Analyst - Software Asset Management (SAM) - SBOM
Reference Number: 413791
Posted: 10/06/2026
Job Type: Contract
- Industry: Technology and IT
Title: Analyst - Software Asset Management (SAM) - SBOM
Fully Remote - US
Pay - Up to $75p/h
Contract - 1 Year with likely extension
You’ll be part of the Software Asset Management (SAM) team and help with its everyday work, including inventory, licensing, compliance, and cleaning up unauthorized software. Most of your time, though, will come to understand what’s inside the software we build and buy, especially the open-source pieces.
Every application we run is built from hundreds of components, many of them open source, each with its own license and security history. When the next Log4j-style vulnerability hits, or Legal asks whether a product can ship with a GPL library in it, this is the person who can answer quickly and back it up with data. You’ll work closely with Application Development, DevSecOps, Enterprise Architecture, Legal, Procurement, Third-Party Risk, Cybersecurity, and our software vendors.
Primary Responsibilities – SBOM
- Help run the SBOM program day to day: shape the process, set standards, and keep improving it.
- Collect and review SBOMs for software we build and buy. Check them against the NTIA Minimum Elements and look for the usual gaps, like missing transitive dependencies, no component hashes, or an unclear SBOM type.
- Work with developers and DevSecOps to generate SBOMs automatically in our GitLab CI/CD pipelines and keep a versioned SBOM repository so we always know what shipped in each release.
- Clean up and normalize component data (suppliers, versions, dependencies, and identifiers like PURL, CPE, and SWID) and tie it back to the right applications, software models, and publishers.
- Pull data from GitLab, JFrog Artifactory, ServiceNow SAM, Flexera - Technopedia/DejaCode to build a full picture of each product and what’s inside it.
- Match SBOM components against our license and entitlement records so licensing obligations and risks don’t slip through the cracks.
- When a new vulnerability is disclosed, help Cybersecurity figure out fast whether we’re exposed, using sources like NVD, CISA KEV, and OSV along with vendor VEX statements.
- Partner with Procurement, Third-Party Risk, and Legal on what we ask vendors for, such as SBOM contract language, formats, and update frequency, in line with EO 14028, NIST SSDF (SP 800-218), and the EU Cyber Resilience Act.
- Find and fix data problems like missing fields, duplicate components, and inconsistent naming.
- Build the metrics, dashboards, procedures, and audit evidence that show how the program is doing and look for places to automate.
- Help maintain our open-source policy and approval process, including which licenses are approved, restricted, or off-limits.
- Identify licenses using SPDX identifiers and understand the practical difference between permissive licenses (MIT, BSD, Apache-2.0), weak copyleft (LGPL, MPL), strong and network copyleft (GPL, AGPL), and source-available or custom terms.
- Work out what each license requires of us (attribution, notices, source disclosure) based on how we use the component: internally, in a SaaS offering, or in software we distribute.
- Flag the tricky cases, like missing or conflicting licenses, projects that changed licenses between versions, and code snippets copied from open-source projects. Bring them to Legal and help document the decision.
- Put together notice files, attribution, and source code offers for software we distribute.
- Keep an eye on the health of the open-source projects we depend on. Watch for abandoned or end-of-life projects, typo squatted or malicious packages, and questionable provenance, and steer teams toward curated sources in JFrog Artifactory.
- Use DejaCode and ScanCode Toolkit to keep license data accurate and help developers understand what the policy means for their everyday work.
As part of the SAM team, you’ll also pitch in on the team’s broader work:
- Maintain and analyze inventory, installation, license, contract, and entitlement data.
- Review discovery results and normalize publisher, product, version, and edition.
- Support license reconciliation and point out where we’re out of compliance or overspending.
- Keep software models, entitlements, license metrics, product use rights, and subscriptions up to date.
- Research licensing models and end-of-life and end-of-support dates, including commercial subscriptions for open-source–based products like Red Hat or Oracle Java versus OpenJDK.
- Work unauthorized software tasks: confirm whether the software is approved, work with its owners on remediation, and track it to closure.
- Help with audits, license reviews, compliance assessments, and requests for software asset information.
- Support SAM controls, reporting, metrics, audit evidence, and ongoing improvements.
- 3+ years in Software Asset Management, IT Asset Management, software licensing, software governance, or a closely related field.
- A solid grasp of SBOMs, software components, and how software supply chains work.
- Working knowledge of open-source licensing. You know the difference between permissive and copyleft licenses and what each one asks of the user.
- Comfort with dependencies, including transitive ones, package ecosystems like npm, Maven, PyPI, and NuGet, and container images.
- A good foundation in SAM concepts: lifecycle, discovery, normalization, licensing, entitlements, and compliance.
- Strong analytical skills. You enjoy reconciling inventory, usage, license, and entitlement data from sources that don’t always agree.
- Clear writing and speaking, especially when explaining technical, licensing, or security findings to developers, attorneys, and leadership.
- A collaborative style that works well across Technology, Cybersecurity, Procurement, Legal, Risk, and the business.
- Experience with ServiceNow SAM (normalization, reconciliation, software models, entitlements) and Flexera.
- Experience using GitLab and JFrog Artifactory to trace packages, components, and dependencies.
- Familiarity with Technopedia’s DejaCode Open-Source Content Pack.
- Hands-on work with CycloneDX and SPDX: reading, validating, comparing, and converting SBOMs.
- Familiarity with CVE, CPE, PURL, SWID, CVSS, EPSS, and VEX formats (CSAF, CycloneDX VEX, OpenVEX).
- Experience with SCA and SBOM tools such as Black Duck, Snyk, JFrog Xray, OWASP Dependency-Track, ScanCode Toolkit, Syft, or Trivy.
- Knowledge of EO 14028, NIST SSDF, SLSA, OpenSSF Scorecard, OpenChain, and the EU Cyber Resilience Act.
- Some scripting (Python, SQL, jq, REST APIs). Certifications like ServiceNow CIS-SAM or IAITAM CSAM are a plus.
| · SBOM Management & Analysis | · SAM & License Management | · CycloneDX / SPDX |
| · FOSS License Compliance | · Entitlement & Lifecycle Mgmt. | · ServiceNow SAM / CMDB · Flexera |
| · Supply Chain Security | · Unauthorized SW Remediation | · GitLab · Artifactory · DejaCode |
| · Software Composition Analysis | · Data Analysis & Reconciliation | · Reporting, Metrics & Controls |
If this is a role that interests you and you’d like to learn more, click apply now and a recruiter will be in touch with you to discuss this great opportunity. We look forward to speaking with you!
About ManpowerGroup, Parent Company of: Manpower, Experis and Talent Solutions
Experis® is a global leader in technology services and part of the ManpowerGroup® (NYSE: MAN) family of brands. We connect skilled technology professionals with meaningful opportunities where they can grow their careers, expand their expertise and make a real impact. Guided by the belief that it takes Human Ingenuity to unlock the true potential of technology, Experis helps people gain experience with leading organizations, build sought-after skills and take the next step toward a brighter future. Backed by ManpowerGroup's 75+ years of workforce expertise and global reach across more than 70 countries and territories, Experis brings the scale, insight and opportunity to help people and businesses thrive. ManpowerGroup is consistently recognized for its commitment to inclusion, ethics and responsible business, including being named one of the World's Most Ethical Companies. Learn more at Experis.com.
CONSULTANT TESTIMONIAL
An Experis consultant
"Communication, instructions, expectations and follow-through were exceptional, throughout the hiring, interviewing and onboarding process. Thank you, Experis!"

