NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Security Engineer in India
5 days ago
Apply with autofill
Apply with autofill
Blackduck·5 days ago
5 days ago

Application Security Engineer 2

Bengaluru, IndiaMid · 2-4 yearsSecurity Engineer

Sign up free to see how well your resume matches this role.

Boost your chances at blackduck

How you compare FREE

?
Your scoreYour score: not yet known
→
62
Top 10%Top 10%: 62 out of 100

Top 10% of NextRaise users matched against Security Engineer roles in India.

Must-have skills for this role

  • application security
  • software assurance
  • bsimm
  • nist ssdf

PDF or DOCX · no account needed

Apply faster with autofill FREEblackduck uses Greenhouse - autofill it instead of retyping.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Comprehensive AppSec Program Roadmaps, maturity assessments, and framework-aligned reports.
  • Visuals and documentation for capability maturity models and strategic planning.
  • Executive summaries and strategic recommendations tailored to leadership audiences.

What they're looking for

  • 2 - 4 years of experience in application security, software assurance, or product security consulting.
  • Strong knowledge of frameworks such as BSIMM, NIST SSDF, or OWASP SAMM.
  • Experience with Open-Source Software (OSS) security, including identification, tracking, and remediation of vulnerabilities in third-party components.
  • Familiarity with Software Bill of Materials (SBOM) standards and tools (e.g., SPDX, CycloneDX), and their role in software supply chain transparency and compliance
  • Proven experience in developing or executing maturity models, capability assessments, or multi-year roadmaps for AppSec or DevSecOps programs.
  • Hands-on experience with secure software development practices, including familiarity with SDLC, CI/CD pipelines, and code-level security controls.
  • Excellent verbal and written communication skills, with the ability to translate technical findings into clear, executive-level narratives and actionable plans.
  • Strong presentation and facilitation skills in client-facing environments.

Nice to have

  • Prior consulting experience with a Big Four, boutique AppSec consultancy, or internal software security governance team.
  • Experience in software supply chain risk management (SSCRM), AI/ML assurance, or DevSecOps pipeline design.
  • Background in software development (e.g., Java, Python, C#) and experience working within secure SDLCs.
  • Industry certifications such as CEH, CISSP, CSSLP, CISM, or equivalent.

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.

 

About the Role

2 - 4 years of experience in application security, software assurance, or product security consulting.

Strong knowledge of frameworks such as BSIMM, NIST SSDF, or OWASP SAMM.

Experience with Open-Source Software (OSS) security, including identification, tracking, and remediation of vulnerabilities in third-party components.  

Familiarity with Software Bill of Materials (SBOM) standards and tools (e.g., SPDX, CycloneDX), and their role in software supply chain transparency and compliance

Proven experience in developing or executing maturity models, capability assessments, or multi-year roadmaps for AppSec or DevSecOps programs.

Hands-on experience with secure software development practices, including familiarity with SDLC, CI/CD pipelines, and code-level security controls.

Excellent verbal and written communication skills, with the ability to translate technical findings into clear, executive-level narratives and actionable plans.

Strong presentation and facilitation skills in client-facing environments.

Preferred:

Prior consulting experience with a Big Four, boutique AppSec consultancy, or internal software security governance team.

Experience in software supply chain risk management (SSCRM), AI/ML assurance, or DevSecOps pipeline design.

Background in software development (e.g., Java, Python, C#) and experience working within secure SDLCs.

Industry certifications such as CEH, CISSP, CSSLP, CISM, or equivalent.

What You’ll Deliver

Comprehensive AppSec Program Roadmaps, maturity assessments, and framework-aligned reports.

Visuals and documentation for capability maturity models and strategic planning.

Executive summaries and strategic recommendations tailored to leadership audiences.

Black Duck is an equal opportunity employer. We consider all applicants for employment without regard to race, color, national origin, religion, sex, gender identity or expression, age, disability, sexual orientation, veteran or military service status, or any other characteristic protected by applicable law. Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law.

Company

Blackduck
Bengaluru, India

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Blackduck's careers site·first seen 15 Sept 2026·last verified 15 Sept 2026·How we source jobs

Similar jobs

  • Product Security Engineer at smithnephewPune, India–match not yet calculated
  • Senior Security Engineer at kestraEurope, India–match not yet calculated
  • L2 Security Engineer at HPE (Hewlett Packard Enterprise)Bengaluru, India–match not yet calculated
  • Network and Security Engineer at skillsoftHyderabad, India–match not yet calculated
  • Senior Security Engineer at ambient.aiBengaluru, India–match not yet calculated

Browse more jobs

  • Security Engineer jobs in India
  • Security Analyst jobs in India
  • Cloud Security Engineer jobs in India
  • Penetration Tester jobs in India
  • Security Engineer jobs in United States
  • Security Engineer jobs in United Kingdom