Black Duck delivers True Scale Application Security — SAST, SCA, DAST, and AI-powered AppSec — to help security and development teams detect vulnerabilities, manage open source license risk, and secure the software supply chain. Trusted by 4,000+... Backed by General Catalyst.
About the role
We’re seeking a Lead Strategic Services Consultant with deep expertise in DevSecOps tooling, software security, processes, governance, maturity modeling, and framework-driven transformation planning. In this role, you’ll lead client engagements to assist in DevSecOps and CI/CD pipeline configuration and operations, assess Application Security Programs (AppSec Program) against established frameworks and design and deliver AppSec Program Strategic Roadmaps that help organizations build, scale, and measure their...
What they're looking for
- US Citizenship or GC with 3 years of US residency and ability to pass a background check
- 5–8+ years of experience in application security, software assurance, or product security consulting
- Application Security and Vulnerability Management skills
- Gitlab CI/CD, Python, AWS, Grafana
- Working knowledge of frameworks such as BSIMM, NIST SSDF or OWASP SAMM
- Proven experience developing or executing maturity models, capability assessments, or multi-year roadmaps for AppSec, Product Security, or DevSecOps programs
More about this role
Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.
We’re seeking a Lead Strategic Services Consultant with deep expertise in DevSecOps tooling, software security, processes, governance, maturity modeling, and framework-driven transformation planning. In this role, you’ll lead client engagements to assist in DevSecOps and CI/CD pipeline configuration and operations, assess Application Security Programs (AppSec Program) against established frameworks and design and deliver AppSec Program Strategic Roadmaps that help organizations build, scale, and measure their secure software development capabilities.
This position combines technical hands-on work with strategic...
Browse similar: Startup jobs · Remote jobs