NextHire logo
NextHirePosted 1 month ago

CyberNX- SBOM License Compliance Analyst

On-siteMumbai, Maharashtra, India

Full TimeSenior LevelSmall

Job Summary

Lead enterprise-wide SBOM governance by analyzing automated outputs to catalog Open-Source Software components across critical banking applications. Evaluate complex license profiles, copyleft obligations, and dual-licensing risks against regulatory requirements, then design remediation pathways for high-risk license conflicts. Coordinate internally with Legal, Procurement, and security units on escalations while apprising top management periodically. Architect and update internal OSS governance policies ensuring alignment with RBI-CERT-IN guidelines, serving as the primary subject matter expert during internal, external, and regulatory audits.

Required Qualifications

  • 5+ years of software license compliance or IT audit experience specifically within banking, fintech, or highly regulated financial environments
  • Deep understanding of OSS licenses (e.g., AGPL, GPL, Apache, MIT), patents, copyleft risks, and license compatibility constraints
  • Extensive hands-on experience with Enterprise Software Composition Analysis (SCA) and SBOM management tools
  • Familiarity with Regulatory requirements
  • Proven ability to advise solutions team on technical compliance strategies along with top management updates

Desired Qualifications

  • Specific certifications such as OpenChain, CISA, or CISSP

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce