🔔 FCM Loaded

Senior Engineer - Level 2

Arrow

5 - 10 years

Bengaluru

Posted: 11/08/2025

Job Description

Position:

Senior Engineer - Level 2

Job Description:

Key Responsibilities:

  • Lead the design and development of SBOM generation pipelines within Yocto-based embedded build systems

  • Integrate and validate SPDX 3.0-compliant SBOMs using open-source and custom tools

  • Automate SBOM creation as part of the CI/CD pipelines using Jenkins and other DevOps tools

  • Work with security teams to analyze and track Open-Source Vulnerabilities (CVE) from generated SBOMs

  • Collaborate with development teams to ensure accurate tracking of software components, licenses, and dependencies

  • Maintain and improve tooling for source scanning, license compliance, and vulnerability management
  • Analyze complex source code bases and integrate SBOM processes with SCM systems (Git, Gerrit, etc.)

  • Write and maintain Python scripts for build integration, reporting, and automation of SBOM tasks

Required Skills:
  • 5+ years of experience with Yocto Build System (BitBake, meta layers, custom recipes)

  • Strong hands-on experience with SPDX standards (preferably 3.0) and SBOM generation tools (e.g., SPDX tools, FOSSology, CycloneDX, scancode-toolkit)

  • Solid understanding of CI/CD concepts and Jenkins pipeline development

  • Proficiency with Git, Gerrit, JIRA, and other collaborative tools

  • In-depth knowledge of Python scripting, including advanced concepts

  • Experience working with Makefiles, toolchains, and compiler optimization in embedded environments

  • Strong grasp of open-source licensingcompliance, and security scanning (CVE/NVD tools)

  • Excellent problem-solving, communication, and collaboration skills

Preferred Qualifications:
  • Experience with SBoM automation in production environments

  • Familiarity with Linux Security Modules (LSM) or other embedded Linux security frameworks

  • Understanding of DevSecOps practices

  • Contributions to open-source SBOM initiatives or SPDX community is a strong plus

Location:

IN-KA-Bangalore, India (eInfochips)

Time Type:

Full time

Job Category:

Engineering Services

About Company

Arrow Electronics is a Fortune 500 technology company that specializes in providing electronic components and enterprise IT solutions. Headquartered in Centennial, Colorado, it supports over 220,000 customers across 80+ countries. Arrow helps businesses design, build, and manage innovative technology products through its global distribution, engineering, and supply chain services.

Services you might be interested in

One-Shot Campaign

Reach out to ideal employees in one shot!

The intelligent campaign for reaching out to the ideal audience to whom you can ask for help (guidance or referral).