13 Sep
|
Cloudxtreme
|
Hyderabad
13 Sep
Cloudxtreme
Hyderabad
Role & responsibilities
Primary mandate skill required
SCA tool expertise (Snyk, JFrog Xray, WhiteSource, Black Duck, or equivalent), software composition analysis (SCA) tools and open source vulnerability management, Proficiency in at least one programming language (Java, Python, Go, C#, JavaScript, or similar), Familiarity with open source package managers and ecosystems (npm, Maven, pip, NuGet, or similar), Basic understanding of CI/CD pipelines and DevOps practices
Secondary mandate skill required.
Advanced CI/CD pipeline design and configuration, Open source ecosystem knowledge, Dependency management and package managers.
Preferred candidate profile
Detailed Job Description –
Junior to Intermediate Application Security Engineer responsible for triaging and managing open-source vulnerabilities identified through Software Composition Analysis (SCA). The role involves validating CVEs, handling false positives, prioritizing remediation using CVSS/risk-based approaches, and working closely with development and DevOps teams to fix vulnerable dependencies. Candidates should have 2–4 years of experience in application security or DevOps, hands-on exposure to SCA tools (Snyk, JFrog Xray, Black Duck, etc.), understanding of CI/CD pipelines, and proficiency in at least one programming language (Java, Python, JavaScript, Go, or C#).
📌 Application Security Engineer Hyderabad
🏢 Cloudxtreme
📍 Hyderabad