Lead Strategic Services Consultant – Application Security

Job not on LinkedIn

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Black Duck

Black Duck

5001 - 10000 employees

🔒 Cybersecurity

☁️ SaaS

📋 Compliance

Cybersecurity • SaaS • Compliance

Black Duck is a leader in application security testing and software composition analysis. Now part of Synopsys Software Integrity Group, it offers a unified SaaS platform optimized for DevSecOps. Their solutions enable businesses to automate security testing across the entire software development life cycle, manage open source licenses and compliance, and secure the software supply chain. Recognized as a leader by Gartner and Forrester, Black Duck provides a range of services including static, dynamic, and interactive application security testing, as well as open source audits and risk management solutions.

📋 Description

• Assist customers with application security testing (AST) tool configurations in their pipeline through creation of templates and confirmation of configurations. • Provide customers triage support for AST findings from their pipeline testing. • Lead AppSec Program maturity assessments using frameworks such as BSIMM and SSDF, including stakeholder interviews, evidence collection, and scoring. • Develop Strategic Roadmaps defining the client’s target state, 12–36-month roadmap, resource requirements, and success metrics. • Facilitate workshops with executive, engineering, and AppSec leadership to prioritize initiatives and align with organizational risk and compliance goals. • Deliver strategic presentations and recommendations to CISOs, CTOs, and software leadership teams. • Contribute to internal frameworks, templates, and accelerators, including AppSec Program Roadmap IP, maturity scoring tools, and reporting dashboards. • Contribute to thought leadership through press commentary, webinars, or conference presentations on secure software governance and maturity advancement. • Deliver hands-on DevSecOps and CI/CD operations assistance, AppSec Program Roadmap plans and assessments, framework reports and presentations, capability maturity and roadmap visuals, and executive-level engagement summaries and strategic recommendations.

🎯 Requirements

• US Citizenship or Green Card with 3 years of US residency and ability to pass a background check. • 5–8+ years of experience in application security, software assurance, or product security consulting. • Application Security and Vulnerability Management skills. • Experience with GitLab CI/CD, Python, AWS, and Grafana. • Working knowledge of BSIMM, NIST SSDF, or OWASP SAMM frameworks. • Proven experience developing or executing maturity models, capability assessments, or multi-year roadmaps for AppSec, Product Security, or DevSecOps programs. • Excellent client-facing communication, facilitation, and presentation skills. • Ability to synthesize technical findings into executive-level narratives and actionable plans. • Preferred: consulting experience with a Big Four, boutique AppSec consultancy, or internal software security governance team. • Preferred: experience in software supply chain risk management, AI/ML assurance, or DevSecOps pipeline design. • Preferred: experience developing software and functioning within secure development lifecycles. • Preferred: industry certifications such as CEH, CISSP, or CISM.

Apply Now

Similar Jobs

🔥 0 minutes ago

Nebius Group

1001 - 5000

🤖 Artificial Intelligence

🏢 Enterprise

☁️ SaaS

Nebius builds cloud infrastructure for AI developers and enterprises. Transportation Security Lead securing US shipments, carriers, routes, and in-transit incidents.

🔥 5 minutes ago

GuidePoint Security

201 - 500

💼 Consulting

🏥 Healthcare

📦 Logistics

Microsoft security consulting engagement lead delivering Azure, Microsoft 365, and cloud security solutions for enterprise clients. Overseeing delivery teams, client relationships, architectures, compliance, and pre-sales engagements.

🔥 1 hour ago

Sargent & Lundy

1001 - 5000

🏗️ Construction

🎖️ Defense

⚡ Energy

Lead cyber security engineering for Sargent & Lundy’s nuclear power clients and digital plant systems. Review critical assets, implement controls, and guide automation and AI-enabled engineering workflows.

🔥 1 hour ago

CVS Health

10,000+ employees

🏥 Healthcare

⚕️ Healthcare Insurance

🛒 Retail

Senior Security Engineer investigating insider threats for CVS Health. Performing digital forensics, correlating security data, and supporting enterprise incident response.

🔥 2 hours ago

Aptive Resources

501 - 1000

🎖️ Defense

📦 Logistics

📣 Marketing

Aptive federal consulting ISSO overseeing cybersecurity compliance and ATO authorization for ICE health IT systems. Supporting risk management, continuous monitoring, and security governance.