Lead Strategic Services Consultant (Application Security)

Black Duck

Burlington (MA)

Hybrid

USD 124,000 - 185,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Black Duck Software, Inc. seeks a Lead Strategic Services Consultant to drive DevSecOps transformation, CI/CD pipeline optimization, and AppSec maturity programs.

You will engage with clients to assess programs, design roadmaps, and align governance with BSIMM and NIST SSDF, delivering actionable recommendations at the executive level. Combining hands-on security tooling with strategic consulting, you will translate findings into measurable programs, facilitate leadership workshops, and

Qualifications

  • US Citizenship or GC with 3 years of US residency and ability to pass a background check.
  • 5–8+ years of experience in application security, software assurance, or product security consulting.
  • Experience with AST tooling and vulnerability management concepts.
  • Familiarity with BSIMM, NIST SSDF, or OWASP SAMM frameworks.
  • Proven ability to develop or execute maturity models and multi-year roadmaps for AppSec/DevSecOps.
  • Excellent client-facing communication, facilitation, and presentation skills.
  • Ability to translate technical findings into executive-level narratives and actionable plans.

Responsibilities

  • Assist customers with AST tool configurations in their pipeline via templates and configuration confirmations.
  • Provide triage support for AST findings from pipeline testing.
  • Lead AppSec Program maturity assessments using BSIMM and SSDF; conduct interviews, collect evidence, score results.
  • Develop Strategic Roadmaps defining target state, 12–36 month plan, resources, and success metrics.
  • Facilitate workshops with executive, engineering, and AppSec leadership to align initiatives with risk and compliance goals.
  • Deliver strategic presentations and recommendations to CISOs, CTOs, and software leaders.
  • Contribute to internal frameworks, templates, and accelerators; support thought leadership.

Skills

Python
AWS
Grafana
Executive communication

Tools

GitLab CI/CD

Job description

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.

About the Role

We’re seeking a Lead Strategic Services Consultant with deep expertise in DevSecOps tooling, software security, processes, governance, maturity modeling, and framework-driven transformation planning. In this role, you’ll lead client engagements to assist in DevSecOps and CI/CD pipeline configuration and operations, assess Application Security Programs (AppSec Program) against established frameworks and design and deliver AppSec Program Strategic Roadmaps that help organizations build, scale, and measure their secure software development capabilities. This position combines technical hands-on work with strategic consulting, framework alignment, and technical governance to translate assessment findings into actionable, measurable programs aligned to frameworks such as Building Security in Maturity Model (BSIMM) and NIST Secure Software Development Framework (SSDF).

Key Responsibilities
  • Assist customers with application security testing (AST) tool configurations in their pipeline through creation of templates and confirmation of configurations.
  • Provide customers triage support for AST finding from their pipeline testing.
  • Lead AppSec Program maturity assessments using frameworks such as BSIMM and SSDF, including stakeholder interviews, evidence collection, and scoring.
  • Develop Strategic Roadmaps that define the client’s target state, 12–36-month roadmap, resource requirements, and success metrics.
  • Facilitate workshops with executive, engineering, and AppSec leadership to prioritize initiatives and align to organizational risk and compliance goals.
  • Deliver strategic presentations and recommendations to CISOs, CTOs, and software leadership teams.
  • Contribute to internal frameworks, templates, and accelerators (e.g., AppSec Program Roadmap IP, maturity scoring tools, reporting dashboards).
  • Contribute to thought leadership through press commentary, webinars, or conference presentations on secure software governance and maturity advancement.
Qualifications Required
  • US Citizenship or GC with 3 years of US residency and ability to pass a background check.
  • 5–8+ years of experience in application security, software assurance, or product security consulting.
  • Application Security and Vulnerability Management skills: Gitlab CI/CD, Python, AWS, Grafana.
  • Working knowledge of frameworks such as BSIMM, NIST SSDF or OWASP SAMM.
  • Proven experience developing or executing maturity models, capability assessments, or multi-year roadmaps for AppSec, Product Security, or DevSecOps programs.
  • Excellent client-facing communication, facilitation, and presentation skills.
  • Ability to synthesize technical findings into executive-level narratives and actionable plans.
Preferred
  • Prior consulting experience with a Big Four, boutique AppSec consultancy, or internal software security governance team.
  • Experience in software supply chain risk management (SSCRM), AI/ML assurance, or DevSecOps pipeline design.
  • Experience developing software and functioning within secure development lifecycles (SDLCs).
  • Industry certifications such as CEH, CISSP, CISM.
What You’ll Deliver
  • Hands on assistance with DevSecOps and CI/CD operations.
  • Comprehensive AppSec Program Roadmap plans and assessments against frameworks reports and presentations.
  • Capability maturity and roadmap visuals.
  • Executive-level engagement summaries and strategic recommendations.
Pay Range

$123,500 — $185,000 USD

Black Duck is an equal opportunity employer. We consider all applicants for employment without regard to race, color, national origin, religion, sex, gender identity or expression, age, disability, sexual orientation, veteran or military service status, or any other characteristic protected by applicable law.

Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Strategic Services Consultant (Application Security)
Lead Strategic Services Consultant (Application Security)

Socket.dev • Burlington (MA)

On-site
USD 124,000 - 185,000
Lead Solutions Architect (East Coast)
Lead Solutions Architect (East Coast)

Black Duck Software, Inc. • Massachusetts

Hybrid
USD 123,000 - 186,000
Annual Performance Bonus
Paid Vacation and Wellness Days
Group Retirement Savings Plans
+1
Senior AppSec Strategy & DevSecOps Transformation Lead
Senior AppSec Strategy & DevSecOps Transformation Lead

Socket.dev • Burlington (MA)

On-site
USD 124,000 - 185,000
Lead Sales Engineer (South East)
Lead Sales Engineer (South East)

Blackduck • Jacksonville (FL)

On-site
USD 141,000 - 212,000
Senior AppSec Strategy Lead for DevSecOps & Roadmaps
Senior AppSec Strategy Lead for DevSecOps & Roadmaps

Black-Duck-Software • Atlanta (GA)

On-site
USD 124,000 - 185,000
Lead Sales Engineer
Lead Sales Engineer

Black Duck • Burlington (MA)

On-site
USD 141,000 - 212,000
Lead Sales Engineer (West Coast)
Lead Sales Engineer (West Coast)

Francisco Partners • Mountain View (CA)

On-site
USD 141,000 - 212,000
AppSec Strategy & Transformation Lead
AppSec Strategy & Transformation Lead

Black Duck • Burlington (MA)

Hybrid
USD 124,000 - 185,000
Lead Technical Account Manager
Lead Technical Account Manager

Francisco Partners • United States

On-site
USD 125,000 - 188,000
Lead Enterprise Account Executive-Strategic Account Management
Lead Enterprise Account Executive-Strategic Account Management

Black Duck Software, Inc. • Chicago (IL)

On-site
USD 130,000 - 196,000