21 Sep
|
ZettaMine Labs
|
Hyderabad
21 Sep
ZettaMine Labs
Hyderabad
Hello,
Greetings from ZettaMine Labs Pvt Ltd!!
We are looking for Software Composition Analysis (SCA) Engineer – Application Security with exciting project opportunities.
Job Role: Software Composition Analysis (SCA) Engineer – Application Security
Location: Hyderabad
Notice Period: Immediate / 15 Days
Experience: 5–7 Years
Relevant Experience: Strong hands-on experience in Application Security, Software Composition Analysis (SCA), Open-Source Security, CI/CD Security, Vulnerability Management, License Compliance, and Software Supply Chain Security.
Mandatory:
5–7 years of experience in Application Security / AppSec domains
Strong hands-on experience with Software Composition Analysis (SCA) solutions
Experience with one or more SCA/Application Security tools such as Black Duck, Mend, Veracode, or Checkmarx
Strong experience integrating security tools into CI/CD pipelines
Hands-on experience with Jenkins, GitHub Actions, and/or GitLab CI
Strong understanding of open-source vulnerability management and software supply chain security
Experience with vulnerability triage, exploitability analysis, reachability analysis, and risk-based prioritization
Experience validating findings and reducing false positives
Robust knowledge of Open-Source License Compliance and Governance
Strong understanding of OWASP Top 10, SSDLC, Application Security, and Vulnerability Management
Strong understanding of third-party package ecosystems such as npm, pip, Maven, and Gradle
Good programming/scripting experience in multiple languages such as Java, Python, C++, and Ruby
Good-to-Have:
Experience with AI/LLM-focused security scanning tools
Exposure to emerging AI/GenAI Application Security technologies
Experience with Artifactory integration within CI/CD pipelines and developer workflows
Experience implementing security guardrails across build and deployment pipelines
Knowledge of Software Bill of Materials (SBOM) and software supply chain risk management
Experience developing and enforcing Open-Source Software (OSS) governance policies
Knowledge of secure coding practices and developer security enablement
Experience working with enterprise-scale application security programs
Key Responsibilities:
Lead the implementation, configuration, and optimization of Software Composition Analysis (SCA)
solutions across enterprise applications.
Identify and manage open-source vulnerabilities, license compliance issues, and software supply chain risks .
Establish and maintain processes for managing risks associated with open-source and third-party software dependencies .
Integrate and automate SCA and Application Security tools within CI/CD pipelines.
Implement continuous security validation throughout the Software Development Lifecycle (SDLC) .
Configure and manage tools such as Black Duck, Mend, Veracode, and Checkmarx .
Integrate security controls with Jenkins, GitHub Actions, GitLab CI , and other CI/CD platforms.
Work with Artifactory and developer workflows to strengthen software dependency governance.
Analyze vulnerabilities to determine exploitability, reachability, severity, and potential business impact .
Perform risk-based prioritization of security findings and focus remediation efforts on critical risks.
Validate SCA findings and help reduce false positives to improve vulnerability management effectiveness.
Develop, maintain, and enforce Open-Source Software governance and security policies .
Partner with developers and engineering teams to provide secure coding guidance and application security best practices .
Educate development teams on dependency management, vulnerability remediation, and secure software development practices.
Monitor emerging AI/LLM-based security scanning technologies and evaluate their applicability to enterprise security.
Ensure application security controls are embedded throughout the SSDLC and software supply chain .
Maintain security standards, procedures, documentation, and governance processes related to SCA and OSS security.
Collaborate with Security, DevOps, Development, Architecture, and Engineering teams to improve the overall application security posture.
Who Can Apply?
✔️ 5–7 years of strong experience in Application Security / AppSec .
✔️ Strong hands-on experience with Software Composition Analysis (SCA) .
✔️ Experience with Black Duck, Mend, Veracode, Checkmarx , or similar SCA/Application Security platforms.
✔️ Strong experience integrating security tools into CI/CD pipelines .
✔️ Hands-on experience with Jenkins, GitHub Actions, or GitLab CI .
✔️ Strong understanding of Open-Source Security and Software Supply Chain Security .
✔️ Experience in vulnerability triage, exploitability, reachability, risk assessment, and remediation prioritization .
✔️ Experience with false-positive validation and vulnerability management .
✔️ Strong knowledge of Open-Source License Compliance and OSS Governance .
✔️ Good understanding of OWASP Top 10, SSDLC, and Application Security best practices .
✔️ Strong understanding of package ecosystems including npm, pip, Maven, and Gradle .
✔️ Programming/scripting experience with Java, Python, C++, Ruby , or similar languages.
✔️ Experience with AI/LLM security scanning tools is an added advantage.
✔️ Experience with Artifactory and CI/CD security guardrails is preferred.
✔️ Strong analytical, problem-solving, communication, and stakeholder management skills.
✔️ Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related technical discipline .
Candidate Details:
Please share the following details along with your updated resume:
Full Name:
Contact Number:
Current Location:
Total Experience:
Relevant Experience in Application Security:
SCA Experience:
Black Duck Experience:
Mend Experience:
Veracode / Checkmarx Experience:
CI/CD Security Experience:
Jenkins / GitHub Actions / GitLab CI Experience:
Vulnerability Management Experience:
Exploitability / Reachability Analysis Experience:
False Positive Validation Experience:
Open-Source License Compliance Experience:
OSS Governance Experience:
Software Supply Chain Security Experience:
OWASP / SSDLC Experience:
Java / Python / C++ / Ruby Experience:
npm / pip / Maven / Gradle Experience:
Artifactory Experience:
AI/LLM Security Scanning Experience:
SBOM Experience:
Current Company:
Notice Period:
Current CTC:
Expected CTC:
We look forward to connecting with you!!
Thanks and Regards,
TAG Team
📌 SCA -Software Composition Analysis (Hyderabad)
🏢 ZettaMine Labs
📍 Hyderabad