Application Security Engineer 2

Posted 5 Days Ago
Be an Early Applicant
Bengaluru, Bengaluru Urban, Karnataka, IND
In-Office
Mid level
On-Demand • Security • Software
The Role
Develop AppSec program roadmaps, maturity assessments, capability models, and framework-aligned reports. Assess software security programs, address open-source and supply-chain risks, evaluate SBOM practices, and define multi-year DevSecOps strategies. Apply secure SDLC and CI/CD security controls while translating technical findings into executive recommendations. Create strategic documentation and presentations for client-facing leadership audiences.
Summary Generated by Built In

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.


About the Role

2 - 4 years of experience in application security, software assurance, or product security consulting.

Strong knowledge of frameworks such as BSIMM, NIST SSDF, or OWASP SAMM.

Experience with Open-Source Software (OSS) security, including identification, tracking, and remediation of vulnerabilities in third-party components.  

Familiarity with Software Bill of Materials (SBOM) standards and tools (e.g., SPDX, CycloneDX), and their role in software supply chain transparency and compliance

Proven experience in developing or executing maturity models, capability assessments, or multi-year roadmaps for AppSec or DevSecOps programs.

Hands-on experience with secure software development practices, including familiarity with SDLC, CI/CD pipelines, and code-level security controls.

Excellent verbal and written communication skills, with the ability to translate technical findings into clear, executive-level narratives and actionable plans.

Strong presentation and facilitation skills in client-facing environments.

Preferred:

Prior consulting experience with a Big Four, boutique AppSec consultancy, or internal software security governance team.

Experience in software supply chain risk management (SSCRM), AI/ML assurance, or DevSecOps pipeline design.

Background in software development (e.g., Java, Python, C#) and experience working within secure SDLCs.

Industry certifications such as CEH, CISSP, CSSLP, CISM, or equivalent.

What You’ll Deliver

Comprehensive AppSec Program Roadmaps, maturity assessments, and framework-aligned reports.

Visuals and documentation for capability maturity models and strategic planning.

Executive summaries and strategic recommendations tailored to leadership audiences.

Black Duck is an equal opportunity employer. We consider all applicants for employment without regard to race, color, national origin, religion, sex, gender identity or expression, age, disability, sexual orientation, veteran or military service status, or any other characteristic protected by applicable law. Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law.

Skills Required

  • 2–4 years of experience in application security, software assurance, or product security consulting
  • Strong knowledge of BSIMM, NIST SSDF, or OWASP SAMM
  • Experience identifying, tracking, and remediating vulnerabilities in third-party open-source components
  • Familiarity with SBOM standards and tools, including SPDX and CycloneDX
  • Experience developing or executing maturity models, capability assessments, or multi-year AppSec or DevSecOps roadmaps
  • Hands-on experience with secure software development practices, SDLC, CI/CD pipelines, and code-level security controls
  • Excellent verbal and written communication skills for translating technical findings into executive narratives and actionable plans
  • Strong presentation and facilitation skills in client-facing environments
  • Consulting experience with a Big Four firm, boutique AppSec consultancy, or internal software security governance team
  • Experience in software supply chain risk management, AI/ML assurance, or DevSecOps pipeline design
  • Software development background in Java, Python, or C# and experience with secure SDLCs
  • Industry certification such as CEH, CISSP, CSSLP, CISM, or equivalent

Black Duck Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Black Duck and has not been reviewed or approved by Black Duck.

  • Healthcare Strength Medical, dental, and vision coverage provide multiple plan choices with transparent costs, with carrier updates noted for 2026. Vision via VSP and dental plan options offer defined tiers and network access.
  • Retirement Support Retirement programs include a 401(k) with company matching alongside an employee stock purchase plan with a discount and lookback. These features support longer‑term savings and wealth building.
  • Leave & Time Off Breadth Exempt employees use a manager‑approved, no‑cap time‑off model, while non‑exempt employees accrue flexible time off alongside sick time. Paid leaves include parental and family care leave, with additional protections under applicable leave laws.

Black Duck Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Burlington, MA
275 Employees
Year Founded: 2002

What We Do

Organizations worldwide use Black Duck Software’s industry-leading products to secure and manage open source software, eliminating the pain related to security vulnerabilities, compliance and operational risk. Black Duck is headquartered in Burlington, MA, and has offices in San Jose, London, Frankfurt, Hong Kong, Tokyo, Vancouver, Seoul & Beijing

Why Work With Us

We pride ourselves on cultivating an environment of collaboration, creativity, and fun! We know where you work can influence how you work, which is why our collaborative office space focuses on community and continuous learning. Our work-hard, play-hard attitude even got us named a Top Place to Work in Massachusetts by The Boston Globe!

Gallery

Gallery

Similar Jobs

DigitalOcean Logo DigitalOcean

Software Engineer

Artificial Intelligence • Cloud • Software • Infrastructure as a Service (IaaS)
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
1400 Employees
Hybrid
2 Locations
289097 Employees

Capital One Logo Capital One

Director, Recruitment

Fintech • Machine Learning • Payments • Software • Financial Services
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
55000 Employees

Micron Technology Logo Micron Technology

Senior Engineer

Artificial Intelligence • Hardware • Information Technology • Machine Learning
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND
45000 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account