Black Duck
Lead Strategic Services Consultant (Application Security)
Burlington, MA (Remote)
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Lead / management
- Stated salary
- $123,500 – $185,000 per year
- Country
- US
- Work mode
- Remote-friendly
- First seen by hirly
- 10 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.
About the Role
We’re seeking a Lead Strategic Services Consultant with deep expertise in DevSecOps tooling, software security, processes, governance, maturity modeling, and framework-driven transformation planning. In this role, you’ll lead client engagements to assist in DevSecOps and CI/CD pipeline configuration and operations, assess Application Security Programs (AppSec Program) against established frameworks and design and deliver AppSec Program Strategic Roadmaps that help organizations build, scale, and measure their secure software development capabilities.
This position combines technical hands-on work with strategic consulting, framework alignment, and technical governance to translate assessment findings into actionable, measurable programs aligned to frameworks such as Building Security in Maturity Model (BSIMM) and NIST Secure Software Development Framework (SSDF).
Key Responsibilities
Assist customers with application security testing (AST) tool configurations in their pipeline through creation of templates and confirmation of configurations.
Provide customers triage support for AST finding from their pipeline testing.
Lead AppSec Program maturity assessments using frameworks such as BSIMM and SSDF, including stakeholder interviews, evidence collection, and scoring.
Develop Strategic Roadmaps that define the client’s target state, 12–36-month roadmap, resource requirements, and success metrics.
Facilitate workshops with executive, engineering, and AppSec leadership to prioritize initiatives and align to organizational risk and compliance goals.
Deliver strategic presentations and recommendations to CISOs, CTOs, and software leadership teams.
Contribute to internal frameworks, templates, and accelerators (e.g., AppSec Program Roadmap IP, maturity scoring tools, reporting dashboards).
Contribute to thought leadership through press commentary, webinars, or conference presentations on secure software governance and maturity advancement.
Qualifications Required:
US Citizenship or GC with 3 years of US residency and ability to pass a background check.
5–8+ years of experience in application security, software assurance, or product security consulting.
Application Security and Vulnerability Management skills
Gitlab CI/CD, Python, AWS, Grafana
Working knowledge of frameworks such as BSIMM, NIST SSDF or OWASP SAMM.
Proven experience developing or executing maturity models, capability assessments, or multi-year roadmaps for AppSec, Product Security, or DevSecOps programs.
Excellent client-facing communication, facilitation, and presentation skills.
Ability to synthesize technical findings into executive-level narratives and actionable plans.
Preferred:
Prior consulting experience with a Big Four, boutique AppSec consultancy, or internal software security governance team.
Experience in software supply chain risk management (SSCRM), AI/ML assurance, or DevSecOps pipeline design.
Experience developing software and functioning within secure development lifecycles (SDLCs)
Industry certifications such as CEH, CISSP, CISM
What You’ll Deliver
Hands on assistance with DevSecOps and CI/CD operations
Comprehensive AppSec Program Roadmap plans and assessments against frameworks reports and presentations.
Capability maturity and roadmap visuals.
Executive-level engagement summaries and strategic recommendations.
Pay Range
$123,500 — $185,000 USD
Black Duck is an equal opportunity employer. We consider all applicants for employment without regard to race, color, national origin, religion, sex, gender identity or expression, age, disability, sexual orientation, veteran or military service status, or any other characteristic protected by applicable law. Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law.
Similar jobs
- Lead Audit Services ConsultantBcbsla · Corporate - Baton Rouge, LAFirst seen today
- Lead Benefit Advisory Services ConsultantTriNet · Dublin, CA, United States; Irvine, CA, United States; Remote Location, United StatesFirst seen 4d agoremote
- Sr. Mainframe Software and Open Systems Client Services ConsultantBroadcom · 5 LocationsFirst seen today
- Senior Professional Services ConsultantJobgether · USFirst seen todayremote
- Professional Services Consultant IFortra · United StatesFirst seen yesterday
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job