Job SCA Implementation SME All the skills in JD are must

SCA Implementation SME

Skills:All the skills in JD are must       |  Location: Tampa, FL  ,  United States Of America

Views:591

Role Summary
The SCA Implementation SME will focus on implementing and optimizing Software Composition Analysis (SCA) tools and processes across the organization. This leadership role will guide the integration, and operationalization to strengthen software supply chain security. The SME will influence process improvements, policy development, and training strategies.

Key Responsibilities
· Serve as the delegate for the Project Lead, supporting program execution and stakeholder engagement.

· Lead the implementation, configuration, and management of SCA tools (e.g., Endor Labs, Mend/WhiteSource, Black Duck, Snyk) to identify vulnerabilities and license compliance issues in open-source and third-party components.

· Define and optimize policies, standards, and workflows for SCA integration and vulnerability management.

· Integrate SCA tools and processes into the Software Development Lifecycle (SDLC) and CI/CD pipelines to automate security checks.

· Guide the development of secure coding and open-source governance training programs.

· Monitor industry trends and emerging technologies to recommend enhancements to SCA tools and methodologies.

· Establish metrics and reporting frameworks to measure program effectiveness and progress.

· Support troubleshooting and escalation management for SCA-related issues in collaboration with technical teams and vendors.

· Oversee generation and management of Software Bills of Materials (SBOMs) for compliance and risk assessment.

Required Knowledge & Skills
· SCA Expertise: Deep understanding of SCA principles, tools, and best practices for managing open-source and third-party components.

· Software Supply Chain Security: Strong knowledge of vulnerability prevention, license compliance, and SBOM management.

· Tooling Knowledge: Familiarity with Endor Labs, Mend/WhiteSource, Black Duck, Snyk, and related technologies.

· DevSecOps Integration: Experience embedding SCA into CI/CD pipelines and automating security checks.

· Program Leadership: Ability to guide large-scale security initiatives, manage tool migrations, and optimize processes.

· Strategic Communication: Skilled in influencing stakeholders and articulating program goals and improvements.

· Risk Assessment: Experience assessing vulnerabilities and license risks in third-party components.

Save me for future

Report / Flag this Job Ad

General Job Safety Alert

Before applying to any job, be aware of these common scam warning signs
  • Requests for payment, bank details, or financial information
  • Unusually high salaries for minimal qualifications
  • Job offers without proper interviews
  • Requests to transfer money or cash checks
  • Communications with poor grammar/spelling
  • Pressure to make immediate decisions

Never share sensitive personal or financial information without verification. If you encounter suspicious activity, please report it immediately. Read our full scam prevention guidelines.



Check Similar Jobs

Embedded Software Engineer 3 (TPL) – Chillicothe, IL -- W2

Hiring: Embedded Software Engineer 3 (TPL) – Chillicothe, IL      We are looking for an experienced Embedded Software Engineer to join our team working on telematics and display electronics.

Project Manager with Vulnerability, Patching, and Hardening Expereince

Role: Project Manager with Vulnerability, Patching, and Hardening Expereince      Location: Greensboro, NC Onsite (Local preferred)      Duration : Long Term Contract         Must ...

Python Backend Developer with JavaScript || Canada

Role: Python Backend Developer with JavaScript      Location: Canada (Any City)      Hybrid      12 Months         Job Description:      Talent should be a Full stack ...

Oracle EBS Techno-Functional Consultant (Order to Cash) only on w2 Location: Remote (USA – EST or CST Time Zone)

Job Title: Oracle EBS Techno-Functional Consultant (Order to Cash) only on w2      Location: Remote (USA – EST or CST Time Zone)   Shift: 8 AM – 5 PM EST   Interview Mode: Video (MS Teams) ...

Java Full Stack Developer (Spring Boot + Angular) || Mississauga, Canada (Hybrid)

Job Title: Java Full Stack Developer (Spring Boot + Angular)      Location: Mississauga, Canada (Hybrid)   Duration: 12 Months plus Contract   Experience: 10+ Years   Domain: Banking / ...

UI/UX Consultant with Capital Markets Applications || Toronto, ON - Canada (Hybrid) W2

Position: UI/UX Consultant with Capital Markets Applications         Location: Toronto, ON - Canada (Hybrid) W2         Duration: Long Term               Job Summary: ...

Oracle Fusion HCM Techno Functional Lead || Location: San Jose CA || W2

Role: Oracle Fusion HCM Techno Functional Lead   Location: San Jose CA   Onsite   Full time and Contract W2 Only      This is Senior role need 15 yrs solid experience in ORC - Oracle ...

Oracle Fusion HCM Techno Functional Lead

Role: Oracle Fusion HCM Techno Functional Lead      Location: San Jose CA      Onsite      Full time and Contract               This is Senior role need 15 yrs solid ...