| Job Title | Deputy Manager – Software Asset Management |
| Company | Deloitte Touche Tohmatsu India LLP |
| Job Requisition ID | 109230 |
| Location | Delhi |
| Department/Domain | T&T Cyber – Cyber Strategy & Transformation (CST) |
| Experience | 5+ Years |
| Qualification | Bachelor’s or Master’s Degree |
| Experience Area | SBOM, Software Compliance, Application Security or Software Supply Chain Security |
| Role Focus | Software Bill of Materials (SBOM) management, compliance and software supply chain security |
| SBOM Management | Review, analyze, validate and maintain SBOMs from vendors and internal development teams |
| SBOM Creation | Create and generate SBOMs for internally developed applications and software products |
| Compliance | Ensure SBOM compliance with organizational, regulatory and industry standards |
| Risk Identification | Identify vulnerable, obsolete or unauthorized software components |
| Supply Chain Security | Support software supply chain security and vulnerability management programs |
| Stakeholder Management | Collaborate with Security, Procurement, Development, Application and Vendor Management teams |
| Risk Reporting | Support software supply chain assessments and risk reporting |
| Repository & Documentation | Maintain SBOM repositories, documentation, audit records and reporting metrics |
| Gap Analysis | Identify compliance gaps and provide recommendations |
| SCA Tools | Black Duck, Snyk, Mend (WhiteSource), FOSSA, Sonatype Nexus Lifecycle |
| SBOM Standards | SPDX, CycloneDX and SWID |
| Security Knowledge | SCA, Open-Source Governance, License Compliance, Vulnerability Management, CVE/CVSS |
| DevSecOps | Knowledge of DevSecOps, Secure Software Development and CI/CD integration |
| Frameworks | NIST SSDF and software supply chain security frameworks |
| Key Skills | SBOM, Software Asset Management, Software Compliance, Application Security, SCA, V |