





Niche SCA specialization and senior (8+ years) reduces applicant density despite metro Hyderabad location.
Specialized SCA/AppSec skills are transferable but favor security-focused engineering backgrounds.
Explicit 8-10 years plus mandatory hands-on SCA and artifact-repository tool experience enforces strict filtering.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Own and manage the Software Composition Analysis (SCA) program including identifying, tracking, and remediating vulnerabilities and license risks in open-source/third-party components.
Configure and optimize artifact repositories and package registries with embedded SCA scanning and policy enforcement, and maintain Software Bill of Materials (SBOM) across the application portfolio.
Integrate and maintain SAST and DAST tools in CI/CD pipelines, triage vulnerabilities, and collaborate with development teams to embed secure practices in the SDLC.
8 to 10 years of experience in Application Security, DevSecOps, or related field.
Hands-on experience with at least 2-3 artifact repository/package management tools such as JFrog Artifactory/Xray, Sonatype Nexus, Azure Artifacts, GitHub Packages, GitLab Package Registry, AWS CodeArtifact, or Google Artifact Registry.
Working knowledge of SAST tools like Veracode, Checkmarx, HCL AppScan, SonarQube and DAST tools like Invicti, Acunetix, OWASP ZAP, Veracode DAST, or Burp Suite.
Bachelor's degree in Computer Science, Information Security, or related field OR equivalent practical experience.
Experienced in managing open-source dependency risk with strong focus on SCA and license compliance.
Skilled in integrating security testing tools into CI/CD pipelines and driving secure application development practices.
Able to configure and govern artifact/package repository policies and maintain traceability of open-source usage in complex environments.