We are looking for an experienced FOSS Compliance Engineer to join a global technology organisation and help ensure that software products and services comply with open-source licensing requirements, industry standards and best practices.
This is a hands-on role combining open-source compliance, Software Composition Analysis (SCA), SBOM management and automation. You will work closely with software engineering, security, legal and product teams to embed compliance into the software development lifecycle.
The successful candidate will have strong practical experience in FOSS compliance, open-source licensing and automation, with the ability to work across complex software products and development environments.
Key Skills
- SBOM Management
- Software Composition Analysis (SCA)
- CI/CD Automation
- Python
- C/C++
- FossID / Black Duck or similar tooling
- SPDX
- CycloneDX
- OpenChain
Key Responsibilities
- Perform FOSS compliance analysis across software products and services, including source code and binary components.
- Identify and assess open-source licences and determine their implications for commercial software distribution.
- Maintain accurate inventories of software components, licences, obligations and attribution requirements.
- Ensure traceability across source code, third-party libraries, binaries, containers and software images.
- Operate and integrate Software Composition Analysis (SCA) tooling into software development workflows.
- Automate compliance processes using Python, including scanning, SBOM generation and validation, approvals, reporting and release-readiness checks.
- Implement and maintain SBOM processes in line with recognised standards such as SPDX and CycloneDX.
- Publish, validate and version SBOMs as part of the software release lifecycle.
- Carry out open-source risk assessments covering licensing, security and software provenance.
- Recommend practical remediation approaches, including component replacement, configuration changes and exception management.
- Support engineering teams with open-source software intake, dependency management, attribution requirements and licence-compliant usage.
- Provide guidance and education to development teams around FOSS compliance and open-source best practices.
- Monitor developments in open-source licensing, industry standards, regulations and community practices.
- Contribute to the continuous improvement of compliance policies, processes and tooling.
- Support governance activities, internal and external audits, compliance reviews and pre-release approval processes.
- Assist with customer and partner disclosures where required.
Required Skills & Experience
- 4–8 years' experience in FOSS / Open Source compliance, software licensing or a closely related discipline.
- Hands‑on experience conducting FOSS compliance analysis, reporting and publishing.
- Practical experience with Software Composition Analysis (SCA) tools such as FossID, Black Duck or equivalent.
- Good understanding of SBOM standards, particularly SPDX and CycloneDX.
- Familiarity with the OpenChain standard and open-source compliance frameworks.
- Experience automating compliance processes and integrating them into CI/CD pipelines.
- Strong Python development or scripting experience.
- Ability to read and understand software written in languages such as C/C++, Java, Python or Go.
- Good understanding of open-source licensing models and their implications for commercial software distribution.
- Experience working with Linux environments.
- Strong attention to detail and a commitment to producing accurate, high-quality work.
- Ability to work independently, manage priorities and deliver against deadlines.
- Strong written and verbal communication skills.
- Comfortable collaborating with technical and non-technical stakeholders across multiple teams.
- Experience working within a large-scale software or technology organisation.
- Experience with automated SBOM generation and validation.
- Experience integrating SCA tooling directly into developer workflows.
- Knowledge of software supply-chain security and provenance.
- Experience supporting software audits, governance or regulatory compliance programmes.
Education
Required:
- Bachelor's degree in Computer Science, Computer Engineering or a related technical discipline, or equivalent professional experience.
Preferred:
- Master's degree in Computer Science, Computer Engineering or a related discipline.
Ideal Candidate
The ideal candidate will combine strong open-source licensing knowledge with practical technical skills. You should be comfortable working directly with engineering teams, analysing software components and licences, automating compliance processes and helping organisations build FOSS compliance into their everyday development and release processes.