Senior Application Security Consultant
24 hours ago
Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.
Senior Application Security Consultant
We're seeking a Senior Application Security Consultant with deep expertise in software security, secure development practices, governance, and framework-driven transformation planning. In this role, you will lead client engagements to assess Application Security Programs (AppSec) against industry frameworks and deliver strategic roadmaps that help organizations build, scale, and measure their secure software development capabilities. This position blends strategic consulting, technical governance, and development lifecycle expertise to translate assessment findings into actionable, measurable programs aligned with frameworks such as BSIMM and NIST SSDF.
Key Responsibilities
- Lead AppSec Program maturity assessments using frameworks like BSIMM, NIST SSDF, and OWASP SAMM, including stakeholder interviews, evidence collection, and scoring.
- Design and deliver Strategic Roadmaps outlining target states, 12–36-month plans, resource needs, and success metrics.
- Facilitate workshops with executive, engineering, and AppSec leadership to align initiatives with organizational risk and compliance goals.
- Deliver compelling, executive-level presentations and recommendations to CISOs, CTOs, and software leadership teams.
- Contribute to internal tools and accelerators (e.g., maturity scoring tools, roadmap templates, reporting dashboards).
- Support thought leadership through whitepapers, webinars, and conference presentations on secure software development and governance.
Qualifications
Must to have:
- 5 – 8 years of experience in application security, software assurance, or product security consulting.
- Strong knowledge of frameworks such as BSIMM, NIST SSDF, or OWASP SAMM.
- Experience with Open-Source Software (OSS) security, including identification, tracking, and remediation of vulnerabilities in third-party components.
- Familiarity with Software Bill of Materials (SBOM) standards and tools (e.g., SPDX, CycloneDX), and their role in software supply chain transparency and compliance
- Proven experience in developing or executing maturity models, capability assessments, or multi-year roadmaps for AppSec or DevSecOps programs.
- Hands-on experience with secure software development practices, including familiarity with SDLC, CI/CD pipelines, and code-level security controls.
- Excellent verbal and written communication skills, with the ability to translate technical findings into clear, executive-level narratives and actionable plans.
- Strong presentation and facilitation skills in client-facing environments.
Nice to have:
- Prior consulting experience with a Big Four, boutique AppSec consultancy, or internal software security governance team.
- Experience in software supply chain risk management (SSCRM), AI/ML assurance, or DevSecOps pipeline design.
- Background in software development (e.g., Java, Python, C#) and experience working within secure SDLCs.
- Industry certifications such as CEH, CISSP, CISM, or equivalent.
What You'll Deliver
- Comprehensive AppSec Program Roadmaps, maturity assessments, and framework-aligned reports.
- Visuals and documentation for capability maturity models and strategic planning.
- Executive summaries and strategic recommendations tailored to leadership audiences.
Black Duck considers all applicants for employment without regard to race, color, religion, sex, gender preference, national origin, age, disability, or status as a Covered Veteran in accordance with federal law. In addition, Black Duck complies with applicable state and local laws prohibiting discrimination in employment in every jurisdiction in which it maintains facilities. Black Duck also provides reasonable accommodation to individuals with a disability in accordance with applicable laws.
-
Senior Security Consultant
2 weeks ago
Bengaluru, Karnataka, India Payatu Full time ₹ 12,00,000 - ₹ 36,00,000 per yearAre you a skilled penetration tester looking for an exciting new opportunity to take your career to the next level? Join our dynamic cybersecurity team, where you'll have the chance to work on cutting-edge projects, including cloud security, reverse engineering, threat modelling, and product security.Who we are?Payatu is an ISO certified company where we...
-
Senior Field Consultant
6 days ago
Bengaluru, Karnataka, India Rubrik Security Cloud Full time ₹ 12,00,000 - ₹ 36,00,000 per yearAbout the role:As a Professional Services Field Consultant (FC), you will join our team as an essential contributor, helping our strategic customers successfully deploy and adopt Rubrik's data security and cyber resilience platform. This is a crucial, customer-facing role designed for a motivated individual ready to rapidly build expertise in modern hybrid...
