





Niche SCA and AppSec tooling requirement plus seniority reduces applicant competition significantly.
Core AppSec and DevSecOps skills are broadly transferable across industries, not healthcare-specific.
Explicit 8-10 years requirement and mandatory hands-on SCA/artifact-repository tool experience increases filter strictness.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Lead and manage the Software Composition Analysis (SCA) program end-to-end, including vulnerability and license risk identification, tracking, and remediation for open-source and third-party components.
Configure, optimize, and maintain artifact repositories and package registries with embedded SCA scanning and policy enforcement; establish governance policies across engineering teams.
Integrate and manage SAST and DAST security tools in CI/CD pipelines, conduct vulnerability triage and remediation prioritization, and oversee application security metrics reporting and security policy development.
8 to 10 years of experience in Application Security, DevSecOps, or related field.
Hands-on experience with 2-3 artifact repository/package registry tools such as JFrog Artifactory/Xray, Sonatype Nexus, Azure Artifacts, GitHub Packages, GitLab Package Registry, AWS CodeArtifact, or Google Artifact Registry.
Experience with SCA tools plus working knowledge of SAST and DAST tools like Veracode, Checkmarx, SonarQube, or OWASP ZAP.
Bachelor's degree in computer science, Information Security, or related field OR equivalent practical experience (preferred but not explicitly mandatory).
Experienced in managing and leading secure dependency management programs within complex software environments with measurable impact on reducing vulnerability risks.
Skilled in integrating and optimizing multiple security scanning tools in CI/CD pipelines, working closely with development, DevOps, and QA teams.
Comfortable operating in Agile/DevOps environments with strong technical knowledge of application security risks, artifact repositories, and vulnerability management frameworks.