Security Engineer SAST & SCA
Sonata Software · Noida, Uttar Pradesh, India
Sonata Software · Noida, Uttar Pradesh, India
We are looking for a **Security Engineer SAST & SCA** to strengthen our Application Security (AppSec) program by driving secure software development practices across the SDLC. The ideal candidate should have hands-on experience with **Static Application Security Testing (SAST)** and **Software Composition Analysis (SCA)** tools, vulnerability management, secure coding practices, and DevSecOps automation. You will collaborate closely with engineering teams to identify, prioritize, and remediate code-level and open-source vulnerabilities while integrating security into CI/CD pipelines. Key Responsibilities - Manage and operate enterprise SAST tools such as Checkmarx, Fortify, Veracode, or CodeQL. - Analyze scan findings, eliminate false positives, and prioritize vulnerabilities based on business risk and exploitability. - Drive remediation efforts with development teams and provide secure coding recommendations. - Configure and optimize SAST rules and policies to improve scan accuracy. - Manage SCA platforms such as Snyk, Black Duck, Mend (WhiteSource), Sonatype, or Dependabot. - Identify vulnerabilities in open-source libraries and third-party dependencies. - Perform software license compliance analysis and dependency risk assessment. - Maintain Software Bill of Materials (SBOM) visibility. - Integrate SAST/SCA tools into CI/CD pipelines using GitHub Actions, GitLab CI, Azure DevOps, or Jenkins. - Automate security scans, reporting, and Jira ticket creation using Python, Bash, or PowerShell. - Track vulnerability lifecycle from identification through remediation and closure. - Create dashboards, reports, and executive summaries for security metrics and compliance. - Conduct secure coding awareness sessions and mentor developers on application security best practices. - Support compliance initiatives including ISO 27001 and SOC 2.