# Lead Strategic Services Consultant (Application Security) at Black Duck

- Company: Black Duck
- What the company does: Black Duck delivers True Scale Application Security — SAST, SCA, DAST, and AI-powered AppSec — to help security and development teams detect vulnerabilities, manage open source license risk, and secure the software supply chain. Trusted by 4,000+... Backed by General Catalyst.
- Company website: https://www.synopsys.com/software-integrity/security-testing/software-composition-analysis.html
- Type: Startups
- Level: Senior
- Location: Burlington, MA (Remote)
- Work setup: Remote
- Posted: 2026-08-18
- Apply by: 2026-10-08
- Apply: https://job-boards.greenhouse.io/blackduck/jobs/5385395008
- Page: https://www.1752.vc/careers/jobs/black-duck-lead-strategic-services-consultant-application-security/

## About the role

We’re seeking a Lead Strategic Services Consultant with deep expertise in DevSecOps tooling, software security, processes, governance, maturity modeling, and framework-driven transformation planning. In this role, you’ll lead client engagements to assist in DevSecOps and CI/CD pipeline configuration and operations, assess Application Security Programs (AppSec Program) against established frameworks and design and deliver AppSec Program Strategic Roadmaps that help organizations build, scale, and measure their...

## What they're looking for

- US Citizenship or GC with 3 years of US residency and ability to pass a background check
- 5–8+ years of experience in application security, software assurance, or product security consulting
- Application Security and Vulnerability Management skills
- Gitlab CI/CD, Python, AWS, Grafana
- Working knowledge of frameworks such as BSIMM, NIST SSDF or OWASP SAMM
- Proven experience developing or executing maturity models, capability assessments, or multi-year roadmaps for AppSec, Product Security, or DevSecOps programs

Tags: Customer Success (GQP)
