Software Composition Analysis: (1 - 3 Years Experience)

Place of work Work from home
Contract type All types
Start date -
Salary -

Job details

Job description, work day and responsibilities

Overview: As a Software Composition Analysis (SCA) Engineer, you will be responsible for ensuring the security, compliance, and integrity of all software components used in our projects. You will identify and address vulnerabilities, enforce licensing rules, and promote secure development practices across our technology stack.

Work Experience: 1 - 3 Years

Job Location: Mumbai

What You Will Do:
• Component Security Analysis: Use SCA tools to scan software codebases including both in-house and third-party/open-source components for vulnerabilities and security risks.
• Vulnerability Assessment: Analyse scan results to determine the severity and urgency of each issue and prioritize fixes.
• License Compliance: Check all software components for compliance with licensing agreements. Advise teams on licensing implications to avoid legal risks.
• SBOM Management: Maintain an accurate Software Bill of Materials (SBOM), tracking all components, versions, and dependencies.
• Collaboration: Work closely with developers to communicate findings, suggest secure alternatives, and assist with remediation.
• Remediation Tracking: Follow up to ensure vulnerabilities are fixed and verify resolutions with follow-up scans.
• Reporting & Documentation: Document all findings, actions, and compliance status. Prepare clear reports for both technical and non-technical stakeholders.
• Continuous Learning: Stay current with the latest trends in software security, open-source risks, and regulatory requirements.
• Training & Improvement: Participate in security meetings and training sessions. Help improve SCA processes and tools based on industry best practices.
• Cross-Functional Coordination: Partner with compliance and legal teams to ensure all software meets regulatory and legal standards.

Key Skills We’re Looking For
• Analytical Skills: Strong ability to analyse, prioritize, and solve complex security issues.
• SCA Tools: Hands-on experience with software composition analysis tools and methodologies.
• DevSecOps: Familiarity with DevSecOps practices and integrating security into CI/CD pipelines.
• Compliance Knowledge: Understanding of regulatory standards such as GDPR, PCI DSS, and others relevant to software development.
• Open-Source Awareness: Basic knowledge of open-source software, including licensing and compliance considerations.
• Communication: Excellent ability to explain technical issues and collaborate with developers, security, and legal teams.
• Organization: Capable of managing multiple tasks and adapting to a fast-paced environment.

Required Qualifications
• Education: Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field.
• Experience: 1–3 years in software development, application security, or a closely related area.
• Certification: Certified Ethical Hacker (CEH) certification is required.

Join our team and contribute to building secure and compliant software solutions through

effective Software Composition Analysis!

The position is suitable for candidates with education

This position is suitable for fresh graduate
Company Name: Security Lit
You will be redirected to another website to apply.
Offer ID: #1242565, Published: 17 hours ago, Company registered: 1 month ago

Other offers

Project Coordinator
2198login
Build your best future with the Johnson Controls team As a global leader in smart, healthy and sustainable buildings, our mission is to reimagine the performance of buildings to serve people, places and the planet. Join ...
Teradata Developer
2198login
About Company : They balance innovation with an open, friendly culture and the backing of a long-established parent company, known for its ethical reputation. We guide customers from what’s now to what’s next by unlockin...
Power BI Consultant / MIS Executive
2198login
• Should be Good with Excel analysis, KPI tracking, dashboarding, Masters, data validations, Trackers, repetitive tasks. • power BI – Good to have • Data crunching from various management dashboard. Send weekly updates t...
Senior Lead Strategy
2198login
Who are we and what do we do? BrowserStack is the world’s leading cloud-based software testing platform, empowering over 50,000 customers—including Amazon, Microsoft, Meta, and Google—to deliver high-quality software at ...
Consultant - Tech Consulting - NAT - CNS - TC - AI and Quantitative Modelling - Mumbai
2198login
Requisition id:1633661 The opportunity EY is looking for Senior Consultant/Consultant Analytics with expertise in one of the industries across: Banking, Insurance, not mandatory. Your key responsibilities • Develop Analy...
Consultant - Tech Consulting - NAT - CNS - TC - AI and Quantitative Modelling - Mumbai
2198login
Requisition id:1633661 The opportunity EY is looking for Senior Consultant/Consultant Analytics with expertise in one of the industries across: Banking, Insurance, not mandatory. Your key responsibilities • Develop Analy...
Consultant - Tech Consulting - NAT - CNS - TC - AI and Quantitative Modelling - Mumbai
2198login
Requisition id:1633661 The opportunity EY is looking for Senior Consultant/Consultant Analytics with expertise in one of the industries across: Banking, Insurance, not mandatory. Your key responsibilities • Develop Analy...
25144634- Associate Manager Security Operations
2198login
Job Description: • * Essential Job Functions: • Support the management of security initiatives under the direction of senior security personnel. • Assist in implementing security policies and standards, collaborating wit...
Lead Fullstack Engineer
2198login
Company Introduction iSchoolConnect is an online platform that maakes the University Admissions process hassle-free, fun and accessible to students around the globe. Using our unique AI technology, we allow students to a...
Need Profiles- Helpdesk Coordinator- Mumbai - (Third Party Payroll)
2198login
· Mumbai, IN
Need replacement profile for helpdesk coordinator at Mumbai office against Karishma Divecha serving notice period having LWD- 22nd August 2025.
React JS Frontend Developer
2198login
About the jobSeeking a skilled React.js developer to build and maintain responsive web applications. You'll collaborate with designers and backend teams to deliver high-quality UI components and seamless user experiences...
Talent Acquisition Intern
2198login
About OML: Only Much Louder Entertainment is a market-leading, full-service creative and entertainment business network that has instigated pop culture for over two decades by creating iconic moments across television, d...
AGM, Global Events Marketing
2198login
Job Role AGM, Global Events Marketing Department Marketing Reports to: Head of Demand Generation Experience Minimum 10 years Location Mumbai About the Role: We are seeking a dynamic and experienced AGM, Global Events Mar...
Pre Sales - Estimation- ELV / fire fighting
2198login
Pre-Sales Estimation Engineer for ELV (Electronic Low Voltage) & Firefighting systems, responsible for , preparing cost estimates, supporting the sales team with technical expertise, ensuring projects are feasible an...