Lead Strategic Services Consultant (Application Security)

Black Duck Software, Inc.

$123K — $185K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • US Citizenship or Green Card with 3 years of US residency and ability to pass a background check.
  • 5-8+ years of experience in application security, software assurance, or product security consulting.
  • Expertise in Application Security and Vulnerability Management.
  • Familiarity with Gitlab CI/CD, Python, AWS, and Grafana.
  • Knowledge of frameworks such as BSIMM, NIST SSDF, or OWASP SAMM.
  • Experience in developing or executing maturity models and multi-year roadmaps for security programs.
  • Strong client-facing communication, facilitation, and presentation skills.

Responsibilities

  • Assist customers with configuring application security testing (AST) tools in their CI/CD pipelines.
  • Provide triage support for AST findings from client pipeline testing.
  • Lead maturity assessments of AppSec Programs using frameworks like BSIMM and SSDF.
  • Develop and define Strategic Roadmaps for clients including target state and success metrics.
  • Facilitate workshops to align security initiatives with organizational goals.
  • Deliver presentations and strategic recommendations to software leadership.
  • Contribute to internal frameworks, tools, and accelerators related to application security.

Benefits

  • Opportunities for hands-on technical work in a strategic consulting role.
  • Engage with executive leadership across various organizations.
  • Involvement in developing comprehensive security roadmaps.
  • Potential to contribute to thought leadership through speaking engagements and publications.
  • Flexibility in working on advanced security frameworks and tools.
Full Job Description
About the Role

We're seeking a Lead Strategic Services Consultant with deep expertise in DevSecOps tooling, software security, processes, governance, maturity modeling, and framework-driven transformation planning. In this role, you'll lead client engagements to assist in DevSecOps and CI/CD pipeline configuration and operations, assess Application Security Programs (AppSec Program) against established frameworks and design and deliver AppSec Program Strategic Roadmaps that help organizations build, scale, and measure their secure software development capabilities.

This position combines technical hands-on work with strategic consulting, framework alignment, and technical governance to translate assessment findings into actionable, measurable programs aligned to frameworks such as Building Security in Maturity Model (BSIMM) and NIST Secure Software Development Framework (SSDF).

Key Responsibilities
  • Assist customers with application security testing (AST) tool configurations in their pipeline through creation of templates and confirmation of configurations.
  • Provide customers triage support for AST finding from their pipeline testing.
  • Lead AppSec Program maturity assessments using frameworks such as BSIMM and SSDF, including stakeholder interviews, evidence collection, and scoring.
  • Develop Strategic Roadmaps that define the client's target state, 12-36-month roadmap, resource requirements, and success metrics.
  • Facilitate workshops with executive, engineering, and AppSec leadership to prioritize initiatives and align to organizational risk and compliance goals.
  • Deliver strategic presentations and recommendations to CISOs, CTOs, and software leadership teams.
  • Contribute to internal frameworks, templates, and accelerators (e.g., AppSec Program Roadmap IP, maturity scoring tools, reporting dashboards).
  • Contribute to thought leadership through press commentary, webinars, or conference presentations on secure software governance and maturity advancement.

Qualifications Required:
  • US Citizenship or GC with 3 years of US residency and ability to pass a background check.
  • 5-8+ years of experience in application security, software assurance, or product security consulting.
  • Application Security and Vulnerability Management skills
  • Gitlab CI/CD, Python, AWS, Grafana
  • Working knowledge of frameworks such as BSIMM, NIST SSDF or OWASP SAMM.
  • Proven experience developing or executing maturity models, capability assessments, or multi-year roadmaps for AppSec, Product Security, or DevSecOps programs.
  • Excellent client-facing communication, facilitation, and presentation skills.
  • Ability to synthesize technical findings into executive-level narratives and actionable plans.

Preferred:
  • Prior consulting experience with a Big Four, boutique AppSec consultancy, or internal software security governance team.
  • Experience in software supply chain risk management (SSCRM), AI/ML assurance, or DevSecOps pipeline design.
  • Experience developing software and functioning within secure development lifecycles (SDLCs)
  • Industry certifications such as CEH, CISSP, CISM

What You'll Deliver
  • Hands on assistance with DevSecOps and CI/CD operations
  • Comprehensive AppSec Program Roadmap plans and assessments against frameworks reports and presentations.
  • Capability maturity and roadmap visuals.
  • Executive-level engagement summaries and strategic recommendations.


Pay Range

$123,500-$185,000 USD

Similar Jobs

More Jobs at Black Duck Software, Inc.

More Information Technology Jobs

Find similar Lead Strategic Services Consultant (Application Security) jobs: