Application Security Engineer 3

Reposted 9 Days Ago
Easy Apply
Be an Early Applicant
Bangalore, Bengaluru Urban, Karnataka
In-Office
5-8 Annually
Senior level
On-Demand • Security • Software
The Role
Lead client engagements and assessments of Application Security Programs, deliver strategic roadmaps, and facilitate workshops to enhance secure software development practices.
Summary Generated by Built In

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.


Application Security Engineer III

We’re seeking a Senior Application Security Consultant with deep expertise in software security, secure development practices, governance, and framework-driven transformation planning. In this role, you will lead client engagements to assess Application Security Programs (AppSec) against industry frameworks and deliver strategic roadmaps that help organizations build, scale, and measure their secure software development capabilities. This position blends strategic consulting, technical governance, and development lifecycle expertise to translate assessment findings into actionable, measurable programs aligned with frameworks such as BSIMM and NIST SSDF.

Key Responsibilities

  • Lead AppSec Program maturity assessments using frameworks like BSIMM, NIST SSDF, and OWASP SAMM, including stakeholder interviews, evidence collection, and scoring.
  • Design and deliver Strategic Roadmaps outlining target states, 12–36-month plans, resource needs, and success metrics.
  • Facilitate workshops with executive, engineering, and AppSec leadership to align initiatives with organizational risk and compliance goals.
  • Deliver compelling, executive-level presentations and recommendations to CISOs, CTOs, and software leadership teams.
  • Contribute to internal tools and accelerators (e.g., maturity scoring tools, roadmap templates, reporting dashboards).
  • Support thought leadership through whitepapers, webinars, and conference presentations on secure software development and governance.

Qualifications

Must to have:

  • 5 – 8 years of experience in application security, software assurance, or product security consulting.
  • Strong knowledge of frameworks such as BSIMM, NIST SSDF, or OWASP SAMM.
  • Experience with Open-Source Software (OSS) security, including identification, tracking, and remediation of vulnerabilities in third-party components.
  • Familiarity with Software Bill of Materials (SBOM) standards and tools (e.g., SPDX, CycloneDX), and their role in software supply chain transparency and compliance
  • Proven experience in developing or executing maturity models, capability assessments, or multi-year roadmaps for AppSec or DevSecOps programs.
  • Hands-on experience with secure software development practices, including familiarity with SDLC, CI/CD pipelines, and code-level security controls.
  • Excellent verbal and written communication skills, with the ability to translate technical findings into clear, executive-level narratives and actionable plans.
  • Strong presentation and facilitation skills in client-facing environments.

Nice to have:

  • Prior consulting experience with a Big Four, boutique AppSec consultancy, or internal software security governance team.
  • Experience in software supply chain risk management (SSCRM), AI/ML assurance, or DevSecOps pipeline design.
  • Background in software development (e.g., Java, Python, C#) and experience working within secure SDLCs.
  • Industry certifications such as CEH, CISSP, CISM, or equivalent.

What You’ll Deliver

  • Comprehensive AppSec Program Roadmaps, maturity assessments, and framework-aligned reports.
  • Visuals and documentation for capability maturity models and strategic planning.
  • Executive summaries and strategic recommendations tailored to leadership audiences.

Black Duck considers all applicants for employment without regard to race, color, religion, sex, gender preference, national origin, age, disability, or status as a Covered Veteran in accordance with federal law. In addition, Black Duck complies with applicable state and local laws prohibiting discrimination in employment in every jurisdiction in which it maintains facilities. Black Duck also provides reasonable accommodation to individuals with a disability in accordance with applicable laws.

Top Skills

Bsimm
C#
Cyclonedx
Java
Nist Ssdf
Owasp Samm
Python
Spdc
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Burlington, MA
275 Employees
Year Founded: 2002

What We Do

Organizations worldwide use Black Duck Software’s industry-leading products to secure and manage open source software, eliminating the pain related to security vulnerabilities, compliance and operational risk. Black Duck is headquartered in Burlington, MA, and has offices in San Jose, London, Frankfurt, Hong Kong, Tokyo, Vancouver, Seoul & Beijing

Why Work With Us

We pride ourselves on cultivating an environment of collaboration, creativity, and fun! We know where you work can influence how you work, which is why our collaborative office space focuses on community and continuous learning. Our work-hard, play-hard attitude even got us named a Top Place to Work in Massachusetts by The Boston Globe!

Gallery

Gallery

Similar Jobs

Accuris Logo Accuris

Software Architect

Information Technology • Machine Learning • Software • Conversational AI • Generative AI • Manufacturing
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND
1200 Employees

CrowdStrike Logo CrowdStrike

Regional Sales Manager

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Hybrid
Bangalore, Bengaluru Urban, Karnataka, IND
10000 Employees

CrowdStrike Logo CrowdStrike

Regional Sales Manager

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Hybrid
Bangalore, Bengaluru Urban, Karnataka, IND
10000 Employees

TransUnion Logo TransUnion

User Experience Designer

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
2 Locations
13000 Employees

Similar Companies Hiring

Scotch Thumbnail
Software • Retail • Payments • Fintech • eCommerce • Artificial Intelligence • Analytics
US
25 Employees
Milestone Systems Thumbnail
Software • Security • Other • Big Data Analytics • Artificial Intelligence • Analytics
Lake Oswego, OR
1500 Employees
Fairly Even Thumbnail
Software • Sales • Robotics • Other • Hospitality • Hardware
New York, NY

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account