
5001 - 10000 employees
🔒 Cybersecurity
☁️ SaaS
📋 Compliance
Cybersecurity • SaaS • Compliance
Black Duck is a leader in application security testing and software composition analysis. Now part of Synopsys Software Integrity Group, it offers a unified SaaS platform optimized for DevSecOps. Their solutions enable businesses to automate security testing across the entire software development life cycle, manage open source licenses and compliance, and secure the software supply chain. Recognized as a leader by Gartner and Forrester, Black Duck provides a range of services including static, dynamic, and interactive application security testing, as well as open source audits and risk management solutions.
🕒 August 18
🍂 Massachusetts – Remote
💵 $123.5k - $185k / year
⏰ Full Time
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
👻 Ghost score 0%
Improve your chances of getting an interview by checking your resume score before you apply.

5001 - 10000 employees
🔒 Cybersecurity
☁️ SaaS
📋 Compliance
Cybersecurity • SaaS • Compliance
Black Duck is a leader in application security testing and software composition analysis. Now part of Synopsys Software Integrity Group, it offers a unified SaaS platform optimized for DevSecOps. Their solutions enable businesses to automate security testing across the entire software development life cycle, manage open source licenses and compliance, and secure the software supply chain. Recognized as a leader by Gartner and Forrester, Black Duck provides a range of services including static, dynamic, and interactive application security testing, as well as open source audits and risk management solutions.
• Assist customers with application security testing (AST) tool configurations in their pipeline through creation of templates and confirmation of configurations. • Provide customers triage support for AST findings from their pipeline testing. • Lead AppSec Program maturity assessments using frameworks such as BSIMM and SSDF, including stakeholder interviews, evidence collection, and scoring. • Develop Strategic Roadmaps defining the client’s target state, 12–36-month roadmap, resource requirements, and success metrics. • Facilitate workshops with executive, engineering, and AppSec leadership to prioritize initiatives and align with organizational risk and compliance goals. • Deliver strategic presentations and recommendations to CISOs, CTOs, and software leadership teams. • Contribute to internal frameworks, templates, and accelerators, including AppSec Program Roadmap IP, maturity scoring tools, and reporting dashboards. • Contribute to thought leadership through press commentary, webinars, or conference presentations on secure software governance and maturity advancement. • Deliver hands-on DevSecOps and CI/CD operations assistance, AppSec Program Roadmap plans and assessments, framework reports and presentations, capability maturity and roadmap visuals, and executive-level engagement summaries and strategic recommendations.
• US Citizenship or Green Card with 3 years of US residency and ability to pass a background check. • 5–8+ years of experience in application security, software assurance, or product security consulting. • Application Security and Vulnerability Management skills. • Experience with GitLab CI/CD, Python, AWS, and Grafana. • Working knowledge of BSIMM, NIST SSDF, or OWASP SAMM frameworks. • Proven experience developing or executing maturity models, capability assessments, or multi-year roadmaps for AppSec, Product Security, or DevSecOps programs. • Excellent client-facing communication, facilitation, and presentation skills. • Ability to synthesize technical findings into executive-level narratives and actionable plans. • Preferred: consulting experience with a Big Four, boutique AppSec consultancy, or internal software security governance team. • Preferred: experience in software supply chain risk management, AI/ML assurance, or DevSecOps pipeline design. • Preferred: experience developing software and functioning within secure development lifecycles. • Preferred: industry certifications such as CEH, CISSP, or CISM.
Apply Now🕒 August 18
Lead cyber security engineering for Sargent & Lundy’s nuclear power clients and digital plant systems. Review critical assets, implement controls, and guide automation and AI-enabled engineering workflows.
🇺🇸 United States – Remote
💵 $118k - $180.3k / year
⏰ Full Time
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
🕒 August 18
Aptive federal consulting ISSO overseeing cybersecurity compliance and ATO authorization for ICE health IT systems. Supporting risk management, continuous monitoring, and security governance.
🕒 August 18
Security Engineer developing controls, automation, and infrastructure protections for Paylocity’s cloud-based HR and payroll software. Administering security platforms across hybrid on-premise and cloud environments.
🇺🇸 United States – Remote
💵 $83k - $135k / year
💰 $10M Venture Round - Paylocity on 2008-05
⏰ Full Time
🟡 Mid-level
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
🕒 August 18
Senior Security Engineer securing Credit Sesame’s AI-powered financial wellness platform. Building AppSec, cloud security, incident response, compliance, detection, and LLM threat-modeling programs.
🇺🇸 United States – Remote
💵 $170k - $215k / year
⏰ Full Time
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
🕒 August 18
Senior Security Architect engineering SIEM, SOAR, EDR, and cloud security services for Bespin Global US. Advising customers, leading onboarding, and shaping managed detection practice architecture.