Application Security Engineer – Software Composition Analysis (SCA)
Core
Strengthen software supply chain security by integrating SCA tools into CI/CD pipelines to identify vulnerabilities and license compliance issues in open-source and third-party components.
Role type
Senior Application Security Engineer (Software Composition Analysis)
Builds
Secure software supply chain and developer workflows
Domain
Healthcare technology / Application Security
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Software Composition Analysis (SCA), CI/CD pipeline integration, vulnerability exploitability analysis, open-source license compliance, risk-based prioritization, Jenkins/GitHub Actions/GitLab CI, Java/Python/C++/Ruby, package manager knowledge (npm/pip/Maven/Gradle), OWASP Top 10, SSDLC
Preferred skills
AI/LLM-focused security scanning tools, Synk/Black Duck/Mend/Veracode/Checkmarx ONE, Artifactory integration
Responsibilities
Lead implementation and optimization of SCA solutions, integrate and automate security tools within CI/CD pipelines, analyze vulnerabilities for exploitability and business impact, perform risk-based prioritization of findings, develop and enforce open-source governance policies, provide technical guidance to development teams
Seniority
Senior, hands-on IC