IT Software Asset Management Analyst - SBOM
Location: Raleigh, NC
Onsite Flexibility: Remote
Contract Details
- Position Type: Contract
- Contract Duration: 11 months
- Pay Rate: $68.96 $75.86 / Hour (USD)
- Work Authorization: Applicants must be authorized to work for ANY employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa at this time. Additionally, all candidates must be U.S. Citizens or Green Card holders. C2C and other citizenship statuses are not accepted for this role.
Job Summary
We're looking for a Software Asset Management Analyst SBOM to lead the hands-on work of our Software Bill of Materials (SBOM) program. You'll be part of the Software Asset Management (SAM) team and help with its everyday work, including inventory, licensing, compliance, and cleaning up unauthorized software. Most of your time, though, will come to understand what's inside the software we build and buy, especially the open-source pieces. Every application we run is built from hundreds of components, many of them open source, each with its own license and security history. When the next Log4j-style vulnerability hits, or Legal asks whether a product can ship with a GPL library in it, this is the person who can answer quickly and back it up with data. You'll work closely with Application Development, DevSecOps, Enterprise Architecture, Legal, Procurement, Third-Party Risk, Cybersecurity, and our software vendors.
Key Responsibilities
Primary Responsibilities SBOM
- Help run the SBOM program day to day: shape the process, set standards, and keep improving it.
- Collect and review SBOMs for software we build and buy. Check them against the NTIA Minimum Elements and look for the usual gaps, like missing transitive dependencies, no component hashes, or an unclear SBOM type.
- Work with developers and DevSecOps to generate SBOMs automatically in our GitLab CI/CD pipelines and keep a versioned SBOM repository so we always know what shipped in each release.
- Clean up and normalize component data (suppliers, versions, dependencies, and identifiers like PURL, CPE, and SWID) and tie it back to the right applications, software models, and publishers.
- Pull data from GitLab, JFrog Artifactory, ServiceNow SAM, Flexera - Technopedia/DejaCode to build a full picture of each product and what's inside it.
- Match SBOM components against our license and entitlement records so licensing obligations and risks don't slip through the cracks.
- When a new vulnerability is disclosed, help Cybersecurity figure out fast whether we're exposed, using sources like NVD, CISA KEV, and OSV along with vendor VEX statements.
- Partner with Procurement, Third-Party Risk, and Legal on what we ask vendors for, such as SBOM contract language, formats, and update frequency, in line with EO 14028, NIST SSDF (SP 800-218), and the EU Cyber Resilience Act.
- Find and fix data problems like missing fields, duplicate components, and inconsistent naming.
- Build the metrics, dashboards, procedures, and audit evidence that show how the program is doing and look for places to automate.
Primary Responsibilities Free and Open-Source Software (FOSS)
- Help maintain our open-source policy and approval process, including which licenses are approved, restricted, or off-limits.
- Identify licenses using SPDX identifiers and understand the practical difference between permissive licenses (MIT, BSD, Apache-2.0), weak copyleft (LGPL, MPL), strong and network copyleft (GPL, AGPL), and source-available or custom terms.
- Work out what each license requires of us (attribution, notices, source disclosure) based on how we use the component: internally, in a SaaS offering, or in software we distribute.
- Flag the tricky cases, like missing or conflicting licenses, projects that changed licenses between versions, and code snippets copied from open-source projects. Bring them to Legal and help document the decision.
- Put together notice files, attribution, and source code offers for software we distribute.
- Keep an eye on the health of the open-source projects we depend on. Watch for abandoned or end-of-life projects, typo squatted or malicious packages, and questionable provenance, and steer teams toward curated sources in JFrog Artifactory.
- Use DejaCode and ScanCode Toolkit to keep license data accurate and help developers understand what the policy means for their everyday work.
Software Asset Management Team Responsibilities
- Maintain and analyze inventory, installation, license, contract, and entitlement data.
- Review discovery results and normalize publisher, product, version, and edition.
- Support license reconciliation and point out where we're out of compliance or overspending.
- Keep software models, entitlements, license metrics, product use rights, and subscriptions up to date.
- Research licensing models and end-of-life and end-of-support dates, including commercial subscriptions for open-source based products like Red Hat or Oracle Java versus OpenJDK.
- Work unauthorized software tasks: confirm whether the software is approved, work with its owners on remediation, and track it to closure.
- Help with audits, license reviews, compliance assessments, and requests for software asset information.
- Support SAM controls, reporting, metrics, audit evidence, and ongoing improvements.
Required Experience
- 3 years in Software Asset Management, IT Asset Management, software licensing, software governance, or a closely related field.
Required Skills
- A solid grasp of SBOMs, software components, and how software supply chains work.
- Working knowledge of open-source licensing. You know the difference between permissive and copyleft licenses and what each one asks of the user.
- Comfort with dependencies, including transitive ones, package ecosystems like npm, Maven, PyPI, and NuGet, and container images.
- A good foundation in SAM concepts: lifecycle, discovery, normalization, licensing, entitlements, and compliance.
- Strong analytical skills. You enjoy reconciling inventory, usage, license, and entitlement data from sources that don't always agree.
- Clear writing and speaking, especially when explaining technical, licensing, or security findings to developers, attorneys, and leadership.
- A collaborative style that works well across Technology, Cybersecurity, Procurement, Legal, Risk, and the business.
- Software asset management (3 years required)
- Software Bill of Materials (3 years required)
- ServiceNow (3 years required)
- Flexera/Technopedia/DejaCode (3 years required)
- GitLab/JFrog Artifactory/CycloneDX (3 years required)
Preferred Skills
- Experience with ServiceNow SAM (normalization, reconciliation, software models, entitlements) and Flexera.
- Experience using GitLab and JFrog Artifactory to trace packages, components, and dependencies.
- Familiarity with Technopedia's DejaCode Open-Source Content Pack.
- Hands-on work with CycloneDX and SPDX: reading, validating, comparing, and converting SBOMs.
- Familiarity with CVE, CPE, PURL, SWID, CVSS, EPSS, and VEX formats (CSAF, CycloneDX VEX, OpenVEX).
- Experience with SCA and SBOM tools such as Black Duck, Snyk, JFrog Xray, OWASP Dependency-Track, ScanCode Toolkit, Syft, or Trivy.
- Knowledge of EO 14028, NIST SSDF, SLSA, OpenSSF Scorecard, OpenChain, and the EU Cyber Resilience Act.
- Some scripting (Python, SQL, jq, REST APIs). Certifications like ServiceNow CIS-SAM or IAITAM CSAM are a plus.
Benefits
- Medical, Vision, and Dental Insurance Plans
- 401k Retirement Fund
About the Client
This client is a top-20 U.S. banking and financial services institution with more than $200 billion in assets, over 550 branches across 23 states, and a Fortune 500 presence providing comprehensive personal and business banking stability for over 125 years. Headquartered in Raleigh, North Carolina, the organization delivers the full spectrum of financial services including personal banking, business banking, commercial lending, private banking, and wealth management to clients coast to coast. Teams here include commercial bankers, wealth management advisors, credit analysts, technology specialists, and retail banking professionals working within a values-driven, relationship-focused culture.
About GTT
GTT is a minority-owned staffing firm and a subsidiary of Chenega Corporation, a Native American-owned company in Alaska. We highly value diverse and inclusive workplaces and support Fortune 500 organizations across banking, financial services, technology, life sciences, biotech, utilities, and retail sectors throughout the U.S. and Canada.
Job Number: 26-15426 Industry: Software Engineering
#LI-Remote #LI-GTT