Professional, Security Tool, SBOM Engineer

Zinnov Management Consulting

Bengaluru

Hybrid

INR 1,800,000 - 2,400,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Zinnov invites applications for a Professional, Security Tool, SBOM Engineer role in Bengaluru as part of its new India Global Capability Centre. You will drive SBOM generation, validation, and integration within CI/CD, collaborating with cross-functional teams to secure software supply chains.

The role requires 3+ years in security tooling and SBOM expertise, with hands-on platform experience and scripting skills. Join a fast-paced environment shaping global healthcare tech.

Qualifications

  • 3+ years in application security, product security, DevSecOps, or software-supply-chain security.
  • Hands-on SBOM/SCA exposure and knowledge of SPDX/CycloneDX.
  • Experience with SBOM platforms such as Black Duck, Snyk, Mend, or similar.
  • Experience integrating security scanning into CI/CD pipelines.
  • Proficiency with Python, Bash, PowerShell, REST APIs for data ingestion.
  • Familiarity with Docker, Kubernetes, and modern build/release processes.
  • Bachelor's degree or equivalent experience in a technical field.

Responsibilities

  • Develop and operate SBOM generation and validation pipelines across apps, firmware, and medical-device software.
  • Integrate SBOM tooling into CI/CD using Jenkins, GitHub Actions, GitLab CI, or Azure DevOps.
  • Establish SBOM standards for completeness, provenance, licensing, and traceability.
  • Correlate component data with vulnerability feeds to prioritize risk in SBOMs.
  • Support container security, license checks, and scanning with tuning to reduce false positives.
  • Automate SBOM data exchange via REST APIs and scripting in Python/Bash/PowerShell.
  • Assess supplier SBOMs, reconcile inventories, and track component risk.

Skills

SBOM/SCA exposure
SPDX/CycloneDX
CI/CD integration
Python
REST APIs
Docker/Kubernetes
Analytical collaboration

Education

Bachelor's degree in CS/SE/InfoSec

Tools

Black Duck
Snyk
Mend
Sonatype Lifecycle
Anchore
Dependency-Track
Syft/Grype

Job description

Zinnov is hiring for the role of Professional, Security Tool, SBOM Engineer on behalf of our Global MNC MedTech client company a company where technology sits at the centre of everything: powering how the core business operates day to day and shaping the products and digital solutions that will define the future of patient care. This role is part of the companys establishment of their new India Global Capability Centre (GCC) in Bengaluru which will drive enterprise technology, digital transformation and innovation for its global operations and contributing to technology that ultimately helps millions of people around the world.

How you'll make an impact
  • Develop and operate SBOM generation and validation pipelines using SPDX and CycloneDX across applications, firmware, containers, and medical-device software.
  • Integrate SCA/SBOM tooling such as Black Duck, Snyk, Mend, Sonatype Lifecycle, Anchore, Syft/Grype, Dependency-Track, Trivy, or equivalent into Jenkins, GitHub Actions, GitLab CI, or Azure DevOps.
  • Establish standards for SBOM completeness, provenance, versioning, component identifiers, package URLs (purl), licensing, dependency relationships, and release traceability.
  • Correlate component data with NVD, CISA KEV, vendor advisories, CVSS/EPSS, VEX/OpenVEX, and vulnerability-management platforms to prioritize actionable software risk.
  • Support container/image, secrets, license, and supply-chain scanning and reduce false positives through tuning, suppression governance, and evidence-based validation.
  • Automate ingestion and exchange of SBOM and vulnerability data through REST APIs, Python/Bash/PowerShell, artifact repositories, GRC, asset inventory, and product-security systems.
  • Assess supplier-provided SBOMs, validate formats and component coverage, reconcile external inventories with internal scans, and track identified component risk.
  • Support software-supply-chain integrity practices such as NIST SSDF, SLSA, signing/attestation concepts (for example Sigstore/cosign), and secure build controls where applicable.
  • Produce dashboards, runbooks, architecture documentation, regulatory evidence, and coverage metrics aligned with FDA Section 524B, IEC 81001-5-1, and product-security requirements.
What you'll bring
Skills Required:
  • 3+ years of Experience in application security, product security, DevSecOps, security-tool engineering, or software-supply-chain security with hands-on SBOM/SCA exposure.
  • Strong working knowledge of SPDX, CycloneDX, SBOM lifecycle, SCA, CVE/CVSS, dependency management, open-source licensing, and software-component risk.
  • Hands-on experience with at least one SCA/SBOM platform such as Black Duck, Snyk, Mend, Sonatype Lifecycle, Anchore, Dependency-Track, Syft/Grype, or equivalent.
  • Experience integrating security scanning into CI/CD using Jenkins, GitHub Actions, GitLab CI, Azure DevOps, or equivalent pipeline technologies.
  • Proficiency with Python, Bash, PowerShell, REST APIs, or comparable automation for data ingestion, validation, and tool integration.
  • Familiarity with Docker, Kubernetes, artifact/package ecosystems, container scanning, and modern software build/release processes.
  • Strong analytical, troubleshooting, documentation, data-quality, and cross-functional collaboration skills.
  • Bachelor's degree in Computer Science, Software Engineering, Information Security, or a related technical field; equivalent practical experience may be considered.
Preferred:
  • Experience in medical-device, healthcare, or life-sciences security with FDA Section 524B, IEC 81001-5-1, AAMI TIR57, and regulated software evidence.
  • Experience with VEX/OpenVEX, SLSA, signing/attestation, supplier SBOM validation, GRC integration, or open-source license governance.
  • CSSLP, GIAC GSSP/GWEB, Security+, DevSecOps, or software-supply-chain security certifications.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Product Security Engineer (SBOM)
Product Security Engineer (SBOM)

Zinnov Management Consulting • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Professional, Attack Surface & Exposure Analyst
Professional, Attack Surface & Exposure Analyst

Zinnov Management Consulting • Bengaluru

Hybrid
INR 1,800,000 - 2,800,000
Professional, Sr. Cyber Metrics Analyst
Professional, Sr. Cyber Metrics Analyst

Zinnov Management Consulting • Bengaluru

Hybrid
INR 2,800,000 - 4,200,000
Solution Architect (810 Years ExperienceSBOM, GitLab CI/CD & Python
Solution Architect (810 Years ExperienceSBOM, GitLab CI/CD & Python

Harman International • Bangalore Rural

On-site
INR 2,800,000 - 5,200,000
Professional, Vulnerability Management Lead
Professional, Vulnerability Management Lead

Zinnov Management Consulting • Bengaluru

Hybrid
INR 2,000,000 - 4,000,000
DevSecops Engineer
DevSecops Engineer

HCLSoftware • Bengaluru

Hybrid
INR 2,500,000 - 4,000,000
Sr Cybersecurity Specialist
Sr Cybersecurity Specialist

Healthminds Consulting • Hyderabad

On-site
INR 3,000,000 - 6,000,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2COMS Consulting Pvt. Ltd. • Bengaluru Urban

On-site
INR 1,500,000 - 2,100,000
Professional, Observability Services
Professional, Observability Services

Zinnov Management Consulting • Bengaluru

Hybrid
INR 1,200,000 - 1,800,000
Professional, Machine Identity & Secrets Engineer
Professional, Machine Identity & Secrets Engineer

Zinnov Management Consulting • Bengaluru

Hybrid
INR 1,800,000 - 3,000,000