Black Duck Software, Inc.

Application Security Engineer 2

Black Duck Software, Inc.
Apply
7 hours ago
Bengaluru, IndiaMid Level

Responsibilities

  • Develop comprehensive application security program roadmaps, maturity assessments, and framework-aligned reports.
  • Create visuals and documentation for capability maturity models and strategic planning.
  • Prepare executive summaries and strategic recommendations for leadership audiences.
  • Identify, track, and support remediation of vulnerabilities in third-party open-source components.
  • Conduct client-facing presentations and facilitate discussions that translate technical findings into actionable plans.

Requirements

  • 2–4 years of experience in application security, software assurance, or product security consulting.
  • Strong knowledge of BSIMM, NIST SSDF, or OWASP SAMM frameworks.
  • Experience with open-source software security, Software Bill of Materials standards and tools, and software supply chain transparency.
  • Experience developing or executing maturity models, capability assessments, or multi-year AppSec or DevSecOps roadmaps.
  • Hands-on experience with secure software development practices, SDLC, CI/CD pipelines, and code-level security controls.
  • Excellent verbal and written communication, presentation, and facilitation skills in client-facing environments.
  • Preferred: consulting experience with a Big Four firm, boutique AppSec consultancy, or internal software security governance team.
  • Preferred: experience in software supply chain risk management, AI/ML assurance, or DevSecOps pipeline design.
  • Preferred: software development background with Java, Python, or C# and experience working within secure SDLCs.
  • Preferred: CEH, CISSP, CSSLP, CISM, or equivalent certification.

Tech Stack

Categories

Black Duck Software, Inc.

About Black Duck Software, Inc.

1,001-5,000 employees

Black Duck Software builds application security tools and services for engineering and security teams, including SAST, SCA, and DAST to find vulnerabilities and licensing/compliance risks in proprietary and open-source code. It offers enterprise software plus on-demand audits and M&A due diligence, delivered in the cloud or on premises. The company is privately held and headquartered in Burlington, Massachusetts.

Contact me