Deputy Manager | Software Asset Management | Delhi | Cyber Strategy & Transformation
- Job requisition ID : 109230
- Location: Delhi
- Entity: Deloitte Touche Tohmatsu India LLP
The Team
Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity
Your work profile
- Review, analyse, validate, and maintain Software Bills of Materials (SBOMs) received from vendors and internal development teams
- Create and generate SBOMs for internally developed applications and software products
- Ensure SBOM compliance with organizational, regulatory, and industry standards
- Identify vulnerable, obsolete, or unauthorized software components through SBOM analysis
- Support software supply chain security and vulnerability management programs
- Collaborate with Security, Procurement, Development, and Application teams to drive SBOM compliance
- Support software supply chain security assessments and risk reporting activities
- Collaborate with Security, Procurement, Development, and Vendor Management teams on SBOM compliance requirements
- Maintain SBOM repositories, documentation, audit records, and reporting metrics.
- Perform gap analysis and provide recommendations for non-compliant SBOM
Key Skills Required
- 5+ years of experience in SBOM, Software Compliance, Application Security, or Software Supply Chain Security
- Hands-on experience in SBOM creation, review, validation, and governance
- Strong understanding of software supply chain security, open-source software compliance, and dependency management
- Experience analyzing software vulnerabilities and software component risks
- Strong stakeholder management and communication skills.
- Experience with SBOM and Software Composition Analysis (SCA) tools such as Black Duck, Snyk, Mend (WhiteSource), FOSSA, Sonatype Nexus Lifecycle, etc
- Knowledge of SBOM standards such as SPDX, CycloneDX, and SWID
- Knowledge of Software Composition Analysis (SCA), Open-Source Governance, and License Compliance
- Understanding of Vulnerability Management, CVE/CVSS, DevSecOps, and Secure Software Development practices
- Experience integrating SBOM generation and validation within CI/CD pipelines
- Knowledge of NIST SSDF and software supply chain security frameworks.