Application Security Engineer

BMC Software, Inc.

Maharashtra

Hybrid

INR 2,400,000 - 3,200,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

BMC Software, Inc. is seeking a highly motivated Product Security Engineer with 5+ years of experience to strengthen security across modern applications, APIs, and mainframe-integrated systems. You will partner with Product, Legal, and Compliance teams to ensure secure software delivery throughout the SDLC.

Responsibilities include secure design reviews, threat modeling, OSS governance, and remediation coordination with development teams, leveraging SAST/DAST/SCA and CI/CD integration.

Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering, or equivalent practical experience.
  • 5+ years of experience in Product Security, Software Security Engineering, or a related discipline.
  • Strong understanding of SSDLC, DevSecOps, vulnerability management, secure architecture, and modern software delivery practices.
  • Hands-on experience with security testing and tooling across SAST, DAST, SCA, container security, secrets detection, and CI/CD integrations.
  • Experience with SCA platforms such as FOSSA, Black Duck, Sonatype, JFrog Xray, or similar solutions.
  • Knowledge of open-source licensing, license compliance, SBOM concepts, software supply chain risks, and related governance processes.
  • Deep understanding of OWASP Top 10, OWASP API Top 10, OWASP LLM/AI Top 10, CWE, CVSS, and risk-based vulnerability prioritization.
  • Strong analytical, communication, stakeholder management, and problem-solving skills, with the ability to explain security and compliance concepts clearly to technical and non-technical audiences.

Responsibilities

  • Perform secure design reviews, penetration testing, threat modeling, and risk based security assessments across web applications, APIs, thick clients, mainframe-integrated systems, and emerging LLM/AI-enabled technologies.
  • Execute security testing aligned with OWASP Top 10, OWASP API Top 10, OWASP , LLM/AI Top 10, CWE Top 25, CVSS, and evolving threat landscapes.
  • Evaluate open-source components for security, license, and compliance risks, and collaborate with Product, Engineering, Legal, Compliance, and OSPO stakeholders to address findings.
  • Operate and support Software Composition Analysis platforms, including dependency analysis, software inventory management, software supply chain visibility, and SBOM generation and maintenance.
  • Support open-source governance processes, including intake reviews, approval workflows, exception management, policy enforcement, standards, procedures, and best practices.
  • Triage, validate, prioritize, track, and report vulnerabilities identified through manual assessments and security scanning tools, supporting governance and metrics.
  • Partner with development teams to drive remediation, perform retesting, improve secure-by-design practices, and advance shift-left security initiatives throughout the SDLC.
  • Identify and assess risks related to authentication, authorization, data protection, secure communications, integration patterns, and interactions with RACF, DB2, CICS, MQ, and related mainframe subsystems.
  • Administer and improve security tooling across SAST, DAST, SCA, container scanning, and secrets detection, including CI/CD integration, workflow automation, onboarding, reporting, developer adoption, and continuous process improvement.

Skills

Product Security
Secure SDLC
Vulnerability Management
Open-source Governance
Security Tooling
SAST
DAST
SCA
CI/CD Integration
OWASP Top 10
Threat Modeling
Mainframe Security

Education

Bachelor's degree

Tools

FOSSA
Black Duck
Sonatype
JFrog Xray

Job description

You may occasionally be required to travel for business

Looking for details about our benefits? You can learn more about them by clicking HERE

Description and Requirements

CA-SB

Hybrid: #LI-Hybrid

BMC empowers nearly 80% of the Forbes Global 100 to accelerate business value, faster than humanly possible. Our industry-leading portfolio unlocks human and machine potential to drive business growth, innovation, and sustainable success. BMC does this in a simple and optimized way by connecting people, systems, and data that power the world’s largest organizations so they can seize a competitive advantage.

We are seeking a highly motivated Product Security Engineer with 5+ years of experience in product security, secure SDLC, vulnerability management, open-source governance, and security tooling. This individual contributor role will help strengthen product security practices across modern applications, APIs, mainframe-integrated systems, and emerging AI-enabled technologies.

The ideal candidate will partner closely with Product, Legal, and Compliance teams to ensure secure and compliant software delivery throughout the SDLC while supporting operational excellence across product security programs.

Here is how, through this exciting role, YOU will contribute to BMC's and your own success:

  • Perform secure design reviews, penetration testing, threat modeling, and risk based security assessments across web applications, APIs, thick clients, mainframe-integrated systems, and emerging LLM/AI-enabled technologies.
  • Execute security testing aligned with OWASP Top 10, OWASP API Top 10, OWASP , LLM/AI Top 10, CWE Top 25, CVSS, and evolving threat landscapes.
  • Evaluate open-source components for security, license, and compliance risks, and collaborate with Product, Engineering, Legal, Compliance, and OSPO stakeholders to address findings.
  • Operate and support Software Composition Analysis platforms, including dependency analysis, software inventory management, software supply chain visibility, and SBOM generation and maintenance.
  • Support open-source governance processes, including intake reviews, approval workflows, exception management, policy enforcement, standards, procedures, and best practices.
  • Triage, validate, prioritize, track, and report vulnerabilities identified through manual assessments and security scanning tools, supporting governance and metrics.
  • Partner with development teams to drive remediation, perform retesting, improve secure‑by‑design practices, and advance shift‑left security initiatives throughout the SDLC.
  • Identify and assess risks related to authentication, authorization, data protection, secure communications, integration patterns, and interactions with RACF, DB2, CICS, MQ, and related mainframe subsystems.
  • Administer and improve security tooling across SAST, DAST, SCA, container scanning, and secrets detection, including CI/CD integration, workflow automation, onboarding, reporting, developer adoption, and continuous process improvement.

To ensure you’re set up for success, you will bring the following skillset & experience:

  • Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering, or equivalent practical experience.
  • 5+ years of experience in Product Security, Software Security Engineering, or a related discipline.
  • Strong understanding of SSDLC, DevSecOps, vulnerability management, secure architecture, and modern software delivery practices.
  • Hands‑on experience with security testing and tooling across SAST, DAST, SCA, container security, secrets detection, and CI/CD integrations.
  • Experience with SCA platforms such as FOSSA, Black Duck, Sonatype, JFrog , Xray, or similar solutions.
  • Knowledge of open-source licensing, license compliance, SBOM concepts, software supply chain risks, and related governance processes.
  • Deep understanding of OWASP Top 10, OWASP API Top 10, OWASP LLM/AI Top 10, CWE, CVSS, and risk‑based vulnerability prioritization.
  • Strong analytical, communication, stakeholder management, and problem?solving skills, with the ability to explain security and compliance concepts clearly to technical and non‑technical audiences.

Whilst these are nice to have, our team can help you develop in the following skills:

  • Experience with software licensing governance, compliance programs, product security operations, and open‑source review processes.
  • Familiarity with supply chain security frameworks such as OpenSSF, NIST SSDF,
  • and SLSA.
  • Relevant certifications such as OSCP, OSCE, CRTP, GPEN, GXPN, CSSLP, CISSP,
  • or equivalent security credentials.

Our commitment to you!

BMC’s culture is built around its people. We have 6000+ brilliant minds working together across the globe. You won’t be known just by your employee number, but for your true authentic self. BMC lets you be YOU!

BMC is committed to equal opportunity employment regardless of race, age, sex, creed, color, religion, citizenship status, sexual orientation, gender, gender expression, gender identity, national origin, disability, marital status, pregnancy, disabled veteran or status as a protected veteran. If you need a reasonable accommodation for any part of the application and hiring process, visit the accommodation request page.

BMC Software maintains a strict policy of not requesting any form of payment in exchange for employment opportunities, upholding a fair and ethical hiring process.

At BMC we believe in pay transparency and have set the midpoint of the salary band for this role at 2,841,000 INR. Actual salaries depend on a wide range of factors that are considered in making compensation decisions, including but not limited to skill sets; experience and training, licensure, and certifications; and other business and organizational needs.

The salary listed is just one component of BMC's employee compensation package. Other rewards may include a variable plan and country specific benefits.

We are committed to ensuring that our employees are paid fairly and equitably, and that we are transparent about our compensation practices.

We use AI technology to support parts of our recruitment process, but people—not algorithms—make all final hiring decisions. AI may assist with tasks like scheduling, screening for role alignment, or helping us manage large volumes of applications more efficiently. However, candidates are reviewed by a member of our recruitment team, and interviews and hiring decisions are always made by people. We’re committed to ensuring that technology enhances fairness, efficiency, and the candidate experience—never replaces genuine human judgment.

( Returnship@BMC )

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal AI DevSecOps Engineer
Principal AI DevSecOps Engineer

BMC Software • Pune District

Hybrid
INR 6,000,000 - 7,000,000
Associate Product Developer
Associate Product Developer

BMC Software • Pune City

On-site
INR 1,180,000
Application Security Engineer
Application Security Engineer

BMC Software • Pune City

On-site
INR 1,800,000 - 2,400,000
Full Stack Developer
Full Stack Developer

BMC Software, Inc. • Karnataka

Hybrid
INR 3,200,000 - 3,600,000
Sr DevOps Engineer - India
Sr DevOps Engineer - India

BMC Software, Inc. • Maharashtra

Hybrid
INR 3,399,000 - 3,909,000
Sr Product Developer - India
Sr Product Developer - India

BMC Software • Pune City

On-site
INR 3,316,000
Flexible work hours
Health insurance
Career development programs
+2
Java Full Stack Developer
Java Full Stack Developer

BMC Software, Inc. • Pune City

On-site
INR 1,726,000
Pay transparency
Career returnship program
Culturally diverse environment
Full Stack Developer
Full Stack Developer

BMC Software, Inc. • Pune District

Hybrid
INR 1,564,000 - 1,911,000
Senior Penetration Tester
Senior Penetration Tester

BMC Software, Inc. • Pune City

On-site
INR 3,380,000
Sr Fullstack Developer (Java/Python & React)
Sr Fullstack Developer (Java/Python & React)

BMC Software • Bengaluru

On-site
INR 2,889,000 - 3,909,000