Application Security Engineer 3

Black Duck

Bengaluru

On-site

INR 1,500,000 - 2,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Black Duck in Bengaluru is seeking a Senior Application Security Consultant to lead client engagements in assessing Application Security Programs using industry frameworks. The role demands 5 to 8 years of experience in application security and proven skills in strategic consulting. Candidates must have a strong understanding of frameworks like BSIMM and NIST SSDF, along with hands-on experience in secure software development practices. The position offers the opportunity to influence the software security landscape within organizations.

Qualifications

  • 5 – 8 years of experience in application security, software assurance, or product security consulting.
  • Strong knowledge of frameworks such as BSIMM, NIST SSDF, or OWASP SAMM.
  • Proven experience in developing or executing maturity models for AppSec or DevSecOps programs.

Responsibilities

  • Lead AppSec Program maturity assessments using BSIMM, NIST SSDF, and OWASP SAMM frameworks.
  • Design and deliver Strategic Roadmaps outlining target states and success metrics.
  • Deliver executive-level presentations and recommendations to C-suite stakeholders.

Skills

Application Security Expertise
Framework Knowledge (BSIMM, NIST SSDF, OWASP SAMM)
Open-Source Software Security
Secure Software Development Practices
Excellent Communication Skills

Tools

SPDX
CycloneDX

Job description

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.

Application Security Engineer III

We’re seeking a Senior Application Security Consultant with deep expertise in software security, secure development practices, governance, and framework-driven transformation planning. In this role, you will lead client engagements to assess Application Security Programs (AppSec) against industry frameworks and deliver strategic roadmaps that help organizations build, scale, and measure their secure software development capabilities. This position blends strategic consulting, technical governance, and development lifecycle expertise to translate assessment findings into actionable, measurable programs aligned with frameworks such as BSIMM and NIST SSDF.

Key Responsibilities
  • Lead AppSec Program maturity assessments using frameworks like BSIMM, NIST SSDF, and OWASP SAMM, including stakeholder interviews, evidence collection, and scoring.
  • Design and deliver Strategic Roadmaps outlining target states, 12–36-month plans, resource needs, and success metrics.
  • Facilitate workshops with executive, engineering, and AppSec leadership to align initiatives with organizational risk and compliance goals.
  • Deliver compelling, executive-level presentations and recommendations to CISOs, CTOs, and software leadership teams.
  • Contribute to internal tools and accelerators (e.g., maturity scoring tools, roadmap templates, reporting dashboards).
  • Support thought leadership through whitepapers, webinars, and conference presentations on secure software development and governance.
Qualifications
  • 5 – 8 years of experience in application security, software assurance, or product security consulting.
  • Strong knowledge of frameworks such as BSIMM, NIST SSDF, or OWASP SAMM.
  • Experience with Open-Source Software (OSS) security, including identification, tracking, and remediation of vulnerabilities in third-party components.
  • Familiarity with Software Bill of Materials (SBOM) standards and tools (e.g., SPDX, CycloneDX), and their role in software supply chain transparency and compliance.
  • Proven experience in developing or executing maturity models, capability assessments, or multi-year roadmaps for AppSec or DevSecOps programs.
  • Hands‑on experience with secure software development practices, including familiarity with SDLC, CI/CD pipelines, and code-level security controls.
  • Excellent verbal and written communication skills, with the ability to translate technical findings into clear, executive-level narratives and actionable plans.
  • Strong presentation and facilitation skills in client-facing environments.
Nice To Have
  • Prior consulting experience with a Big Four, boutique AppSec consultancy, or internal software security governance team.
  • Experience in software supply chain risk management (SSCRM), AI/ML assurance, or DevSecOps pipeline design.
  • Background in software development (e.g., Java, Python, C#) and experience working within secure SDLCs.
  • Industry certifications such as CEH, CISSP, CISM, or equivalent.
What You’ll Deliver
  • Comprehensive AppSec Program Roadmaps, maturity assessments, and framework-aligned reports.
  • Visuals and documentation for capability maturity models and strategic planning.
  • Executive summaries and strategic recommendations tailored to leadership audiences.

Black Duck considers all applicants for employment without regard to race, color, religion, sex, gender preference, national origin, age, disability, or status as a Covered Veteran in accordance with federal law. In addition, Black Duck complies with applicable state and local laws prohibiting discrimination in employment in every jurisdiction in which it maintains facilities. Black Duck also provides reasonable accommodation to individuals with a disability in accordance with applicable laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Engineer 2
Application Engineer 2

Black Duck • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Customer Delivery Engineer 4
Customer Delivery Engineer 4

Black Duck Software, Inc. • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Implementation Engagement Manager
Implementation Engagement Manager

Black Duck Software, Inc. • Bengaluru

Hybrid
INR 1,000,000 - 2,000,000
Implementation Engagement Manager
Implementation Engagement Manager

Francisco Partners • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Senior Application Security Engineer
Senior Application Security Engineer

FloQast, Inc. • Pune District

On-site
INR 1,500,000 - 2,500,000
Sr. Manager, Sales Engineering (Enterprise, West Coast)
Sr. Manager, Sales Engineering (Enterprise, West Coast)

Black Duck Software, Inc. • India

Remote
INR 16,483,000 - 24,730,000
Lead Technical Account Manager
Lead Technical Account Manager

Black Duck • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Mentorship from industry leaders
Specialized training
Software Engineer 3
Software Engineer 3

Francisco Partners • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

DigiCert • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Generous time off policies
Top shelf benefits
Education, wellness, and lifestyle support
Technical Account Manager
Technical Account Manager

Black Duck • Bengaluru

On-site
INR 3,000,000 - 6,000,000