368,611open jobs
9,439companies
50,719added this week
Browse all
Salary
$104k – $256k per year (Estimated)
Location
Remote (Morocco)
Seniority
Staff · 8+ years exp
Overview
Company
Impact
Profile match
Black Duck Software is an application security company that specializes in automated solutions for securing and managing software code. The platform automates Software Composition Analysis (SCA), helping development and security teams detect security vulnerabilities, license compliance risks, and operational defects across open-source and third-party software components.

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.

About the Role

We’re seeking a Lead Strategic Services Consultant with deep expertise in DevSecOps tooling, software security, processes, governance, maturity modeling, and framework-driven transformation planning. In this role, you’ll lead client engagements to assist in DevSecOps and CI/CD pipeline configuration and operations, assess Application Security Programs (AppSec Program) against established frameworks and design and deliver AppSec Program Strategic Roadmaps that help organizations build, scale, and measure their secure software development capabilities.

This position combines technical hands-on work with strategic consulting, framework alignment, and technical governance to translate assessment findings into actionable, measurable programs aligned to frameworks such as Building Security in Maturity Model (BSIMM) and NIST Secure Software Development Framework (SSDF). 

Key Responsibilities

  • Assist customers with application security testing (AST) tool configurations in their pipeline through creation of templates and confirmation of configurations.
  • Provide customers triage support for AST finding from their pipeline testing.
  • Lead AppSec Program maturity assessments using frameworks such as BSIMM and SSDF, including stakeholder interviews, evidence collection, and scoring.
  • Develop Strategic Roadmaps that define the client’s target state, 12-36-month roadmap, resource requirements, and success metrics.
  • Facilitate workshops with executive, engineering, and AppSec leadership to prioritize initiatives and align to organizational risk and compliance goals.
  • Deliver strategic presentations and recommendations to CISOs, CTOs, and software leadership teams.
  • Contribute to internal frameworks, templates, and accelerators (e.g., AppSec Program Roadmap IP, maturity scoring tools, reporting dashboards).
  • Contribute to thought leadership through press commentary, webinars, or conference presentations on secure software governance and maturity advancement.

Qualifications Required:

  • US Citizenship or GC with 3 years of US residency and ability to pass a background check.
  • 5-8+ years of experience in application security, software assurance, or product security consulting.
  • Application Security and Vulnerability Management skills
  • Gitlab CI/CD, Python, AWS, Grafana
  • Working knowledge of frameworks such as BSIMM, NIST SSDF or OWASP SAMM.
  • Proven experience developing or executing maturity models, capability assessments, or multi-year roadmaps for AppSec, Product Security, or DevSecOps programs.
  • Excellent client-facing communication, facilitation, and presentation skills.
  • Ability to synthesize technical findings into executive-level narratives and actionable plans.

Preferred:

  • Prior consulting experience with a Big Four, boutique AppSec consultancy, or internal software security governance team.
  • Experience in software supply chain risk management (SSCRM), AI/ML assurance, or DevSecOps pipeline design.
  • Experience developing software and functioning within secure development lifecycles (SDLCs)
  • Industry certifications such as CEH, CISSP, CISM

What You’ll Deliver

  • Hands on assistance with DevSecOps and CI/CD operations
  • Comprehensive AppSec Program Roadmap plans and assessments against frameworks reports and presentations.
  • Capability maturity and roadmap visuals.
  • Executive-level engagement summaries and strategic recommendations.

Pay Range

$123,500—$185,000 USD

Black Duck is an equal opportunity employer. We consider all applicants for employment without regard to race, color, national origin, religion, sex, gender identity or expression, age, disability, sexual orientation, veteran or military service status, or any other characteristic protected by applicable law. Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,611 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Burlington
$110k – $131k per year • Remote • Full-Time • 10+ years exp • Bachelor's Degree
DevOps
AWS
Incident Management
VMWare
Apply
$118k – $142k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • El Segundo
C++
MATLAB
Python
SystemC
SystemVerilog
Verilog
VHDL
DevOps
CI/CD
QEMU
Chips/EDA
UVM
Apply
$129k – $232k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Austin
C++
DevOps
CI/CD
Git
RTOS
Apply
$169k – $321k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Phoenix
AI/ML
AI Agents
Anomaly Detection
LLM Guardrails
DevOps
AWS
Kong
Amazon S3
API Gateway
Cybersecurity
Zero Trust
Apply
$133k – $161k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Westminster
C++
Python
DevOps
CI/CD
SpaceTech
NASA cFS
Apply
$128k – $250k per year (Estimated) • Remote • 5+ years exp • Bachelor's Degree
Management
Confluence
Jira
Smartsheet
Marketing
Salesforce
Apply
Regional Field CTO 6 days ago
$164k – $312k per year (Estimated) • In office • Bachelor's Degree
AI/ML
Anomaly Detection
AI Agents
Human-in-the-Loop
Apply
$54k – $97k per year (Estimated) • In office • 7+ years exp • Bachelor's Degree
C#
C++
Java
DevOps
CI/CD
Apply
$13k – $42k per year (Estimated) • In office • 6+ years exp • Bachelor's Degree • Bengaluru
Python
DevOps
Ansible
AWS
CI/CD
Docker
Git
GitHub Actions
Jenkins
Kubernetes
GitHub
QA
Postman
Robot Framework
Selenium
Apply
In office • Bachelor's Degree • Singapore
C#
C++
Java
Perl
PowerShell
Python
DevOps
AWS
Azure
CI/CD
Docker
GCP
Kubernetes
Apply
$140k – $200k per year • In office • Burlington
Java
Kotlin
Mobile
Kotlin Multiplatform
DevOps
GCP
Apply
$140k – $200k per year • In office • PhD • Burlington
Swift
AI/ML
Text-to-Speech
Mobile
Fastlane
SwiftUI
DevOps
CI/CD
Git
Vercel
Apply
$86k – $143k per year • Remote/Hybrid • Full-Time • 7+ years exp • Bachelor's Degree • Buffalo • Washington • Baltimore • Burlington • Boston
Design
Figma
InVision
Sketch
Management
Miro
Apply
$111k – $145k per year • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Burlington
Robotics
AirSim
Management
Confluence
Jira
Apply
$120k – $160k per year • In office • Contractor • 7+ years exp • Burlington
Apply
See all jobs
This is one of many
368,611 more open roles from verified company boards, updated every day.