Associate III - Cloud Infrastructure Services (Bengaluru)

Associate III - Cloud Infrastructure Services (Bengaluru)

16 Sep
|
UST
|
Bengaluru

16 Sep

UST

Bengaluru

Role Description

"Assignment Title: Open-source Compliance Coordinator Job title: Open-Source Software Compliance Coordinator Transport is the core of modern society. Imagine using your expertise to shape sustainable transport and infrastructure solutions for the future. If you seek to make a difference on a global scale, working with the next-gen technologies and the sharpest collaborative teams, then we could be a perfect match.

Role Description We are looking for a Professional Open-Source Compliance Coordinator to join our Open-Source Compliance Team within AppSec Platform & Security Engineering. We are looking for someone who has a real interest and passion for Open-Source Software Compliance and has a good technical background in application security, especially Software Composition Analysis. Your ability to learn new things, to inspire others around you and your excellent communication skills may be just what we are looking for.

This position is based in Bangalore, India, and follows a hybrid working model. The expectation is to work from the office at least 3 days per week (especially during the onboarding), with the remaining days working remotely. The specific days are flexible and can be agreed upon based on what works best for you and the team.

You will

- Work with the delivery teams on results of Software Composition Analysis scans.
- Provide auditors ‘expertise and know-how to Application delivery teams that use Open- Source software in 2000+ Applications
- Drive all Open-Source Compliance activities
- Collaborate with Open-Source Software Program Lead to solidify Open-Source Software Compliance in Volvo.
- Coordinate source code scans
- Contribute to development and implementation of compliance training and education materials.
- Drive improvements in DevSecOps Transformations in relation to open-source compliance.
- Use tools like Sonatype lifecycle to identify the OSS used to develop a software product, as well as identifying open-source licenses.
- Support teams out in the Volvo organization in how to analyse, assess, and respond to various internet threats in the open-source domain. Who are you? Your experience:
- You have at least 4 years of experience with Open-Source software compliance




- You are a strong communicator that is comfortable working both close to development teams as well as report and inform upper management on the status of open source compliance and vulnerability. You already:
- Have the ability to read and understand open source and commercial license terms and conditions.
- Have the ability to derive an understanding of license obligations.
- High level understanding of Risk acceptance and workflow in case of non-compliant licenses.
- Posses knowledge in understanding working flow for any of the popular programming language(s)and scripting language(s) to understand and identify plagiarism of code or logic.
- Should have working knowledge of using any of the SCA tools (Blackduck, Sonatype Lifecycle, MendIO, Revenera codeinsight, FOSSID).
- Should possess understanding of SCA package scanning and snippet scanning
- Should be able to explain and train teams on different categories of open-source licenses.
- Should be able to identify origin open-source of code/package.
- Working knowledge of SBOM generation and review of data within it.
- Clear written communication and oration skills.
- A desire to scale security through education and compliance. It is an advantage to have:
- Solid software engineering experience in one or more general purpose languages and solid experience in IT Architecture.
- Experience with CI/CD pipelines.
- As a good understanding of application security awareness of OWASP Top 10 vulnerabilities and OWASP ASVS requirements.
- Experience with security maturity models frameworks like OWASP SAMM or BSIMM.
- Experience analyzing and improving products and software security at scale.
- Experience in implementing application security testing processes & tools.
- Aware of Cyber Resilience Act (CRA) activities in EU or similar regulations across the world. What´s in it for you?
- Application security is an area of growing importance.



While we can´t offer you an effortless job, we can offer you a chance to be part of an exciting, growing and evolving domain.
- We are ready to help you develop and gain experience in areas you need to be a successful Open-Source Compliance Coordinator.
- Our team is fun to work with, diverse and we are all passionate about developing, supporting and helping others in many aspects of software development. We value your data privacy and therefore do not accept applications via mail.

Why Join

Us?

- Be part of building and evolving the organization’s AppSec platform capabilities
- Work with modern DevSecOps and cloud technologies in a security-focused environment
- Opportunity to influence both technical direction and team ways of working
- A collaborative culture focused on learning, innovation, and continuous improvement
- Flexibility to shape your growth path based on your strengths and ambitions
- Supportive leadership committed to professional development and empowerment Who we are and what we believe in We are committed to shaping the future landscape of efficient, safe, and sustainable transport solutions. Fulfilling our mission creates countless career opportunities for talents across the group´s leading brands and entities. Applying for this job offers you the opportunity to join Volvo Group.

Every day, you will be working with some of the sharpest and most creative brains in our field to be able to leave our society in better shape for the next generation. We are passionate about what we do, and we thrive on teamwork. We are almost 100.000 people united around the world by culture of care, inclusiveness, and empowerment.

Digital

Technology and Operations is the hub for digital development within Volvo Group. Imagine yourself working with cutting-edge technologies in a global team, represented in more than 30 countries. We are dedicated to leading the way of tomorrow´s transport solutions, guided by a strong customer mindset and high level of curiosity, both as individuals and as a team. Here, you will thrive in your career in an environment where your voice is heard and your ideas matter."

Skills Security Awareness, Risk Management, Compliance Management, Vulnerability Assessment

📌 Associate III - Cloud Infrastructure Services (Bengaluru)
🏢 UST
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: associate iii - cloud infrastructure services (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: associate iii - cloud infrastructure services (bengaluru) / bengaluru