S

Security Engineer - Static Code Analysis

Sonata Software · Noida, Uttar Pradesh, India

full_timePosted 3w ago
Apply now →

Job description

**About Sonata Software** In today's market, we observe a distinct duality in technology adoption. On one front, clients are keenly focused on cost containment, while on the other, there is a strong drive to modernize their digital storefronts, aiming to appeal to both consumers and B2B customers alike. As a leading Modernization Engineering company, we aim to deliver modernization-driven hypergrowth for our clients based on the deep differentiation we have created in Modernization Engineering, powered by our Lightening suite and 16-step Platformation playbook. In addition, we bring agility and systems thinking to accelerate time to market for our clients. Headquartered in Bengaluru, India, Sonata Software has a strong global presence, with strategic operations spanning across key regions such as the US, UK, Europe, APAC, and ANZ. We are a trusted partner of world-leading companies in TMT (Telecom, Media, and Technology), Retail & CPG, Manufacturing, BFSI (Banking, Financial Services and Insurance), and HLS (Healthcare and Lifesciences). Our bouquet of Modernization Engineering services cuts across Cloud, Data, Dynamics, Contact Centers, and around newer technologies like Generative AI, MS Fabric, and other modernization platforms. To know more, visit: www.sonata-software.com **Position:** Security Engineer **Location:** Noida **Job Type:** Full time **Experience:** 5-7 Key Responsibilities : **SAST (Static Application Security Testing)** - Operate and manage SAST tools (e.g., Checkmarx, Fortify, Veracode, CodeQL) • Analyze scan results to: o Identify true positives vs false positives o Prioritize based on exploitability and business impact • Partner with development teams to: o Remediate vulnerabilities o Improve secure coding practices • Tune rules and policies to reduce noise and increase scan accuracy **SCA (Software Composition Analysis)** - Manage and optimize SCA tools (e.g., Sonatype, Snyk, Black Duck, WhiteSource/Mend, Dependabot) • Identify and track: o Vulnerabilities in third-party and open-source components o License and compliance risks • Drive: o Dependency upgrades and patching strategies o Risk-based prioritization for remediation • Maintain visibility into software bill of materials (SBOM) **SDLC Integration & Automation** - Integrate SAST/SCA into: o CI/CD pipelines (GitHub, GitLab, Azure DevOps, Jenkins) o Developer workflows (PR checks, pre-commit hooks) • Automate: o Scan execution and reporting o Ticket creation and tracking (Jira or similar) • Ensure shift-left security adoption across engineering teams **Vulnerability Management & Reporting** - Track vulnerability lifecycle: o Identification Triage Remediation Closure • Provide: o Metrics and dashboards (e.g., SLA compliance, risk trends) o Executive-ready summaries for leadership • Support: o Audit and compliance requirements (ISO, SOC2, etc.) **Developer Enablement** - Act as a trusted advisor to engineering teams • Provide: o Remediation guidance and secure coding recommendations o Documentation, FAQs, and best practices • Conduct: o Developer training and awareness sessions **Required Qualifications** **Experience:** - 36+ years in Application Security, DevSecOps, or Secure Development - Hands-on experience with: o SAST and/or SCA tools in enterprise environments - Experience working closely with development teams and CI/CD pipelines Technical Skills - Strong knowledge of: o OWASP Top 10 o Secure coding practices (Java, Python, C/C++, JavaScript, etc.) - Experience with SAST tools such as: o Checkmarx, Fortify, Veracode, CodeQL - Experience with SCA tools such as: o Snyk, Black Duck, Mend, Dependabot DevSecOps & Automation - Familiarity with: o CI/CD tools (GitHub Actions, Jenkins, GitLab CI, Azure DevOps) • Experience with: o Scripting (Python, Bash, PowerShell) - Ability to: o Automate workflows and integrate security into pipelines Vulnerability Management - Understanding of: o CVSS scoring and risk prioritization o Vulnerability tracking and remediation processes - Experience with: o Jira or similar ticketing systems Preferred Qualifications - Certifications: o CSSLP, GWAPT, OSCP (optional but valuable) - Experience with: o SBOM frameworks (CycloneDX, SPDX) o Container security and dependency scanning o Cloud-native application security - Familiarity with: o Secrets scanning, IaC scanning tools (e.g., Terraform security) Key Competencies • Strong analytical skills and attention to detail - Ability to separate signal from noise in scan results - E ective communication with both technical and non-technical stakeholders - Focus on scalable, developer-friendly security solutions