Source description
About the role
You will own application and open-source security quality assurance, focusing on Software Composition Analysis (SCA) and vulnerability management. You integrate SCA tools into CI/CD pipelines and drive remediation tracking for open-source vulnerabilities. ResponsibilitiesPerform vulnerability triage and license compliance analysis for open-source components.Integrate Black Duck or equivalent SCA tools into CI/CD pipelines (GitHub, GitLab, Azure DevOps, Jenkins).Track and coordinate remediation efforts for identified security vulnerabilities.Validate secure SDLC practices and DevSecOps implementations across cloud platforms.Ensure compliance with application security standards through rigorous QA processes.Required Skills58 years of experience in Application Security, Security QA, or Software Security.Hands-on expertise with Black Duck or equivalent SCA tools (CodeDx, JFrog Xray, FOSSA).Proven experience in OSS vulnerability analysis and license compliance.Strong knowledge of CI/CD integration for security tooling.Understanding of Secure SDLC and DevSecOps practices.Familiarity with cloud platforms (AWS, Azure, GCP). You will own application and open-source security quality assurance, focusing on Software Composition Analysis (SCA) and vulnerability management. You integrate SCA tools into CI/CD pipelines and drive remediation tracking for open-source vulnerabilities. ResponsibilitiesPerform vulnerability triage and license compliance analysis for open-source components.Integrate Black Duck or equivalent SCA tools into CI/CD pipelines (GitHub, GitLab, Azure DevOps, Jenkins).Track and coordinate remediation efforts for identified security vulnerabilities.Validate secure SDLC practices and DevSecOps implementations across cloud platforms.Ensure compliance with application security standards through rigorous QA processes.Required Skills58 years of experience in Application Security, Security QA, or Software Security.Hands-on expertise with Black Duck or equivalent SCA tools (CodeDx, JFrog Xray, FOSSA).Proven experience in OSS vulnerability analysis and license compliance.Strong knowledge of CI/CD integration for security tooling.Understanding of Secure SDLC and DevSecOps practices.Familiarity with cloud platforms (AWS, Azure, GCP).
More at IIT JOBS INC
Related open roles
GCP Data Engineer - Onsite - Bangalore
Bangalore
JAVA Technical Coach - @Bangalore
Bangalore
software development II Full Stack (Java/React) (Karnataka)
India
Salesforce Administrator with Pardot/MCAE (Delhi)
Delhi NCR
Application Tester (Manual QA)
Mumbai
System Engineering- Network security + Check Point (Full-time opportunity)
Mumbai