Zelis

Sr SCA Engineer

Zelis
Apply
1 month ago
Hyderābād, IndiaSenior

Responsibilities

  • Own and drive the Software Composition Analysis program, including identification, tracking, and remediation of open-source dependency vulnerabilities and license-compliance risks.
  • Configure, manage, and optimize artifact repositories and package registries with SCA scanning and policy enforcement.
  • Establish dependency governance policies, monitor CVEs, drive remediation, and maintain SBOM traceability across the application portfolio.
  • Configure and integrate SAST and DAST tools into CI/CD pipelines and triage findings with development teams.
  • Conduct manual code reviews, validate automated findings, support penetration testing, and coordinate remediation.
  • Develop application-security policies and guidelines, report security metrics, and train teams on secure coding and vulnerability remediation.

Requirements

  • 8 to 10 years of relevant experience in Application Security, DevSecOps, or a related field.
  • Hands-on experience with at least two to three artifact repository or package registry tools, including SCA configuration and policy enforcement.
  • Experience with SBOM generation using CycloneDX or SPDX and open-source license-compliance scanning.
  • Working knowledge of SAST and DAST tools, CI/CD security integrations, vulnerability triage, and application-security remediation.
  • Working knowledge of at least one programming or scripting language such as Java, Python, JavaScript, or .NET for reviewing code-level vulnerabilities.
  • Understanding of OWASP Top 10, CWE/SANS Top 25, API security testing, secure API design, and application-security practices.
  • Familiarity with container security and cloud security concepts across AWS, Azure, or GCP is preferred.
  • Knowledge of NIST, ISO 27001, and PCI-DSS is preferred.
  • A bachelor’s degree in computer science, information security, or a related field, or equivalent practical experience, is preferred.
  • Security certifications such as CEH, OSCP, GWAPT, CSSLP, or Security+ are preferred.

Benefits

  • Opportunity to build and shape a growing Application Security program with exposure to modern DevSecOps tools and practices.
  • Collaborative work culture with continuous learning opportunities.
  • Competitive compensation and benefits package, including healthcare benefits and financial wellness programs.
  • Hybrid work flexibility and cultural celebrations are offered.

Tech Stack

AWSAzureGitHub ActionsGitLab CI/CDGoogle Cloud PlatformJavaJavaScriptJenkins.NETPythonSonarQube

Categories

Zelis

About Zelis

1,001-5,000 employees
Contact me