Live opening · Posted 1 day ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
About the Company
UST is a global digital transformation, AI, and IT consulting services provider. For more than 20 years, UST has worked side by side with the world’s best companies to make a real impact through transformation. Powered by technology, inspired by people and led by purpose, UST partners with their clients from design to operation. The company builds end-to-end tech solutions, specializing in advanced data & analytics, cloud modernization, generative AI agent frameworks, cybersecurity, and advanced engineering/R&D. With deep domain expertise and a future-proof philosophy, UST embeds innovation and agility into their clients’ organizations. With over 30K+ employees in 30+ countries, UST builds a boundless impact—touching billions of lives in the process.
Website
https://www.ust.com/
Open Source Compliance Coordinator
📍 Bangalore | 🛡️ Application Security
We are looking for an experienced Open Source Compliance Coordinator who has a real interest and passion for Open-Source Software Compliance and has a good technical background in application security, especially Software Composition Analysis.
Key Responsibilities:
Drive Open Source Software Compliance activities across applications.
Analyze and manage Software Composition Analysis (SCA) scan results.
Support development teams in license compliance, vulnerability management, and OSS governance.
Coordinate source code, package, and snippet scans.
Review and validate SBOMs and license obligations.
Conduct compliance awareness sessions and training programs.
Collaborate with AppSec, DevSecOps, Engineering, and Audit teams to strengthen OSS compliance practices.
Required Skills:
4+ years of experience in Open Source Software Compliance.
Strong communicator with comfortable working both close to development teams as well as report and inform upper management on the status of Open Source Compliance and Vulnerability.
Posses knowledge in understanding working flow for any of the popular programming language(s)and scripting language(s) to understand and identify plagiarism of code or logic.
Hands-on experience with SCA tools such as BlackDuck, Sonatype Lifecycle, Mend.io, Revenera Code Insight, or FOSSID.
Strong understanding of open-source licenses, compliance obligations, and risk management.
Experience with package scanning, snippet scanning, and SBOM generation/review.
Knowledge of Application Security and DevSecOps practices.
Excellent communication and stakeholder management skills.
Good to Have
Experience with CI/CD pipelines.
Knowledge of OWASP Top 10, OWASP ASVS, SAMM, or BSIMM.
Understanding of Cyber Resilience Act (CRA) or related compliance regulations.
Software development or architecture background.
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.