Pracuj.pl Praca zdalna Mid

Software Supply Chain Engineer

SQUARE ONE RESOURCES sp. z o.o.

⚲ Warszawa

150–180 zł netto (+ VAT) / godz.

Wymagania

  • Python
  • Java
  • Node.js
  • TypeScript
  • SBOM
  • Cyclone DX
  • C
  • C++
  • .NET
  • C#

Opis stanowiska

Nasze wymagania: Proven experience with CI/CD pipelines and integrating open source compliance Minimum of 2 years of practical experience in open source compliance, preferably in a regulated industry such as healthcare or medical device. Thorough understanding of open source licenses, their implications, and best practices for compliance. Demonstrable experience working with CycloneDX or similar SBOM formats. Proficiency in managing dependencies for two or more programming languages, such as .NET/C#, Python, Java, C/C++, Node.JS/TypeScript. Familiarity with both Linux and Windows operating systems and their interactions with open source components. Zakres obowiązków: Collaborate with software architects, senior developers and devops leads to generate a comprehensive Software Bill of Materials (SBOM) for commercial products, including detailed information on open source components and dependencies. Review, analyze, and assess the usage of open source software in products to ensure compliance with relevant regulations and licenses, including knowledge of how usage, deployment, and architecture affects compliance. Integrate open source compliance checks into CI/CD pipelines, facilitating the early identification of compliance issues and minimizing compliance risks. Demonstrate proficiency in managing dependencies for at least two of the following programming languages: .NET/C#, Python, Java, C/C++, Node.JS/TypeScript, considering both proprietary and open source components. Create and maintain clear and concise compliance documentation, including policies, procedures, and best practices, to foster a compliant development environment. Utilize your expertise with CycloneDX, a lightweight SBOM standard, to enhance the accuracy and efficiency of our compliance processes. Stay informed about industry regulations, particularly FDA requirements, and ensure that our open source compliance practices align with current and emerging standards. Provide training and support to development teams on open source compliance practices, fostering a culture of awareness and responsibility. Provide expert guidance to development teams on open source licensing requirements, restrictions, and obligations to ensure legal and regulatory compliance.

🔍 Dekoder Ogłoszenia

🔴
Proven experience with CI/CD pipelines and integrating open source compliance
Oczekuje się, że kandydat samodzielnie skonfiguruje i zoptymalizuje istniejące lub stworzy nowe procesy CI/CD z uwzględnieniem aspektów zgodności licencyjnej open source.
🔴
Thorough understanding of open source licenses, their implications, and best practices for compliance.
Nie wystarczy ogólna wiedza; firma oczekuje dogłębnej analizy prawnej i technicznej potencjalnych problemów związanych z licencjami open source.
🔴
Collaborate with software architects, senior developers and devops leads to generate a comprehensive Software Bill of Materials (SBOM) for commercial products
Będziesz musiał aktywnie współpracować z różnymi zespołami, aby uzyskać potrzebne informacje i zapewnić dokładność generowanych SBOM-ów, co może wymagać przekonywania innych do priorytetów.
🔴
Review, analyze, and assess the usage of open source software in products to ensure compliance with relevant regulations and licenses, including knowledge of how usage, deployment, and architecture affects compliance.
To zadanie wykracza poza proste skanowanie licencji; wymaga zrozumienia kontekstu biznesowego i technicznego, aby ocenić ryzyko zgodności.
🟡
Familiarity with both Linux and Windows operating systems and their interactions with open source components.
Oczekiwana jest umiejętność rozwiązywania problemów związanych z integracją i działaniem komponentów open source w obu środowiskach operacyjnych.