Ahmed ElMallah
Senior Software Engineer at GitHub. I spend my days helping developers actually understand their open-source dependencies — what's in there, why, and whether it's safe to trust.
About
I'm a software engineer who's spent the better part of the last decade untangling software supply chains — software composition analysis, dependency intelligence, and the kind of developer-facing AppSec tooling that turns "wait, what's actually in our software?" into a solvable problem.
These days I work on GitHub's Dependency Graph team, building the systems that help developers and organizations understand their open-source dependencies, generate SBOMs, power Dependabot, and keep up with what's changing underneath their code.
Before that, I spent three years at Veracode building Software Composition Analysis products — dependency collection across Maven, Gradle, npm, Python, and Go, vulnerability curation, and the APIs and workflows that make AppSec teams' lives a little easier.
What keeps me interested is the same question asked a hundred different ways: what dependencies exist, why are they there, what changed, what's vulnerable, and what's actually worth losing sleep over.
Founder of Bomly
Bomly
Founder & MaintainerA free, open-source dependency-intelligence CLI, solely designed and built by me, that scans your projects and tells you what's really in them. Same problem space as my day job — just built entirely on my own time, for the fun of it.
- Explains direct and transitive dependencies across ecosystems
- Generates SBOMs and audits for known vulnerabilities
- Drivable from AI agents over MCP, if you'd rather ask than click
Experience
Bomly
Open source
Founder & Maintainer
Side project
- Founded and maintain Bomly, a free, open-source dependency-intelligence CLI.
- Solely designed and built every part of the tool — the scanning engine, SBOM generation, vulnerability-audit pipeline, and MCP integration for AI-agent-driven analysis.
GitHub
Remote
Senior Software Engineer
Mar 2026 – Present
Software Engineer III
Jul 2024 – Mar 2026
- Work on the Dependency Graph team — systems supporting software supply chain security, dependency intelligence, SBOM generation, Dependabot, and dependency-review experiences.
- Build and improve backend systems and data pipelines for dependency ingestion, parsing, normalization, storage, and analysis across package ecosystems.
- Contribute across major initiatives: dependency accuracy, ecosystem coverage, dependency submission, graph quality, and platform-scale performance.
Veracode
Remote
Senior Software Engineer
Oct 2022 – Jul 2024
Software Engineer
Apr 2021 – Oct 2022
- Designed, developed, and maintained Software Composition Analysis products that help customers identify open-source dependency risk.
- Built dependency-collection tooling for Maven, Gradle, npm, Python, and Go, plus advanced tooling for vulnerable-methods analysis.
- Built curation tools for additional languages and vulnerability sources, and designed scalable REST APIs and backend services for AppSec, SCA, and developer security workflows.
Cognizant
Greater New York City Area
Full Stack Engineer
Sep 2019 – Apr 2021
- Delivered RESTful APIs and AWS serverless components on client engagements including Capital One and Macy's.
- Handled coding, testing, infrastructure provisioning, CI/CD, and front-end migrations in agile teams.
Skills
Backend
Frontend
Cloud & DevOps
Education
Pennsylvania State University
2015 – 2017Master of Engineering, Nuclear Engineering
GPA 4.00
Rutgers University · Cognizant Talent Accelerator
2019Java Development Bootcamp
Thomas Edison State University
2014 – 2015B.S., Nuclear Engineering Technology
GPA 3.76
Alexandria University
2008 – 2012B.S., Nuclear & Radiation Engineering
Let's talk.
Email or LinkedIn are your best bet — I read both. Always happy to talk software supply chains, dependency graphs, or why I decided to build Bomly on top of a full-time job.