SCA -Software Composition Analysis (Hyderabad)

SCA -Software Composition Analysis (Hyderabad)

19 Sep
|
ZettaMine Labs
|
Hyderabad

19 Sep

ZettaMine Labs

Hyderabad

Hello,

Greetings from ZettaMine Labs Pvt Ltd!!

We are looking for Software Composition Analysis (SCA) Engineer – Application Security with exciting project opportunities.

Job Role: Software Composition Analysis (SCA) Engineer – Application Security

Location: Hyderabad

Notice Period: Immediate / 15 Days

Experience: 5–7 Years

Relevant Experience: Strong hands-on experience in Application Security, Software Composition Analysis (SCA), Open-Source Security, CI/CD Security, Vulnerability Management, License Compliance, and Software Supply Chain Security.

Mandatory:

- 5–7 years of experience in Application Security / AppSec domains
- Strong hands-on experience with Software Composition Analysis (SCA) solutions
- Experience with one or more SCA/Application Security tools such as Black Duck, Mend, Veracode, or Checkmarx
- Strong experience integrating security tools into CI/CD pipelines
- Hands-on experience with Jenkins, GitHub Actions, and/or GitLab CI
- Strong understanding of open-source vulnerability management and software supply chain security
- Experience with vulnerability triage, exploitability analysis, reachability analysis, and risk-based prioritization
- Experience validating findings and reducing false positives
- Solid knowledge of Open-Source License Compliance and Governance
- Strong understanding of OWASP Top 10, SSDLC, Application Security, and Vulnerability Management
- Strong understanding of third-party package ecosystems such as npm, pip, Maven, and Gradle
- Good programming/scripting experience in multiple languages such as Java, Python, C++, and Ruby

Good-to-Have:

- Experience with AI/LLM-focused security scanning tools
- Exposure to emerging AI/GenAI Application Security technologies
- Experience with Artifactory integration within CI/CD pipelines and developer workflows
- Experience implementing security guardrails across build and deployment pipelines
- Knowledge of Software Bill of Materials (SBOM) and software supply chain risk management
- Experience developing and enforcing Open-Source Software (OSS) governance policies
- Knowledge of secure coding practices and developer security enablement
- Experience working with enterprise-scale application security programs

Key Responsibilities:

- Lead the implementation, configuration, and optimization of Software Composition Analysis (SCA)



solutions across enterprise applications.
- Identify and manage open-source vulnerabilities, license compliance issues, and software supply chain risks.
- Establish and maintain processes for managing risks associated with open-source and third-party software dependencies.
- Integrate and automate SCA and Application Security tools within CI/CD pipelines.
- Implement continuous security validation throughout the Software Development Lifecycle (SDLC).
- Configure and manage tools such as Black Duck, Mend, Veracode, and Checkmarx.
- Integrate security controls with Jenkins, GitHub Actions, GitLab CI, and other CI/CD platforms.
- Work with Artifactory and developer workflows to strengthen software dependency governance.
- Analyze vulnerabilities to determine exploitability, reachability, severity, and potential business impact.
- Perform risk-based prioritization of security findings and focus remediation efforts on critical risks.
- Validate SCA findings and help reduce false positives to improve vulnerability management effectiveness.
- Develop, maintain, and enforce Open-Source Software governance and security policies.
- Partner with developers and engineering teams to provide secure coding guidance and application security best practices.
- Educate development teams on dependency management, vulnerability remediation, and secure software development practices.
- Monitor emerging AI/LLM-based security scanning technologies and evaluate their applicability to enterprise security.
- Ensure application security controls are embedded throughout the SSDLC and software supply chain.
- Maintain security standards, procedures, documentation, and governance processes related to SCA and OSS security.
- Collaborate with Security, DevOps, Development, Architecture, and Engineering teams to improve the overall application security posture.

Who Can Apply? ✔️ 5–7 years of strong experience in Application Security / AppSec.





✔️ Strong hands-on experience with Software Composition Analysis (SCA).

✔️ Experience with Black Duck, Mend, Veracode, Checkmarx, or similar SCA/Application Security platforms.

✔️ Strong experience integrating security tools into CI/CD pipelines.

✔️ Hands-on experience with Jenkins, GitHub Actions, or GitLab CI.

✔️ Solid understanding of Open-Source Security and Software Supply Chain Security.

✔️ Experience in vulnerability triage, exploitability, reachability, risk assessment, and remediation prioritization.

✔️ Experience with false-positive validation and vulnerability management.

✔️ Strong knowledge of Open-Source License Compliance and OSS Governance.

✔️ Good understanding of OWASP Top 10, SSDLC, and Application Security best practices.

✔️ Strong understanding of package ecosystems including npm, pip, Maven, and Gradle.

✔️ Programming/scripting experience with Java, Python, C++, Ruby, or similar languages.

✔️ Experience with AI/LLM security scanning tools is an added advantage.

✔️ Experience with Artifactory and CI/CD security guardrails is preferred.

✔️ Strong analytical, problem-solving, communication, and stakeholder management skills.

✔️ Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related technical discipline.

Candidate Details:

Please share the following details along with your updated resume: [email protected]

Full Name:

Contact Number:

Current Location:

Total Experience:

Relevant Experience in Application Security:

SCA Experience:

Black Duck Experience:

Mend Experience:

Veracode / Checkmarx Experience:

CI/CD Security Experience:

Jenkins / GitHub Actions / GitLab CI Experience:

Vulnerability Management Experience:

Exploitability / Reachability Analysis Experience:

False Positive Validation Experience:

Open-Source License Compliance Experience:

OSS Governance Experience:

Software Supply Chain Security Experience:

OWASP / SSDLC Experience:

Java / Python / C++ / Ruby Experience:

npm / pip / Maven / Gradle Experience:

Artifactory Experience:

AI/LLM Security Scanning Experience:

SBOM Experience:

Current Company:

Notice Period:

Current CTC:

Expected CTC:

We look forward to connecting with you!!

Thanks and Regards,

TAG Team

📌 SCA -Software Composition Analysis (Hyderabad)
🏢 ZettaMine Labs
📍 Hyderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: sca -software composition analysis (hyderabad) / hyderabad

Subscribe to this job alert:

Get the latest job offers by email for: sca -software composition analysis (hyderabad) / hyderabad