Application Security Engineer 2
Job Summary
Black Duck Software Inc. helps organizations build secure high-quality software minimizing risks while maximizing speed and productivity. Black Duck a recognized pioneer in application security provides SAST SCA and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code open source components and application behavior. With a combination of industry-leading tools services and expertise only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.
About the Role
2 - 4 years of experience in application security software assurance or product security consulting.
Strong knowledge of frameworks such asBSIMM NIST SSDF or OWASP SAMM.
Experience with Open-Source Software (OSS) security including identification tracking and remediation of vulnerabilities in third-party components.
Familiarity with Software Bill of Materials (SBOM) standards and tools (e.g. SPDX CycloneDX) and their role in software supply chain transparency and compliance
Proven experience in developing or executing maturity models capability assessments or multi-year roadmaps for AppSec or DevSecOps programs.
Hands-on experience with secure software development practices including familiarity with SDLC CI/CD pipelines and code-level security controls.
Excellent verbal and written communication skills with the ability to translate technical findings into clear executive-level narratives and actionable plans.
Strong presentation and facilitation skills in client-facing environments.
Preferred:
Prior consulting experience with a Big Four boutique AppSec consultancy or internal software security governance team.
Experience in software supply chain risk management (SSCRM) AI/ML assurance or DevSecOps pipeline design.
Background in software development (e.g. Java Python C#) and experience working within secure SDLCs.
Industry certifications such as CEH CISSP CSSLP CISM or equivalent.
What Youll Deliver
Comprehensive AppSec Program Roadmaps maturity assessments and framework-aligned reports.
Visuals and documentation for capability maturity models and strategic planning.
Executive summaries and strategic recommendations tailored to leadership audiences.
Black Duck is an equal opportunity employer. We consider all applicants for employment without regard to race color national origin religion sex gender identity or expression age disability sexual orientation veteran or military service status or any other characteristic protected by applicable law. Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law.
Required Experience:
IC
About Company
Build high-quality, secure software with application security testing tools and services from Black Duck. We are a Gartner Magic Quadrant Leader in AppSec.