Assignment Title: Open-source Compliance Coordinator
Job title: Open-Source Software Compliance Coordinator
Transport is the core of modern society. Imagine using your expertise to shape sustainable transport and infrastructure solutions for the future. If you seek to make a difference on a global scale, working with the next-gen technologies and the sharpest collaborative teams, then we could be a perfect match.
Role Description
We are looking for a Skilled Open-Source Compliance Coordinator to join our Open-Source Compliance Team within AppSec Platform Security Engineering. We are looking for someone who has a real interest and passion for Open-Source Software Compliance and has a good technical background in application security, especially Software Composition Analysis. Your ability to learn new things, to inspire others around you and your excellent communication skills may be just what we are looking for. This position is based in Bangalore, India, and follows a hybrid working model. The expectation is to work from the office at least 3 days per week (especially during the onboarding), with the remaining days working remotely. The specific days are flexible and can be agreed upon based on what works best for you and the team.
Responsibilities
- Work with the delivery teams on results of Software Composition Analysis scans.
- Provide auditors expertise and know-how to Application delivery teams that use Open- Source software in 2000+ Applications
- Drive all Open-Source Compliance activities
- Collaborate with Open-Source Software Program Lead to solidify Open-Source Software Compliance in Volvo.
- Coordinate source code scans
- Contribute to development and implementation of compliance training and education materials.
- Drive improvements in DevSecOps Transformations in relation to open-source compliance.
- Use tools like Sonatype Lifecycle to identify the OSS used to develop a software product, as well as identifying open-source licenses.
- Support teams out in the Volvo organization in how to analyse, assess, and respond to various internet threats in the open-source domain.
Who You Are
- You have at least 4 years of experience with Open-Source software compliance
- You are a strong communicator that is comfortable working both close to development teams as well as report and inform upper management on the status of open source compliance and vulnerability.
You already
- Have the ability to read and understand open source and commercial license terms and conditions.
- Have the ability to derive an understanding of license obligations.
- High level understanding of Risk acceptance and workflow in case of non-compliant licenses.
- Poeses knowledge in understanding working flow for any of the popular programming language(s)and scripting language(s)
to understand and identify plagiarism of code or logic.
- Should have working knowledge of using any of the SCA tools (Blackduck, Sonatype Lifecycle, MendIO, Revenera codeinsight, FOSSID).
- Should possess understanding of SCA package scanning and snippet scanning
- Should be able to explain and train teams on different categories of open-source licenses.
- Should be able to identify origin open-source of code/package.
- Working knowledge of SBOM generation and review of data within it.
- Clear written communication and oration skills.
- A desire to scale security through education and compliance.
It is an advantage to have
- Solid software engineering experience in one or more general purpose languages and strong experience in IT Architecture.
- Experience with CI/CD pipelines.
- As a positive understanding of application security awareness of OWASP Top 10 vulnerabilities and OWASP ASVS requirements.
- Experience with security maturity models frameworks like OWASP SAMM or BSIMM.
- Experience analyzing and improving products and software security at scale.
- Experience in implementing application security testing processes tools.
- Aware of Cyber Resilience Act (CRA) activities in EU or similar regulations across the world.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Associate III - Cloud Infrastructure Services (Bengaluru)
🏢 UST
📍 Bengaluru