-
Bengaluru, Karnataka, India UltraViolet Cyber Full time ₹ 12,00,000 - ₹ 36,00,000 per yearUltraViolet Cyber is a leading platform-enabled unified security operations company providing a comprehensive suite of security operations solutions. Founded and operated by security practitioners with decades of experience, the UltraViolet Cyber security-as-code platform combines technology innovation and human expertise to make advanced real-time...
-
Application Security Testing-Staff Consultant
2 weeks ago
Bengaluru, Karnataka, India UltraViolet Cyber Full time ₹ 15,00,000 - ₹ 25,00,000 per yearUltraViolet Cyber is a leading platform-enabled unified security operations company providing a comprehensive suite of security operations solutions. Founded and operated by security practitioners with decades of experience, the UltraViolet Cyber security-as-code platform combines technology innovation and human expertise to make advanced real-time...
-
Oracle HCM Cloud Application Security
2 weeks ago
Bengaluru, Karnataka, India Oracle Financial Services Software Ltd Full time ₹ 20,00,000 - ₹ 25,00,000 per yearSenior Principal Consultant - Oracle HCM Cloud Application Security & HCM Advanced Controls As an Oracle HCM Cloud Application Security & HCM Advanced Controls Consultant, you will be responsible for designing, implementing, and managing security frameworks and advanced control mechanisms within Oracle Human Capital Management (HCM) Cloud applications....
-
Application Security Testing-Staff Consultant
2 weeks ago
Bengaluru, Karnataka, India UltraViolet Cyber Full time ₹ 6,00,000 - ₹ 18,00,000 per yearUltraViolet Cyber is a leading platform-enabled unified security operations company providing a comprehensive suite of security operations solutions. Founded and operated by security practitioners with decades of experience, the UltraViolet Cyber security-as-code platform combines technology innovation and human expertise to make advanced real-time...
-
Senior Cyber Security Consultant
1 week ago
Bengaluru, Karnataka, India Aspire Highs Full time ₹ 12,00,000 - ₹ 30,00,000 per yearRequired Skills : Cybersecurity Architecture & Solutions, Technical Proficiency, Compliance & Regulatory Knowledge, Consulting & Communication Skills, Project & Business Acumen Work Mode : HYBRID Working Day : 5 Mandatory Criteria (Can't be neglected during screening) : - Need candidate having Fluent Japanese language proficiency. - Certifications...
-
Senior SAP Security Consultant
1 week ago
Bengaluru, Karnataka, India Two95 International Inc. Full time ₹ 12,00,000 - ₹ 36,00,000 per yearTitle: Senior SAP Security Consultant Job Type: Full Time Location: 100% Remote Work(India) Salary: Open (Base) We are seeking a highly skilled and experienced SAP Security Consultant to join our team. The SAP Security Consultant will play a critical role in ensuring the security and compliance of our SAP systems. The ideal candidate will have a deep...
-
Senior Information Security Consultant
1 day ago
Bengaluru, Karnataka, India RedHunt Labs Full time ₹ 15,00,000 - ₹ 25,00,000 per yearCompany DescriptionRedHunt Labs is a cybersecurity company focused on Attack Surface Management (ASM) and Penetration Testing. We help mid to large enterprises across the UK, US, India, and SE Asia discover unknown assets, monitor exposure, and validate risk. Our CTEM platform unifies ASM with vendor and subsidiary risk, Shadow SaaS discovery, risk rating,...
-
Web Application Security Consultant
7 days ago
Bengaluru, Karnataka, India MK IT Solutions Full time ₹ 12,00,000 - ₹ 36,00,000 per yearPosition 1: WebPT P1 - ConsultantExperience - 4+ YearsWork mode - 5 days working- Bangalore, Pune Hybrid (3 times in office per week) NP - ImmediatePosition Type - Contractual Roles & responsibilities:o Perform automated testing of running applications and static code (SAST, DAST).o Perform manual application penetration tests on one or more of the...