Black Duck logo

Application Security Engineer

Black Duck

On-site
Bengaluru, Karnataka
Full-time
Mid Level
2+ yrs
Salary not listedPosted 19h ago

Real job — pulled straight from Black Duck’s careers page · Verified September 21, 2026 · No reposts.

Job description

Black Duck is hiring a Application Security Engineer — a full-time, based in Bengaluru, Karnataka role. Apply directly on Black Duck's careers page below.

Application Security Engineer 2

Location: Bengaluru, Karnataka, India

Department: 4140 - Customer Success (GQP)

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.

 

About the Role

2 - 4 years of experience in application security, software assurance, or product security consulting.

Strong knowledge of frameworks such as BSIMM, NIST SSDF, or OWASP SAMM.

Experience with Open-Source Software (OSS) security, including identification, tracking, and remediation of vulnerabilities in third-party components.

Familiarity with Software Bill of Materials (SBOM) standards and tools (e.g., SPDX, CycloneDX), and their role in software supply chain transparency and compliance

Proven experience in developing or executing maturity models, capability assessments, or multi-year roadmaps for AppSec or DevSecOps programs.

Hands-on experience with secure software development practices, including familiarity with SDLC, CI/CD pipelines, and code-level security controls.

Excellent verbal and written communication skills, with the ability to translate technical findings into clear, executive-level narratives and actionable plans.

Strong presentation and facilitation skills in client-facing environments.

Preferred:

Prior consulting experience with a Big Four, boutique AppSec consultancy, or internal software security governance team.

Experience in software supply chain risk management (SSCRM), AI/ML assurance, or DevSecOps pipeline design.

Background in software development (e.g., Java, Python, C#) and experience working within secure SDLCs.

Industry certifications such as CEH, CISSP, CSSLP, CISM, or equivalent.

What You’ll Deliver

Comprehensive AppSec Program Roadmaps, maturity assessments, and framework-aligned reports.

Visuals and documentation for capability maturity models and strategic planning.

Executive summaries and strategic recommendations tailored to leadership audiences.

Black Duck is an equal opportunity employer. We consider all applicants for employment without regard to race, color, national origin, religion, sex, gender identity or expression, age, disability, sexual orientation, veteran or military service status, or any other characteristic protected by applicable law. Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law.

Get Security Engineer jobs like this→

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
Target.com logo

Principal Threat Detection Operations Engineer

$168k–$303kBrooklyn Park, MN
✓ From careers page· 20h ago
Clarity Innovates logo

Senior Principal Software Engineer

$160k–$390kJessup, MD
✓ From careers page· 20h ago
Clarity Innovates logo

Senior Principal Software Engineer

$113k–$345kHerndon, VA
✓ From careers page· 20h ago
Fidelity Investments logo

Director, Data Platform

Durham, NC
✓ From careers page· 20h ago

Frequently asked questions

What skills are required for Application Security Engineer at Black Duck?

The required skills for Application Security Engineer at Black Duck include: DevSecOps, CI/CD, Java, Python, C#, CISSP, CISM.

What is the seniority level for Application Security Engineer at Black Duck?

Application Security Engineer at Black Duck is a Mid Level level position.

How do I apply for Application Security Engineer at Black Duck?

You can view the full description and apply for Application Security Engineer at Black Duck on EchoJobs: https://echojobs.io/job/black-duck-application-security-engineer-2-wvwea.