
Cyber Security Specialist
2 weeks ago
About the Company
We are seeking a highly skilled and self-driven FOSS Sonatype IQ Subject Matter Expert (SME) to join our Secure Development Cybersecurity team. This role is crucial to strengthening our software supply chain security and ensuring open-source compliance across development teams in Global business and functions.
About the Role
The ideal candidate will possess deep expertise in Sonatype IQ Server along with other OSS scanning tools (like Snyk, Black Duck, Dependency-Track, Crowd Strike), a strong grasp of modern DevSecOps practices, and hands-on experience in establishing FOSS usage policies in enterprise environments. In this role, you will be responsible for ensuring the secure code adoption, governance, and compliance of open-source software security across the organization. You will work closely with development, security, and technology teams to mitigate risks, enforce policies, and enhance the security posture of open-source software.
Responsibilities
- Serve as the primary advisor and technical expert for Sonatype Nexus IQ Server and open-source dependency vulnerability scanning.
- Implement and maintain Sonatype IQ integrations within CI/CD pipelines to automate security and compliance checks.
- Analyze and remediate vulnerabilities, license risks, and policy violations in open-source dependencies.
- Develop and enforce software composition analysis (SCA) best practices across development teams.
- Collaborate with security teams to prioritize and mitigate OSS vulnerabilities based on risk assessments.
- Create and maintain custom policy configurations in Sonatype IQ to align with organizational security standards.
- Train and mentor engineering teams on secure OSS usage, dependency management, and DevSecOps best practices.
- Work to uplift the vulnerability scanning and remediation capabilities to meet enhanced Service Level Agreements (SLAs), ensuring timely and effective resolution of security vulnerabilities.
- Monitor and report on FOSS risk metrics, providing actionable insights to leadership.
- Stay updated on emerging software supply chain threats and recommend proactive security measures.
- Support SBOM interlock and proactively participate in wider SBOM program.
- To perform security assessment and identify potential risk with open source LLMs.
Qualifications
- 4+ years of hands-on experience with Sonatype Nexus IQ Server in an enterprise environment.
- Strong understanding of Software Development Life Cycle (SDLC) with a focus on security.
- Strong expertise in open-source Software security, vulnerability management, and license compliance.
- Proficiency in DevSecOps practices, including CI/CD integration (Jenkins, GitLab, GitHub Actions, etc.)
- Experience with software composition analysis (SCA) tools and dependency management (Maven, npm, pip, etc.)
- Knowledge of OWASP Top 10, CVE, and MITRE ATT&CK frameworks related to OSS risks.
- Familiarity with container security (Docker, Kubernetes) and SBOM (Software Bill of Materials) generation.
- Good to have scripting skills (Bash, Python, Groovy) for automation and tool customization.
- Excellent communication skills, with the ability to explain complex security concepts to non-technical stakeholders.
Required Skills
- 7+ years of experience into cybersecurity, Information security or security engineering.
- Strong DevSecOps and Software security background.
- Desirable to have one or more industry-recognised cybersecurity-related certifications including CISSP, CRISC, CISM, OSCP.
- Bachelor or Masters degree in Computer Science, Information Technology, Cybersecurity or equivalent.
Job Title: FOSS Sonatype IQ SME
Location: India (Bengaluru, Hyderabad, Pune)
CSAT- Cybersecurity
-
Cyber Security Sales Manager
2 weeks ago
Bangalore, India Mitigata™ - Smart cyber insurance Full timeAbout Us (Mitigata) is a leading provider of Cyber Security, Compliance, and Risk Management solutions helping businesses safeguard digital assets, ensure regulatory compliance, and minimize exposure to cyber threats. With a strong portfolio of solutions and services, we empower enterprises to build a resilient cyber defense posture. Role Overview ...
-
Avp - cyber security specialist [t500-20014]
1 week ago
Bangalore, India MUFG Full timeAbout Us: MUFG Bank, Ltd. is Japan’s premier bank, with a global network spanning in more than 40 markets. Outside of Japan, the bank offers an extensive scope of commercial and investment banking products and services to businesses, governments, and individuals worldwide. MUFG Bank’s parent, Mitsubishi UFJ Financial Group, Inc. (MUFG) is one of the...
-
Cyber security specialist
1 week ago
Bangalore, India Flipkart Full timeHi, We are hiring Cyber Security Engineers at Flipkart. Exp - 4.5+ Location - Bangalore Mode of work - Hybrid. APPLY HERE : JD : ● Investigate, document, and report on information security issues and emerging threats. ● Provide Incident Response (IR) support when analysis confirms the actionable incident. ● Isolation of affected systems, collect...
-
Cyber security engineer
1 week ago
Bangalore, India TÜV SÜD Full timeKey Responsibilities Complete testing on time. Keep up to date with the latest in standards, regulations and technical developments in the cyber security space. Actively co-develop the security programs and details test method according to ITSAR requirements Set-up lab infrastructure and test equipments needed to deliver the service according to ITSAR,...
-
Cyber and Information Security Risk Specialist
12 hours ago
Bangalore, India Computacenter Full timeLife on the team Operates the Third-Party Cyber Risk Management framework to ensure cybersecurity risks related to our supply chain are effectively, managed to maintain a resilient and compliant security posture. Operate the Third-Party Cyber Risk Management Framework (~ 90%) • Third-Party Risk Management framework: operate processes and procedures as...
-
Cyber Security Architect
4 days ago
Bangalore, India Utthunga Full timeHello Connections! We are hiring for Cyber security Architect Role: The Cyber Security Architect will be responsible for designing, implementing, and maintaining security frameworks for Industrial Automation and Control Systems (IACS). This role ensures compliance with IEC 62443 and EU CRA regulations, protecting critical infrastructure from cyber...
-
Cyber security
1 week ago
Bangalore, India Computacenter Full timeLife on the team Operates the cyber compliance framework to ensure Computacenter is continually compliant to our cybersecurity obligations, helping us to achieve our business goals and build customer trust. What you’ll do Operate the Cyber Compliance Framework (~ 90%)• Compliance Framework: operate processes and procedures as part of the Cyber...
-
Manager- cyber security operations
1 week ago
Bangalore, India Biocon Full timeRole Summary: At least 10+ years of experience in Cybersecurity with hands-on capability is network & other security technologies. The Cybersecurity Operations Manager will work closely with the SOC (Security Operations Centre) & Managed Security Services team to detect, analyse, respond and mitigate cybersecurity incidents. Knowledge & skills in managing...
-
Cyber Security Architect
7 days ago
bangalore, India Utthunga Full timeHello Connections!We are hiring for Cyber security Architect Role:The Cyber Security Architect will be responsible for designing, implementing, and maintaining security frameworks for Industrial Automation and Control Systems (IACS). This role ensures compliance with IEC 62443 and EU CRA regulations, protecting critical infrastructure from cyber...
-
Chief Information Security Officer
1 week ago
Bangalore, India CYBER سايبر Full timeWe at CYBER are looking for an exceptional Chief Information Security Officer (CISO) to join our leadership team. This is a full-time leadership role offering occasional flexibility but requiring a strong on-site and executive presence to drive security strategy across the organization. As CISO, you will design, implement, and oversee a world-class...