{"id":1147745,"url":"https://alion.io/job/bmc-software-application-security-engineer","title":"Application Security Engineer","company":{"id":58475,"name":"BMC Software","domain":"bmc.com","url":"https://alion.io/company/bmc-software","size_band":"5000+","is_staffing_agency":false,"is_intermediary":false,"ats_vendor":"Avature","truth_index":{"grade":"A","score":100,"open_postings":9,"ghost_share":0,"stale_share":0,"repost_share":0.111,"time_to_fill_p50_days":6,"computed_at":"2026-09-23T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"hybrid","remote_scope":null,"hiring_geo_confidence":"structured","locations":[],"countries":[],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":null,"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"CI/CD","optional":false},{"name":"CVSS","optional":false},{"name":"CWE","optional":false},{"name":"Db2","optional":false},{"name":"Go","optional":false},{"name":"JavaScript","optional":false},{"name":"LLM","optional":false},{"name":"OWASP","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Python","optional":false},{"name":"SBOM","optional":false},{"name":"Shift-Left","optional":false},{"name":"Shift-Left Security","optional":false},{"name":"Sonatype Nexus IQ","optional":false},{"name":"Threat Modeling","optional":false},{"name":"TypeScript","optional":false},{"name":"SLSA","optional":true}],"status":"live","first_seen_at":"2026-09-23T16:10:52Z","employer_posted_date":"2026-09-23","last_verified_at":"2026-09-23T19:56:35Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"CareerArc Code\nCA-SB\nHybrid: #LI-Hybrid\nBMC empowers nearly 80% of the Forbes Global 100 to accelerate business value, faster than humanly possible. Our industry-leading portfolio unlocks human and machine potential to drive business growth, innovation, and sustainable success. BMC does this in a simple and optimized way by connecting people, systems, and data that power the world’s largest organizations so they can seize a competitive advantage.\nWe are seeking a highly motivated Product Security Engineer with 5+ years of experience in product security, secure SDLC, vulnerability management, open-source governance, and security tooling. This individual contributor role will help strengthen product security practices across modern applications, APIs, mainframe-integrated systems, and emerging AI-enabled technologies.\nThe ideal candidate will partner closely with Product, Legal, and Compliance teams to ensure secure and compliant software delivery throughout the SDLC while supporting operational excellence across product security programs.\nHere is how, through this exciting role, YOU will contribute to BMC's and your own success:\n\nPerform secure design reviews, penetration testing, threat modeling, and risk based security assessments across web applications, APIs, thick clients, mainframe-integrated systems, and emerging LLM/AI-enabled technologies.\nExecute security testing aligned with OWASP Top 10, OWASP API Top 10, OWASP , LLM/AI Top 10, CWE Top 25, CVSS, and evolving threat landscapes.\nEvaluate open-source components for security, license, and compliance risks, and collaborate with Product, Engineering, Legal, Compliance, and OSPO stakeholders to address findings.\nOperate and support Software Composition Analysis platforms, including dependency analysis, software inventory management, software supply chain visibility, and SBOM generation and maintenance.\nSupport open-source governance processes, including intake reviews, approval workflows, exception management, policy enforcement, standards, procedures, and best practices.\nTriage, validate, prioritize, track, and report vulnerabilities identified through manual assessments and security scanning tools, supporting governance and metrics.\nPartner with development teams to drive remediation, perform retesting, improve secure-by-design practices, and advance shift-left security initiatives throughout the SDLC.\nIdentify and assess risks related to authentication, authorization, data protection, secure communications, integration patterns, and interactions with RACF, DB2, CICS, MQ, and related mainframe subsystems.\nAdminister and improve security tooling across SAST, DAST, SCA, container scanning, and secrets detection, including CI/CD integration, workflow automation, onboarding, reporting, developer adoption, and continuous process\nimprovement.\nTo ensure you’re set up for success, you will bring the following skillset & experience: \n\nBachelor’s degree in Computer Science, Cybersecurity, Software Engineering, or equivalent practical experience.\n5+ years of experience in Product Security, Software Security Engineering, or a related discipline.\nStrong understanding of SSDLC, DevSecOps, vulnerability management, secure architecture, and modern software delivery practices.\nHands-on experience with security testing and tooling across SAST, DAST, SCA, container security, secrets detection, and CI/CD integrations.\nExperience with SCA platforms such as FOSSA, Black Duck, Sonatype, JFrog , Xray, or similar solutions.\nKnowledge of open-source licensing, license compliance, SBOM concepts, software supply chain risks, and related governance processes.\nDeep understanding of OWASP Top 10, OWASP API Top 10, OWASP LLM/AI Top 10, CWE, CVSS, and risk-based vulnerability prioritization.\nProficiency in at least one programming or scripting language such as Python, Java, JavaScript/TypeScript, Go, Bash, or similar.\nStrong analytical, communication, stakeholder management, and problem?solving skills, with the ability to explain security and compliance concepts clearly to technical and non-technical audiences.\nWhilst these are nice to have, our team can help you develop in the following skills:\nExperience with software licensing governance, compliance programs, product\nsecurity operations, and open-source review processes.\nFamiliarity with supply chain security frameworks such as OpenSSF, NIST SSDF,\nand SLSA.\nRelevant certifications such as OSCP, OSCE, CRTP, GPEN, GXPN, CSSLP, CISSP,\nor equivalent security credentials.\nOur commitment to you!\nBMC’s culture is built around its people. We have 6000+ brilliant minds working together across the globe. You won’t be known just by your employee number, but for your true authentic self. BMC lets you be YOU!\nIf after reading the above, You’re unsure if you meet the qualifications of this role but are deeply excited about BMC and this team, we still encourage you to apply! We want to attract talents from diverse backgrounds and experience to ensure we face the world together with the best ideas!\nBMC is committed to equal opportunity employment regardless of race, age, sex, creed, color, religion, citizenship status, sexual orientation, gender, gender expression, gender identity, national origin, disability, marital status, pregnancy, disabled veteran or status as a protected veteran. If you need a reasonable accommodation for any part of the application and hiring process, visit the accommodation request page.\nBMC Software maintains a strict policy of not requesting any form of payment in exchange for employment opportunities, upholding a fair and ethical hiring process.\nAt BMC we believe in pay transparency and have set the midpoint of the salary band for this role at 2,841,000 INR. Actual salaries depend on a wide range of factors that are considered in making compensation decisions, including but not limited to skill sets; experience and training, licensure, and certifications; and other business and organizational needs.\nThe salary listed is just one component of BMC's employee compensation package. Other rewards may include a variable plan and country specific benefits.\nWe are committed to ensuring that our employees are paid fairly and equitably, and that we are transparent about our compensation practices.\n(Returnship@BMC)\nHad a break in your career? No worries. This role is eligible for candidates who have taken a break in their career and want to re-enter the workforce. If your expertise matches the above job, visit to https://bmcrecruit.avature.net/returnship know more and how to apply.\nMin salary\n2,130,750\nMid point salary\n2,841,000\nMax salary\n3,551,250\nMin Salary - NEW\n2,130,750\nMax Salary - NEW\n3,551,250","description_format":"text","description_chars":6707,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":true},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","IT Infrastructure","DevOps","IT Management"],"lifecycle":[{"event":"open","at":"2026-09-23T16:10:52Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":6,"reasons":["conf:3","win:early"],"computed_at":"2026-09-23T23:17:53Z"},"pay":null,"html_url":"https://alion.io/job/bmc-software-application-security-engineer","json_url":"https://alion.io/job/bmc-software-application-security-engineer.json","meta":{"generated_at":"2026-09-23T23:17:53Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers"}}