About the Company
UST is a global digital transformation, AI, and IT consulting services provider. For more than 20 years, UST has worked side by side with the world’s best companies to make a real impact through transformation. Powered by technology, inspired by people and led by purpose, UST partners with their clients from design to operation.
The company builds end-to-end tech solutions, specializing in advanced data & analytics, cloud modernization, generative AI agent frameworks, cybersecurity, and advanced engineering/R&D.; With deep domain expertise and a future-proof philosophy, UST embeds innovation and agility into their clients’ organizations. With over 30K+ employees in 30+ countries, UST builds a boundless impact—touching billions of lives in the process.
Website https://www.ust.com/
Open Source Compliance Coordinator
? Bangalore | ?️ Application Security
We are looking for an experienced Open Source Compliance Coordinator who has a real interest and passion for Open-Source Software Compliance and has a good technical background in application security, especially Software Composition Analysis.
Key Responsibilities:
- Drive Open Source Software Compliance activities across applications.
- Analyze and manage Software Composition Analysis (SCA) scan results.
- Support development teams in license compliance, vulnerability management, and OSS governance.
- Coordinate source code, package,
and snippet scans.
- Review and validate SBOMs and license obligations.
- Conduct compliance awareness sessions and training programs.
- Collaborate with AppSec, DevSecOps, Engineering, and Audit teams to strengthen OSS compliance practices.
Required Skills:
- 4+ years of experience in Open Source Software Compliance.
- Strong communicator with comfortable working both close to development teams as well as report and inform upper management on the status of Open Source Compliance and Vulnerability.
- Posses knowledge in understanding working flow for any of the popular programming language(s)and scripting language(s) to understand and identify plagiarism of code or logic.
- Hands-on experience with SCA tools such as BlackDuck, Sonatype Lifecycle, Mend.io, Revenera Code Insight, or FOSSID .
- Solid understanding of open-source licenses, compliance obligations, and risk management.
- Experience with package scanning, snippet scanning, and SBOM generation/review.
- Knowledge of Application Security and DevSecOps practices.
- Excellent communication and stakeholder management skills.
Good to Have
- Experience with CI/CD pipelines.
- Knowledge of OWASP Top 10, OWASP ASVS, SAMM, or BSIMM.
- Understanding of Cyber Resilience Act (CRA) or related compliance regulations.
- Software development or architecture background.
📌 OSS Compliance Specialist (Bengaluru)
🏢 UST
📍 Bengaluru