Sr. SCA Engineer (Hyderabad)

Sr. SCA Engineer (Hyderabad)

08 Sep
|
Zettamine Labs
|
Hyderabad

08 Sep

Zettamine Labs

Hyderabad

Hello,

Greetings from ZettaMine Labs Pvt Ltd!!

We are looking for Sr. SCA Engineer with project opportunities.

Job Role: Sr. SCA Engineer

Location: Hyderabad (Madhapur)

Experience: 57 Years

Relevant Experience: Minimum 5 Years in Application Security with strong expertise in Software Composition Analysis (SCA), Software Supply Chain Security, CI/CD Security, and Vulnerability Management.

Mandatory: Application Security + SCA + Software Supply Chain Security + CI/CD + Black Duck/Mend/Veracode/Checkmarx + Vulnerability Management + Jenkins/GitHub Actions/GitLab CI + Open-Source Governance + OWASP Top 10 + SSDLC + Java/Python/C++/Ruby

REQUIREMENT FOR SR. SCA ENGINEER:

Key Responsibilities:

- Lead the implementation and optimization of Software Composition Analysis (SCA) solutions to identify vulnerabilities, license compliance issues, and software supply chain risks.
- Establish and maintain processes for managing risks associated with open-source and third-party software dependencies.
- Integrate and automate SCA and Application Security tools within CI/CD pipelines to provide continuous security validation throughout the SDLC.
- Deploy, configure, and manage security platforms such as Black Duck, Mend, Veracode, and Checkmarx.
- Explore and evaluate emerging AI/LLM-based security scanning solutions.
- Embed security guardrails into build pipelines using Jenkins, GitHub Actions, and GitLab CI.
- Integrate Artifactory with CI/CD pipelines and developer workflows where required.
- Analyze identified vulnerabilities to determine exploitability, reachability, severity, and business impact.
- Perform risk-based prioritization of security findings and drive remediation of high-impact vulnerabilities.
- Validate security findings to reduce false positives and improve vulnerability management effectiveness.
- Develop, maintain,



and enforce Open-Source Software Governance and License Compliance policies.
- Partner with developers and engineering teams to triage vulnerabilities and provide secure coding guidance and best practices.
- Embed security controls throughout the Secure Software Development Lifecycle (SSDLC).
- Monitor evolving application security threats and technologies and recommend improvements to the organization's security posture.

Who Can Apply?

5–7 years of experience across various Application Security domains.

Strong hands-on experience with Software Composition Analysis (SCA) and software supply chain security.

Experience integrating SCA and security tools into CI/CD pipelines.

Experience with one or more tools such as Black Duck, Mend, Veracode, or Checkmarx.

Experience with Jenkins, GitHub Actions, or GitLab CI.

Experience with Artifactory integration is an advantage.

Strong understanding of vulnerability exploitability, reachability analysis, risk prioritization, and false-positive validation.

Strong knowledge of Open-Source Software Governance and License Compliance.

Strong programming experience in multiple languages including Java, Python, C++, and Ruby.

Strong understanding of third-party package ecosystems such as npm, pip, Maven, and Gradle.

Strong knowledge of OWASP Top 10, SSDLC, Software Supply Chain Security, and Vulnerability Management.

Excellent communication, analytical, and problem-solving skills.

Self-motivated with a strong commitment to continuous learning and evolving security technologies.

Valuable to Have:





- Experience with AI/LLM-focused security scanning tools.
- Experience with emerging Application Security technologies.
- Hands-on Artifactory and developer workflow integration.
- Experience implementing enterprise-scale Software Supply Chain Security programs.
- Knowledge of open-source license compliance and dependency governance.

Key Security Areas:

- Software Composition Analysis (SCA)
- Software Supply Chain Security
- Open-Source Security
- Dependency Management
- Vulnerability Management
- License Compliance
- CI/CD Security
- Secure SDLC / SSDLC
- Application Security
- Risk-Based Vulnerability Prioritization
- Exploitability & Reachability Analysis
- AI/LLM Security Scanning

Tools & Technologies:

- Black Duck
- Mend
- Veracode
- Checkmarx
- Jenkins
- GitHub Actions
- GitLab CI
- Artifactory
- npm
- pip
- Maven
- Gradle

Programming Languages:

- Java
- Python
- C++
- Ruby

Education:

- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related technical discipline.

Please share the following details along with your updated resume:

Full Name:

Contact Number:

Current Location:

Total Experience:

Relevant Application Security Experience:

SCA Experience:

Software Supply Chain Security Experience:

Black Duck/Mend Experience:

Veracode/Checkmarx Experience:

CI/CD Security Experience:

Jenkins/GitHub Actions/GitLab CI Experience:

Artifactory Experience:

Vulnerability Management Experience:

Open-Source Governance Experience:

AI/LLM Security Experience:

Programming Languages:

npm/pip/Maven/Gradle Experience:

OWASP/SSDLC Experience:

Current Company:

Notice Period:

Current CTC:

Expected CTC:

For any further clarification, feel free to reach out at [email protected].

We look forward to connecting with you!

📌 Sr. SCA Engineer (Hyderabad)
🏢 Zettamine Labs
📍 Hyderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: sr. sca engineer (hyderabad) / hyderabad