systems across several problem domains. Success requires independent judgment in ambiguous settings, rigorous evaluation, and production-minded engineering in a security-sensitive environment.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate
$175,000
US market range$145k–$210k
AI insightNo actual salary range is disclosed in the posting. This is an estimated US-market yearly base-salary range for a senior Data Scientist / applied AI technical lead with ML, LLM, MLOps, and security-domain responsibilities; actual compensation may vary by location, level, and total-rewards structure.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
Describe an ML or GenAI application you took from an early concept to a production workflow. How did you measure success?

I would begin by defining the user decision or workflow to improve and establishing measurable success criteria, such as precision at a review threshold, task-completion quality, latency, and adoption. I would build a small prototype, evaluate it against representative labeled cases and failure scenarios, then productionize it with versioning, monitoring, and a feedback loop. After launch, I would compare the system against the baseline and iterate based on both quantitative performance and user feedback.

How would you approach malicious-behavior or anomaly detection when labeled examples are limited?

I would combine domain-driven features with unsupervised or semi-supervised approaches such as isolation forests, clustering, autoencoders, or one-class methods. I would work with security experts to create high-value review queues, use analyst feedback to develop labels over time, and evaluate precision at operationally useful alert volumes. I would also monitor feature and data drift because adversarial behavior evolves.

How do you evaluate whether an LLM or RAG application is reliable enough to deploy?

I would define a task-specific evaluation set that includes normal cases, edge cases, adversarial prompts, and known failure patterns. Metrics would cover groundedness, factual accuracy, retrieval quality, structured-output validity, latency, cost, and safety behavior. I would use automated evaluations alongside expert review, establish release gates, and instrument production tracing and feedback so performance can be monitored after deployment.

How do you communicate AI tradeoffs to non-technical stakeholders?

I frame discussions around the business decision, expected benefit, risk, cost, and confidence level rather than model internals alone. I use concrete examples and clearly distinguish what the system can automate, what needs human review, and how outcomes will be measured. This helps stakeholders make informed prioritization decisions while maintaining realistic expectations.

What practices would you use to make an AI system maintainable and compliant when working with customer data?

I would apply data minimization, access controls, retention rules, audit logging, and clear lineage for datasets, prompts, models, and outputs. I would partner early with governance and security teams to identify privacy constraints, establish approved data flows, and define human-review or escalation paths for sensitive outcomes. Reproducible pipelines, model versioning, testing, monitoring, and incident-response procedures would support safe long-term operation.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.

Sonatype is the software supply chain management company that invented componentized software development and pioneered the software supply chain category. As leaders in the open-source community and the DevSecOps industry, we run the world’s largest repository of Java open-source components—Maven Central.

Our groundbreaking, full-spectrum platform empowers customers to rapidly create, deploy, and maintain innovative software at scale, all while aligning directly to their business needs. Trusted by more than 2,000 organizations—including 70% of the Fortune 100—and over 15 million software developers, Sonatype’s tools and guidance help deliver exceptional, secure software.

From inventing modern artifact management with Nexus Repository to introducing the world’s only solution that halts malicious open-source malware in its tracks, we’re committed to constant innovation. We leverage AI/ML to give our clients, developers, and the industry complete confidence in the quality, automation, and security of their software.

Learn more at www.sonatype.com

The Role

We’re looking for a Data Scientist to join our growing AI & Data Science team. You’ll operate as an internal AI consultant and technical lead, helping multiple teams across Sonatype apply machine learning and generative AI to real-world problems — from malicious-behavior and anomaly detection in our security data, to developer- and analyst-facing GenAI experiences.

You’ll explore complex datasets, design experiments, build and validate models, and collaborate closely with product, engineering, and security experts to turn research ideas into practical, scalable solutions. We have a mature data engineering team, so you can focus on doing what you do best — building and shipping models.

This role is ideal for someone who thrives on autonomy, loves translating ambiguous ideas into working systems, and enjoys working across boundaries rather than staying in a single product lane.

What you’ll do:

  • Lead applied AI projects from concept to impact — prototype, validate, and help teams deploy practical ML and GenAI solutions.

  • Act as an internal consultant across product, engineering, security, and research teams: scope problems, evaluate approaches, and advise on ML/AI best practices and productive use of generative technologies.

  • Lead the research, development, and deployment of models for use cases such as malicious behavior detection, anomaly detection, and fraud analysis — using techniques ranging from classical ML to LLMs, embeddings, retrieval-augmented generation, and agentic workflows.

  • Design robust experiments and establish evaluation pipelines for model reliability, accuracy, and business impact (cross-validation, drift monitoring, ground-truth evaluation).

