UST logo

OSS Compliance Specialist

UST

RemoteFull timeMid levelPosted today
Apply with JobAssist

About the role

About the Company

UST is a global digital transformation, AI, and IT consulting services provider. For more than 20 years, UST has worked side by side with the world’s best companies to make a real impact through transformation. Powered by technology, inspired by people and led by purpose, UST partners with their clients from design to operation. The company builds end-to-end tech solutions, specializing in advanced data & analytics, cloud modernization, generative AI agent frameworks, cybersecurity, and advanced engineering/R&D. With deep domain expertise and a future-proof philosophy, UST embeds innovation and agility into their clients’ organizations. With over 30K+ employees in 30+ countries, UST builds a boundless impact—touching billions of lives in the process.

Website

https://www.ust.com/

Open Source Compliance Coordinator

📍 Bangalore | 🛡️ Application Security

We are looking for an experienced Open Source Compliance Coordinator who has a real interest and passion for Open-Source Software Compliance and has a good technical background in application security, especially Software Composition Analysis.

Key Responsibilities:

  • Drive Open Source Software Compliance activities across applications.
  • Analyze and manage Software Composition Analysis (SCA) scan results.
  • Support development teams in license compliance, vulnerability management, and OSS governance.
  • Coordinate source code, package, and snippet scans.
  • Review and validate SBOMs and license obligations.
  • Conduct compliance awareness sessions and training programs.
  • Collaborate with AppSec, DevSecOps, Engineering, and Audit teams to strengthen OSS compliance practices.

Required Skills:

  • 4+ years of experience in Open Source Software Compliance.
  • Strong communicator with comfortable working both close to development teams as well as report and inform upper management on the status of Open Source Compliance and Vulnerability.
  • Posses knowledge in understanding working flow for any of the popular programming language(s)and scripting language(s) to understand and identify plagiarism of code or logic.
  • Hands-on experience with SCA tools such as BlackDuck, Sonatype Lifecycle, Mend.io, Revenera Code Insight, or FOSSID .
  • Strong understanding of open-source licenses, compliance obligations, and risk management.
  • Experience with package scanning, snippet scanning, and SBOM generation/review.
  • Knowledge of Application Security and DevSecOps practices.
  • Excellent communication and stakeholder management skills.

Good to Have

  • Experience with CI/CD pipelines.
  • Knowledge of OWASP Top 10, OWASP ASVS, SAMM, or BSIMM.
  • Understanding of Cyber Resilience Act (CRA) or related compliance regulations.
  • Software development or architecture background.

Millions of jobs, with real people getting hired every day

20,000+
New jobs added daily
7,000,000+
Verified job listings
500,000+
Tailored applications submitted
FAQ

Questions, answered

Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.

Yes. This role at UST was screened before publishing – we confirmed the employer before listing it.

The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.

This position can be done from anywhere, with no in-office requirement.

Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.