As a Software Composition Analysis Specialist, you will play a crucial role in ensuring the integrity, security, and compliance of software components used in our projects. Your responsibilities will include identifying and mitigating vulnerabilities, ensuring adherence to licensing requirements, and promoting best practices for secure software development.
Key ResponsibilitiesConduct thorough analysis of software components to identify vulnerabilities and potential security risks. Evaluate open source and third-party libraries for their impact on overall system security.
License ComplianceAssess software components for compliance with licensing agreements. Provide guidance on licensing implications and ensure adherence to legal requirements.
Tool UtilizationUtilize industry-standard Software Composition Analysis tools to identify, track, and manage software components. Stay updated on the latest SCA tools and technologies to enhance analysis capabilities.
CollaborationWork closely with development teams to communicate analysis findings and collaborate on remediation strategies. Provide guidance to ensure secure coding practices and prevent future vulnerabilities.
SupportMaintain comprehensive documentation of software components, vulnerabilities, and remediation efforts. Create reports for stakeholders, including executive summaries and technical details
Qualifications & SkillsEngineering Graduate in CS, IT, EC or InfoSec, CyberSec or MCA equivalent
CertificationsCertified Ethical Hacker (CEH)
ComplianceKnowledge of security best practices and methodologies. Familiarity with open source software and licenses.
Technical SkillsExperience with Software Composition Analysis tools (e.g., WhiteSource, Kiuwan, Black Duck, Snyk, etc).
Proven experience in software development and a strong understanding of various programming languages.
Communication skillsStrong communication and collaboration skills. Ability to prioritize and manage multiple tasks in a dynamic environment.
Keyskills: Software Composition Analysis SCA CEH WhiteSource Kiuwan Black Duck Snyk Component Analysis