About the job
At Black Duck Software, Inc., we empower organizations to develop secure, high-quality software, effectively minimizing risks while accelerating speed and productivity. As a recognized leader in application security, Black Duck offers advanced solutions including SAST, SCA, and DAST, enabling teams to swiftly identify and rectify vulnerabilities and defects in proprietary code, open-source components, and overall application behavior. Through our industry-leading tools, services, and expertise, we uniquely position organizations to enhance security and quality throughout the DevSecOps process and the entire software development life cycle.
Position Overview: Senior Application Security Engineer III
We are looking for a highly skilled Senior Application Security Consultant who possesses extensive knowledge in software security, secure development methodologies, governance, and framework-driven transformation planning. In this pivotal role, you will spearhead client engagements to evaluate Application Security Programs (AppSec) in accordance with established frameworks, delivering strategic roadmaps that facilitate organizations in constructing, scaling, and assessing their secure software development capabilities. This position integrates strategic consulting, technical governance, and development lifecycle expertise, translating assessment findings into actionable, measurable initiatives that align with frameworks like BSIMM and NIST SSDF.
Key Responsibilities:
- Lead AppSec Program maturity assessments using recognized frameworks such as BSIMM, NIST SSDF, and OWASP SAMM, encompassing stakeholder interviews, evidence gathering, and scoring.
- Design and implement Strategic Roadmaps that delineate target states, 12-36 month plans, resource requirements, and success metrics.
- Facilitate collaborative workshops with executive, engineering, and AppSec leadership to ensure initiatives align with organizational risk and compliance objectives.
- Present compelling, executive-level insights and recommendations to CISOs, CTOs, and software leadership teams.
- Contribute to the development of internal tools and accelerators (e.g., maturity scoring tools, roadmap templates, reporting dashboards).
- Support thought leadership endeavors through whitepapers, webinars, and conference presentations focused on secure software development and governance.

