- Ensure that Free and Open Source Software (FOSS) usage at MT complies with the internal operating policies and does not introduce security, license or operational risk for METTLER TOLEDO (MT) products.
- Collaborate with the Open-Source Compliance Officer (OSCO) to monitor FOSS usage and compliance across projects.
- Ensure QA best practices are followed in the team
- Is responsible for maintaining the FOSS corporate repository, where the FOSS components allowed for usage in MT products are managed.
- Responsible for reviewing and approving or rejecting requests for the introduction of new FOSS components
- Support the business units with the usage of Software Composition Analysis tool, ensuring that FOSS components are managed through Software Bill of Materials (SBOM) for continuous validation.
- Promotes FOSS adoption in MT and contributes to projects by developing features, fixing bugs, and collaborating with the community
- Provide training and guidance to software development teams on FOSS policies and best practices.
- Knows FOSS licensing mechanisms, and the particularity of strong copyleft and weak copyleft licenses.
- Can assess if the usage of a specific FOSS component complies with the overall proprietary application license.
- Act as a point of contact for inquiries related to FOSS compliance and licensing.
- Master’s or bachelor’s degree in engineering or equivalent education.
- With minimum 3 years of relevant experience
- Good knowledge of software development (e.g. .NET, C++, Java). Can contribute to FOSS projects by implementing modifications to the FOSS tools.
- Knowledge of software security processes (SCA, SAST, DAST, Penetration Testing).
- Knowledge of Secure Software Development Life-Cycle related processes and in general with practices like the NIST Secure Software Development Framework.
- Familiarity with Vulnerability Databases and Scoring Methodologies, like CVE, NVD and CVSS
- 1.5 months contractual bonus
- MNC exposure
- Medical and Dental benefits
Pour ceux qui priorisent la précision, Mettler Toledo est précisément le lieu où se trouve leur place.
Référence
Localisation souhaitée
Job Type
Entité légale