Hello,
Greetings from ZettaMine Labs Pvt Ltd!!
We are looking for Software Composition Analysis (SCA) Engineer – Application Security with exciting project opportunities.
Job Role: Software Composition Analysis (SCA) Engineer – Application Security
Location: Hyderabad
Notice Period: Immediate / 15 Days
Experience: 5–7 Years
Relevant Experience: Strong hands-on experience in Application Security, Software Composition Analysis (SCA), Open-Source Security, CI/CD Security, Vulnerability Management, License Compliance, and Software Supply Chain Security.
Mandatory:
- 5–7 years of experience in Application Security / AppSec domains
- Strong hands-on experience with Software Composition Analysis (SCA) solutions
- Experience with one or more SCA/Application Security tools such as Black Duck, Mend, Veracode, or Checkmarx
- Strong experience integrating security tools into CI/CD pipelines
- Hands-on experience with Jenkins, GitHub Actions, and/or GitLab CI
- Strong understanding of open-source vulnerability management and software supply chain security
- Experience with vulnerability triage, exploitability analysis, reachability analysis, and risk-based prioritization
- Experience validating findings and reducing false positives
- Solid knowledge of Open-Source License Compliance and Governance
- Strong understanding of OWASP Top 10, SSDLC, Application Security, and Vulnerability Management
- Strong understanding of third-party package ecosystems such as npm, pip, Maven, and Gradle
- Good programming/scripting experience in multiple languages such as Java, Python, C++, and Ruby
Good-to-Have:
- Experience with AI/LLM-focused security scanning tools
- Exposure to emerging AI/GenAI Application Security technologies
- Experience with Artifactory integration within CI/CD pipelines and developer workflows
- Experience implementing security guardrails across build and deployment pipelines
- Knowledge of Software Bill of Materials (SBOM) and software supply chain risk management
- Experience developing and enforcing Open-Source Software (OSS) governance policies
- Knowledge of secure coding practices and developer security enablement
- Experience working with enterprise-scale application security programs
Key Responsibilities:
- Lead the implementation, configuration, and optimization of Software Composition Analysis (SCA)
solutions across enterprise applications.
- Identify and manage open-source vulnerabilities, license compliance issues, and software supply chain risks.
- Establish and maintain processes for managing risks associated with open-source and third-party software dependencies.
- Integrate and automate SCA and Application Security tools within CI/CD pipelines.
- Implement continuous security validation throughout the Software Development Lifecycle (SDLC).
- Configure and manage tools such as Black Duck, Mend, Veracode, and Checkmarx.
- Integrate security controls with Jenkins, GitHub Actions, GitLab CI, and other CI/CD platforms.
- Work with Artifactory and developer workflows to strengthen software dependency governance.
- Analyze vulnerabilities to determine exploitability, reachability, severity, and potential business impact.
- Perform risk-based prioritization of security findings and focus remediation efforts on critical risks.
- Validate SCA findings and help reduce false positives to improve vulnerability management effectiveness.
- Develop, maintain, and enforce Open-Source Software governance and security policies.
- Partner with developers and engineering teams to provide secure coding guidance and application security best practices.
- Educate development teams on dependency management, vulnerability remediation, and secure software development practices.
- Monitor emerging AI/LLM-based security scanning technologies and evaluate their applicability to enterprise security.
- Ensure application security controls are embedded throughout the SSDLC and software supply chain.
- Maintain security standards, procedures, documentation, and governance processes related to SCA and OSS security.
- Collaborate with Security, DevOps, Development, Architecture, and Engineering teams to improve the overall application security posture.
Who Can Apply? ✔️ 5–7 years of strong experience in Application Security / AppSec.
✔️ Strong hands-on experience with Software Composition Analysis (SCA).
✔️ Experience with Black Duck, Mend, Veracode, Checkmarx, or similar SCA/Application Security platforms.
✔️ Strong experience integrating security tools into CI/CD pipelines.
✔️ Hands-on experience with Jenkins, GitHub Actions, or GitLab CI.
✔️ Solid understanding of Open-Source Security and Software Supply Chain Security.
✔️ Experience in vulnerability triage, exploitability, reachability, risk assessment, and remediation prioritization.
✔️ Experience with false-positive validation and vulnerability management.
✔️ Strong knowledge of Open-Source License Compliance and OSS Governance.
✔️ Good understanding of OWASP Top 10, SSDLC, and Application Security best practices.
✔️ Strong understanding of package ecosystems including npm, pip, Maven, and Gradle.
✔️ Programming/scripting experience with Java, Python, C++, Ruby, or similar languages.
✔️ Experience with AI/LLM security scanning tools is an added advantage.
✔️ Experience with Artifactory and CI/CD security guardrails is preferred.
✔️ Strong analytical, problem-solving, communication, and stakeholder management skills.
✔️ Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related technical discipline.
Candidate Details:
Please share the following details along with your updated resume:
[email protected]
Full Name:
Contact Number:
Current Location:
Total Experience:
Relevant Experience in Application Security:
SCA Experience:
Black Duck Experience:
Mend Experience:
Veracode / Checkmarx Experience:
CI/CD Security Experience:
Jenkins / GitHub Actions / GitLab CI Experience:
Vulnerability Management Experience:
Exploitability / Reachability Analysis Experience:
False Positive Validation Experience:
Open-Source License Compliance Experience:
OSS Governance Experience:
Software Supply Chain Security Experience:
OWASP / SSDLC Experience:
Java / Python / C++ / Ruby Experience:
npm / pip / Maven / Gradle Experience:
Artifactory Experience:
AI/LLM Security Scanning Experience:
SBOM Experience:
Current Company:
Notice Period:
Current CTC:
Expected CTC:
We look forward to connecting with you!!
Thanks and Regards,
TAG Team
📌 SCA -Software Composition Analysis (Hyderabad)
🏢 ZettaMine Labs
📍 Hyderabad