





Niche AppSec SCA specialization and seniority reduce applicant density despite Hyderabad metro location.
Role requires specific AppSec tooling, SBOM, and CI/CD security experience, limiting cross-industry transferability.
Explicit 8–10 years requirement plus mandatory SCA/artifact-tool expertise raises shortlisting strictness.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Own and drive the Software Composition Analysis (SCA) program end-to-end, managing vulnerability and license risks in open-source and third-party dependencies.
Configure and optimize artifact repositories and package registries with embedded SCA scanning, enforce dependency governance policies, and maintain Software Bill of Materials (SBOM).
Integrate and manage SAST and DAST tools within CI/CD pipelines, triage vulnerabilities, and collaborate with development teams to embed security in the SDLC.
8 to 10 years of relevant experience in Application Security, DevSecOps, or related field.
Hands-on experience with at least 2-3 artifact repository/package registry tools such as JFrog Artifactory, Sonatype Nexus, Azure Artifacts, GitHub Packages, GitLab Package Registry, AWS CodeArtifact, or Google Artifact Registry.
Working knowledge of SAST and DAST tools (e.g., Veracode, Checkmarx, HCL AppScan, SonarQube, Invicti, Acunetix, OWASP ZAP).
Bachelor's degree in Computer Science, Information Security, or related field, or equivalent practical experience.
Proven expertise in managing open-source and third-party dependency security at scale within product development environments.
Experience working collaboratively across Development, DevOps, and QA teams to operationalize security practices and policies within Agile/DevOps frameworks.
Strong technical proficiency with integrating and optimizing security tools in CI/CD pipelines and familiarity with vulnerability management workflows.