HamburgerMenu
hirist

OSS Compliance Specialist - Applications Security

UST
4 - 8 Years
Bangalore

Posted on: 17/09/2026

Job Description

About the Company :

UST is a global digital transformation, AI, and IT consulting services provider.

For more than 20 years, UST has worked side by side with the world's best companies to make a real impact through transformation.

Powered by technology, inspired by people and led by purpose, UST partners with their clients from design to operation.

The company builds end-to-end tech solutions, specializing in advanced data & analytics, cloud modernization, generative AI agent frameworks, cybersecurity, and advanced engineering/R&D.

With deep domain expertise and a future-proof philosophy, UST embeds innovation and agility into their clients' organizations.

With over 30K+ employees in 30+ countries, UST builds a boundless impact - touching billions of lives in the process.

Open Source Compliance Coordinator :

Bangalore | Application Security.

We are looking for an experienced Open Source Compliance Coordinator who has a real interest and passion for Open-Source Software Compliance and has a good technical background in application security, especially Software Composition Analysis.

Key Responsibilities :

- Drive Open Source Software Compliance activities across applications.

- Analyze and manage Software Composition Analysis (SCA) scan results.

- Support development teams in license compliance, vulnerability management, and OSS governance.

- Coordinate source code, package, and snippet scans.

- Review and validate SBOMs and license obligations.

- Conduct compliance awareness sessions and training programs.

- Collaborate with AppSec, DevSecOps, Engineering, and Audit teams to strengthen OSS compliance practices.

Required Skills :

- 4+ years of experience in Open Source Software Compliance.

- Strong communicator with comfortable working both close to development teams as well as report and inform upper management on the status of Open Source Compliance and Vulnerability.

- Posses knowledge in understanding working flow for any of the popular programming language(s) and scripting language(s) to understand and identify plagiarism of code or logic.

- Hands-on experience with SCA tools such as BlackDuck, Sonatype Lifecycle, Mend.io, Revenera Code Insight, or FOSSID.

- Strong understanding of open-source licenses, compliance obligations, and risk management.

- Experience with package scanning, snippet scanning, and SBOM generation/review.

- Knowledge of Application Security and DevSecOps practices.

- Excellent communication and stakeholder management skills.

Good to Have :

- Experience with CI/CD pipelines.

- Knowledge of OWASP Top 10, OWASP ASVS, SAMM, or BSIMM.

- Understanding of Cyber Resilience Act (CRA) or related compliance regulations.

- Software development or architecture background.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...