





Senior, niche AppSec SCA role with specific artifact-repository toolset reduces candidate density despite Hyderabad location.
Role requires specific AppSec and SCA tooling knowledge, moderately transferable across industries.
Explicit 8–10 years requirement plus mandatory hands-on SCA, artifact repo tools, and CI/CD integrations imply high shortlisting strictness.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Own and drive the Software Composition Analysis (SCA) program including identifying, tracking, and remediating vulnerabilities and license compliance risks in open-source and third-party dependencies.
Configure and manage artifact repositories/package registries with embedded SCA scanning and policy enforcement, and establish dependency governance policies across engineering teams.
Integrate and optimize SAST and DAST tools in CI/CD pipelines, lead vulnerability triage and remediation, and maintain application security policies and metrics reporting.
8 to 10 years of relevant experience in Application Security, DevSecOps, or related field.
Hands-on experience with at least 2-3 artifact repository/package registry tools such as JFrog Artifactory/Xray, Sonatype Nexus, Azure Artifacts, GitHub Packages, or similar.
Working knowledge of SAST tools (e.g., Veracode, Checkmarx, HCL AppScan) and DAST tools (e.g., Invicti, Acunetix, OWASP ZAP).
Bachelor's degree in computer science, Information Security, or related field preferred.
Experienced in managing open-source and third-party dependency risks at scale, with deep expertise in Software Composition Analysis.
Skilled in integrating security practices within CI/CD pipelines and collaborating with development, DevOps, and QA teams in agile/DevOps environments.
Able to lead application security program with strong technical knowledge of OWASP Top 10, vulnerability management, and secure coding practices.