  • Bridge research and production: translate research insights into scalable APIs, tools, or workflows that enable other teams to adopt AI effectively.

  • Explore new techniques (LLMs, embeddings models, RAG, agentic workflows) to enhance developer and security experiences.

  • Communicate technical concepts, tradeoffs, and recommendations clearly to both technical and non-technical stakeholders through presentations, documentation, and collaboration; mentor peers and help elevate the organization’s AI literacy and capabilities.

  • Partner with our data governance team to ensure compliance with data-privacy regulations and ethical considerations when working with customer data.

What you bring:

  • 5+ years of hands-on experience in applied data science, machine learning, AI engineering, or AI research.

  • Computer Science or equivalent technical degree strongly preferred

  • Strong Python skills and practical experience with data and AI libraries/platforms such as Databricks, and LLM APIs, scikit-learn

  • Experience building and shipping ML or GenAI applications—from early prototype through usable internal or customer-facing workflows.

  • Deep familiarity with modern LLM ecosystems, including OpenAI, Anthropic/Claude, Hugging Face, and open-weight models.

  • Ability to select models and design effective LLM applications using prompting, context management, structured outputs, retrieval, and tool use.

  • Experience building agentic or multi-step AI workflows with LangGraph, LangChain, Semantic Kernel, or similar orchestration frameworks.

  • Strong evaluation mindset: defining useful quality metrics, building representative evaluation datasets, assessing reliability, and making data-driven tradeoffs.

  • Comfortable working with large, messy, structured, and unstructured data to produce features, insights, and clear visualizations.

  • Proficiency with Git, testing, code review, and collaborative software-development practices.

  • Practical, balanced judgment: comfortable exploring emerging AI capabilities while building maintainable, secure, dependable systems.

  • Proactive and accountable, with strong written and verbal communication skills across technical and non-technical partners.

It’d be great if you had:

  • Strong MLOps experience, including MLflow or comparable tooling, experiment tracking, reproducible pipelines, model/application versioning, CI/CD, serving, and production monitoring.

  • Experience operating ML or GenAI systems at scale, including observability, tracing, incident response, and data or model-drift detection.

  • Experience with Databricks ML, AWS SageMaker, Azure ML, or similar managed ML platforms.

  • Familiarity with MCP, agent-tool integrations, LLM guardrails, and production safety practices.

  • Experience with AI-assisted development tools such as Copilot, Claude Code, or Codex.

  • Exposure to cybersecurity, fraud detection, anomaly detection, code analysis, or software supply-chain security.

  • Experience with PySpark and production data pipelines.

  • Experience working within a software product company or SaaS.

Things we’re proud of:

  • 2026 Gartner® Magic Quadrant™ Leader for Software Supply Chain Security
  • 2026 Celebrating 15 Years of Sonatype Research Labs – Industry-leading software supply chain and open source security research
  • 2026 Founding Member of the Linux Foundation Initiative for Open Source Sustainability
  • 2026 State of the Software Supply Chain® Report – Continuing industry leadership in software supply chain security and AI security research
  • 2025 Visionary in Gartner® Magic Quadrant™ for Application Security Testing!
  • 2025 AI Compliance Solution of the Year – AI Breakthrough Awards
  • 2025 DEVIES Award to our SBOM Manager for a new product for its innovation and impact in developer technology
  • 2024 Industry Leader in Forrester-Wave for Software Composition Analysis (2024 Q4 report)
  • Constellation AST Shortlist: Sonatype has been listed on the Constellation ShortList™ for Application Security Testing for 2024
  • Data Breakthrough Awards: Sonatype was announced as a 2024 winner in the “Open Source Data Solution of the Year.”
  • SD Times: Best in Show Security
  • Fast Company Best Workplaces for Innovators 2024
  • The Herd Top 100 Private Software Companies 2024
  • Diversity & Inclusion Working Groups
  • Parental Leave Policy
  • Paid Volunteer Time Off (VTO)

Compensation

Additional Information

At Sonatype, we value diversity and inclusivity. We offer perks such as parental leave, diversity and inclusion working groups, and flexible working practices to allow our employees to show up as their whole selves. We are an equal-opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you have a disability or special need that requires accommodation, please do not hesitate to let us know.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. View safety guidance.

Log in to save
One quick step before you apply

Create your free account, then apply.

Build a more organized job search on Jobicy and continue to the employer's application when you're ready.

  • Never lose a promising opportunitySave roles and return to them from your dashboard.
  • See your entire search at a glanceTrack applications, stages and next steps in one place.
  • Get matched with relevant remote jobsChoose the alerts and digests that work for you.
Applying is free. The employer's application opens in a new tab.
Add alert
Jobs Talent AI Tools Salaries
Menu