Vulnerability Analyst (Hyderabad)

Vulnerability Analyst (Hyderabad)

08 Aug
|
Purview Services
|
Hyderabad

08 Aug

Purview Services

Hyderabad

Role: FOSS Sonatype IQ SME

Location: Hyderabad, Pune, Bangalore

Exp:9+

Job Description:

Key Responsibilities:

- Serve as the primary advisor and technical expert for Sonatype Nexus IQ Server and open-source dependency vulnerability scanning.
- Implement and maintain Sonatype IQ integrations within CI/CD pipelines to automate security and compliance checks.
- Analyze and remediate vulnerabilities, license risks, and policy violations in open-source dependencies.
- Develop and enforce software composition analysis (SCA) best practices across development teams.
- Collaborate with security teams to prioritize and mitigate OSS vulnerabilities based on risk assessments.
- Create and maintain custom policy configurations in Sonatype IQ to align with organizational security standards.
- Train and mentor engineering teams on secure OSS usage, dependency management, and DevSecOps best practices.
- Work to uplift the vulnerability scanning and remediation capabilities to meet enhanced Service Level Agreements (SLAs), ensuring timely and effective resolution of security vulnerabilities
- Monitor and report on FOSS risk metrics, providing actionable insights to leadership.
- Stay updated on emerging software supply chain threats and recommend proactive security measures.
- Support SBOM interlock and proactively participate in wider SBOM program.
- To perform security assessment and identify potential risk with open source LLMs.





Required Skills & Qualifications:

- 4+ years of hands-on experience with Sonatype Nexus IQ Server in an enterprise environment.
- Strong understanding of Software Development Life Cycle (SDLC) with a focus on security.
- Strong expertise in open-source Software security, vulnerability management, and license compliance.
- Proficiency in DevSecOps practices, including CI/CD integration (Jenkins, GitLab, GitHub Actions, etc.)
- Experience with software composition analysis (SCA) tools and dependency management (Maven, npm, pip, etc.)
- Knowledge of OWASP Top 10, CVE, and MITRE ATT&CK; frameworks related to OSS risks.
- Familiarity with container security (Docker, Kubernetes) and SBOM (Software Bill of Materials) generation.
- Valuable to have scripting skills (Bash, Python, Groovy) for automation and tool customization.
- Excellent communication skills, with the ability to explain complex security concepts to non-technical stakeholders.

Education & Experience:

- 7+ years of experience into cybersecurity, Information security or security engineering.
- Strong DevSecOps and Software security background.
- Desirable to have one or more industry-recognised cybersecurity-related certifications including CISSP, CRISC, CISM, OSCP.
- Bachelor or Masters degree in Computer Science, Information Technology, Cybersecurity or equivalent.

📌 Vulnerability Analyst (Hyderabad)
🏢 Purview Services
📍 Hyderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: vulnerability analyst (hyderabad) / hyderabad