Black Duck Logo

Black Duck

Lead Strategic Services Consultant (Application Security)

Posted 26 Days Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in Burlington, MA
124K-185K Annually
Senior level
In-Office or Remote
Hiring Remotely in Burlington, MA
124K-185K Annually
Senior level
Leads client engagements focused on application security and DevSecOps transformation. Configures application security testing tools in CI/CD pipelines, supports vulnerability triage, conducts maturity assessments using BSIMM and NIST SSDF, and develops multi-year strategic roadmaps. Facilitates executive workshops, presents recommendations to security and engineering leaders, creates maturity models and dashboards, and contributes to thought leadership on secure software governance.
The summary above was generated by AI

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.

About the Role

We’re seeking a Lead Strategic Services Consultant with deep expertise in DevSecOps tooling, software security, processes, governance, maturity modeling, and framework-driven transformation planning. In this role, you’ll lead client engagements to assist in DevSecOps and CI/CD pipeline configuration and operations, assess Application Security Programs (AppSec Program) against established frameworks and design and deliver AppSec Program Strategic Roadmaps that help organizations build, scale, and measure their secure software development capabilities.

This position combines technical hands-on work with strategic consulting, framework alignment, and technical governance to translate assessment findings into actionable, measurable programs aligned to frameworks such as Building Security in Maturity Model (BSIMM) and NIST Secure Software Development Framework (SSDF). 

Key Responsibilities

  • Assist customers with application security testing (AST) tool configurations in their pipeline through creation of templates and confirmation of configurations.
  • Provide customers triage support for AST finding from their pipeline testing.
  • Lead AppSec Program maturity assessments using frameworks such as BSIMM and SSDF, including stakeholder interviews, evidence collection, and scoring.
  • Develop Strategic Roadmaps that define the client’s target state, 12–36-month roadmap, resource requirements, and success metrics.
  • Facilitate workshops with executive, engineering, and AppSec leadership to prioritize initiatives and align to organizational risk and compliance goals.
  • Deliver strategic presentations and recommendations to CISOs, CTOs, and software leadership teams.
  • Contribute to internal frameworks, templates, and accelerators (e.g., AppSec Program Roadmap IP, maturity scoring tools, reporting dashboards).
  • Contribute to thought leadership through press commentary, webinars, or conference presentations on secure software governance and maturity advancement.

Qualifications Required:

  • US Citizenship or GC with 3 years of US residency and ability to pass a background check.
  • 5–8+ years of experience in application security, software assurance, or product security consulting.
  • Application Security and Vulnerability Management skills
  • Gitlab CI/CD, Python, AWS, Grafana
  • Working knowledge of frameworks such as BSIMM, NIST SSDF or OWASP SAMM.
  • Proven experience developing or executing maturity models, capability assessments, or multi-year roadmaps for AppSec, Product Security, or DevSecOps programs.
  • Excellent client-facing communication, facilitation, and presentation skills.
  • Ability to synthesize technical findings into executive-level narratives and actionable plans.

Preferred:

  • Prior consulting experience with a Big Four, boutique AppSec consultancy, or internal software security governance team.
  • Experience in software supply chain risk management (SSCRM), AI/ML assurance, or DevSecOps pipeline design.
  • Experience developing software and functioning within secure development lifecycles (SDLCs)
  • Industry certifications such as CEH, CISSP, CISM

What You’ll Deliver

  • Hands on assistance with DevSecOps and CI/CD operations
  • Comprehensive AppSec Program Roadmap plans and assessments against frameworks reports and presentations.
  • Capability maturity and roadmap visuals.
  • Executive-level engagement summaries and strategic recommendations.
Pay Range
$123,500$185,000 USD

Black Duck is an equal opportunity employer. We consider all applicants for employment without regard to race, color, national origin, religion, sex, gender identity or expression, age, disability, sexual orientation, veteran or military service status, or any other characteristic protected by applicable law. Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law.

Similar Jobs

3 Hours Ago
Remote or Hybrid
United States
112K-186K Annually
Senior level
112K-186K Annually
Senior level
Artificial Intelligence • Automotive • Greentech • Information Technology • Machine Learning • Software • Cybersecurity
Leads strategic process-improvement initiatives across digital marketplace operations. Maps current and future-state processes, conducts data analysis, develops business cases, manages improvement roadmaps, and oversees cross-functional project delivery. Partners with finance, analytics, and business stakeholders to influence priorities, implement changes, measure outcomes, and improve adoption. Requires strong communication, process design, executive presentation, and change-management skills.
Top Skills: AIGenesysLucidchartPower BISalesforceTableauVisio
3 Hours Ago
Remote or Hybrid
United States
81K-122K Annually
Senior level
81K-122K Annually
Senior level
Artificial Intelligence • Automotive • Greentech • Information Technology • Machine Learning • Software • Cybersecurity
Administer and improve Workday and multi-platform HR security, including role-based access, security groups, access reviews, request approvals, audit support, governance documentation, and compliance controls. Evaluate elevated access requests, identify risks, resolve routine issues, coordinate remediation, and escalate complex decisions. Partner with HR, IT, Legal, and Compliance stakeholders to strengthen policies, processes, and least-privilege access across Workday, Peakon, UKG, Prism, and HR data platforms.
Top Skills: Cei Hr OdsExcelMicrosoft FabricPeakonPower BIPrismSailpointServicenowSharepointTableauUkgWorkday
3 Hours Ago
Remote or Hybrid
Massachusetts, USA
75K-113K Annually
Mid level
75K-113K Annually
Mid level
Artificial Intelligence • Automotive • Greentech • Information Technology • Machine Learning • Software • Cybersecurity
Manages a portfolio of automotive dealership clients, driving product adoption, revenue retention, upgrades, and account growth. Builds client relationships, identifies risks, resolves complex issues, analyzes performance, recommends improvements, and supports client business objectives. Conducts virtual engagements and occasional onsite visits, provides product training, collaborates internally, mentors newer managers, and participates in workshops, webinars, vendor events, and special projects. The regional role covers Connecticut, Rhode Island, Massachusetts, and surrounding states.
Top Skills: Microsoft Office SuiteScreen Sharing SoftwareWeb-Based Systems

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account