SCA -Software Composition Analysis (Hyderabad)

SCA -Software Composition Analysis (Hyderabad)

21 Sep
|
ZettaMine Labs
|
Hyderabad

21 Sep

ZettaMine Labs

Hyderabad

Hello, Greetings from ZettaMine Labs Pvt Ltd!! We are looking for

Software Composition Analysis (SCA) Engineer – Application Security with exciting project opportunities. Job Role:

Software Composition Analysis (SCA) Engineer – Application Security Location:

Hyderabad Notice Period

Immediate / 15 Days Experience:

5–7 Years Relevant Experience:

Strong hands-on experience in

Application Security, Software Composition Analysis (SCA), Open-Source Security, CI/CD Security, Vulnerability Management, License Compliance, and Software Supply Chain Security. Mandatory: 5–7 years of experience in

Application Security / AppSec domains Robust hands-on experience with

Software Composition Analysis (SCA)

solutions Experience with one or more SCA/Application Security tools such as

Black Duck, Mend, Veracode, or Checkmarx Strong experience integrating security tools into

CI/CD pipelines Hands-on experience with

Jenkins, GitHub Actions, and/or GitLab CI Strong understanding of open-source vulnerability management and software supply chain security Experience with vulnerability triage, exploitability analysis, reachability analysis, and risk-based prioritization Experience validating findings and reducing false positives Strong knowledge of

Open-Source License Compliance and Governance Strong understanding of

OWASP Top 10, SSDLC, Application Security, and Vulnerability Management Strong understanding of third-party package ecosystems such as npm, pip, Maven, and Gradle Good programming/scripting experience in multiple languages such as

Java, Python, C++, and Ruby Good-to-Have: Experience with

AI/LLM-focused security scanning tools Exposure to emerging

AI/GenAI Application Security technologies Experience with

Artifactory integration within CI/CD pipelines and developer workflows Experience implementing security guardrails across build and deployment pipelines Knowledge of

Software Bill of Materials (SBOM)

and software supply chain risk management Experience developing and enforcing

Open-Source Software (OSS) governance policies Knowledge of secure coding practices and developer security enablement Experience working with enterprise-scale application security programs Key Responsibilities: Lead the implementation, configuration, and optimization of

Software Composition Analysis (SCA)





solutions across enterprise applications. Identify and manage open-source vulnerabilities, license compliance issues, and software supply chain risks . Establish and maintain processes for managing risks associated with open-source and third-party software dependencies . Integrate and automate

SCA and Application Security tools within CI/CD pipelines. Implement continuous security validation throughout the

Software Development Lifecycle (SDLC) . Configure and manage tools such as

Black Duck, Mend, Veracode, and Checkmarx . Integrate security controls with

Jenkins, GitHub Actions, GitLab CI , and other CI/CD platforms. Work with

Artifactory and developer workflows to strengthen software dependency governance. Analyze vulnerabilities to determine exploitability, reachability, severity, and potential business impact . Perform risk-based prioritization of security findings and focus remediation efforts on critical risks. Validate SCA findings and help reduce false positives to improve vulnerability management effectiveness. Develop, maintain, and enforce

Open-Source Software governance and security policies . Partner with developers and engineering teams to provide secure coding guidance and application security best practices . Educate development teams on dependency management, vulnerability remediation, and secure software development practices. Monitor emerging

AI/LLM-based security scanning technologies and evaluate their applicability to enterprise security. Ensure application security controls are embedded throughout the

SSDLC and software supply chain . Maintain security standards, procedures, documentation, and governance processes related to SCA and OSS security. Collaborate with Security, DevOps, Development, Architecture, and Engineering teams to improve the overall application security posture. Who Can Apply? 5–7 years of strong experience in





Application Security / AppSec . Strong hands-on experience with

Software Composition Analysis (SCA) . Experience with

Black Duck, Mend, Veracode, Checkmarx , or similar SCA/Application Security platforms. Strong experience integrating security tools into

CI/CD pipelines . Hands-on experience with

Jenkins, GitHub Actions, or GitLab CI . Strong understanding of

Open-Source Security and Software Supply Chain Security . Experience in vulnerability triage, exploitability, reachability, risk assessment, and remediation prioritization . Experience with false-positive validation and vulnerability management . Strong knowledge of

Open-Source License Compliance and OSS Governance . Good understanding of

OWASP Top 10, SSDLC, and Application Security best practices . Strong understanding of package ecosystems including npm, pip, Maven, and Gradle . Programming/scripting experience with

Java, Python, C++, Ruby , or similar languages. Experience with

AI/LLM security scanning tools is an added advantage. Experience with

Artifactory and CI/CD security guardrails is preferred. Strong analytical, problem-solving, communication, and stakeholder management skills. Bachelor's degree in

Computer Science, Information Technology, Cybersecurity, Engineering, or a related technical discipline . Candidate Details: Please share the following details along with your updated resume:

[email protected] Full Name: Contact Number: Current Location: Total Experience: Relevant Experience in Application Security: SCA Experience: Black Duck Experience: Mend Experience: Veracode / Checkmarx Experience: CI/CD Security Experience: Jenkins / GitHub Actions / GitLab CI Experience: Vulnerability Management Experience: Exploitability / Reachability Analysis Experience: False Positive Validation Experience: Open-Source License Compliance Experience: OSS Governance Experience: Software Supply Chain Security Experience: OWASP / SSDLC Experience: Java / Python / C++ / Ruby Experience: npm / pip / Maven / Gradle Experience: Artifactory Experience: AI/LLM Security Scanning Experience: SBOM Experience: Current Company: Notice Period: Current CTC: Expected CTC: We look forward to connecting with you!! Thanks and Regards, TAG Team

📌 SCA -Software Composition Analysis (Hyderabad)
🏢 ZettaMine Labs
📍 Hyderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: sca -software composition analysis (hyderabad) / hyderabad

Subscribe to this job alert:

Get the latest job offers by email for: sca -software composition analysis (hyderabad) / hyderabad