Application Security Engineer (Pune)

Application Security Engineer (Pune)

10 Sep
|
BMC Software
|
Pune

10 Sep

BMC Software

Pune

Basic Information

Job Name

Product Developer III - India

Country

India

State

IN_Maharashtra

City

Pune

Date Published

07-Sep-2026

Job ID

47487

Travel

You may occasionally be required to travel for business

Looking for details about our advantages?

Description and Requirements

CareerArc Code

CA-SB

Hybrid: #LI-Hybrid

BMC empowers nearly 80% of the Forbes Global 100 to accelerate business value, faster than humanly possible. Our industry-leading portfolio unlocks human and machine potential to drive business growth, innovation, and sustainable success. BMC does this in a straightforward and optimized way by connecting people, systems, and data that power the world’s largest organizations so they can seize a competitive advantage.

We are seeking a highly motivated Product Security Engineer with 5+ years of experience in product security, secure SDLC, vulnerability management, open-source governance, and security tooling. This individual contributor role will help strengthen product security practices across contemporary applications, APIs, mainframe-integrated systems, and emerging AI-enabled technologies.

The ideal candidate will partner closely with Product, Legal, and Compliance teams to ensure secure and compliant software delivery throughout the SDLC while supporting operational excellence across product security programs.

Here is how, through this exciting role, YOU will contribute to BMC's and your own success:

- Perform secure design reviews, penetration testing, threat modeling, and risk based security assessments across web applications, APIs, thick clients, mainframe-integrated systems, and emerging LLM/AI-enabled technologies.

- Execute security testing aligned with OWASP Top 10, OWASP API Top 10, OWASP , LLM/AI Top 10, CWE Top 25, CVSS, and evolving threat landscapes.

- Evaluate open-source components for security, license, and compliance risks, and collaborate with Product, Engineering, Legal, Compliance, and OSPO stakeholders to address findings.

- Operate and support Software Composition Analysis platforms, including dependency analysis, software inventory management, software supply chain visibility, and SBOM generation and maintenance.

- Support open-source governance processes, including intake reviews, approval workflows, exception management, policy enforcement, standards, procedures, and best practices.

- Triage, validate, prioritize, track, and report vulnerabilities identified through manual assessments and security scanning tools,



supporting governance and metrics.

- Partner with development teams to drive remediation, perform retesting, improve secure-by-design practices, and advance shift-left security initiatives throughout the SDLC.

- Identify and assess risks related to authentication, authorization, data protection, secure communications, integration patterns, and interactions with RACF, DB2, CICS, MQ, and related mainframe subsystems.

- Administer and improve security tooling across SAST, DAST, SCA, container scanning, and secrets detection, including CI/CD integration, workflow automation, onboarding, reporting, developer adoption, and continuous process

improvement.

To ensure you’re set up for success, you will bring the following skillset & experience:

- Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering, or equivalent practical experience.

- 5+ years of experience in Product Security, Software Security Engineering, or a related discipline.

- Strong understanding of SSDLC, DevSecOps, vulnerability management, secure architecture, and modern software delivery practices.

- Hands-on experience with security testing and tooling across SAST, DAST, SCA, container security, secrets detection, and CI/CD integrations.

- Experience with SCA platforms such as FOSSA, Black Duck, Sonatype, JFrog , Xray, or similar solutions.

- Knowledge of open-source licensing, license compliance, SBOM concepts, software supply chain risks, and related governance processes.

- Deep understanding of OWASP Top 10, OWASP API Top 10, OWASP LLM/AI Top 10, CWE, CVSS, and risk-based vulnerability prioritization.

- Proficiency in at least one programming or scripting language such as Python, Java, JavaScript/TypeScript, Go, Bash, or similar.

- Strong analytical, communication, stakeholder management, and problem?solving skills, with the ability to explain security and compliance concepts clearly to technical and non-technical audiences.

Whilst these are nice to have, our team can help you develop in the following skills:

- Experience with software licensing governance, compliance programs, product

security operations,



and open-source review processes.

- Familiarity with supply chain security frameworks such as OpenSSF, NIST SSDF,

and SLSA.

- Relevant certifications such as OSCP, OSCE, CRTP, GPEN, GXPN, CSSLP, CISSP,

or equivalent security credentials.

Our commitment to you!

BMC’s culture is built around its people. We have 6000+ brilliant minds working together across the globe. You won’t be known just by your employee number, but for your true authentic self. BMC lets you be YOU!

If after reading the above, You’re unsure if you meet the qualifications of this role but are deeply excited about BMC and this team, we still encourage you to apply! We want to attract talents from diverse backgrounds and experience to ensure we face the world together with the best ideas!

BMC is committed to equal opportunity employment regardless of race, age, sex, creed, color, religion, citizenship status, sexual orientation, gender, gender expression, gender identity, national origin, disability, marital status, pregnancy, disabled veteran or status as a protected veteran. If you need a reasonable accommodation for any part of the application and hiring process, visit the accommodation request page.

BMC Software maintains a strict policy of not requesting any form of payment in exchange for employment opportunities, upholding a fair and ethical hiring process.

At BMC we believe in pay transparency and have set the midpoint of the salary band for this role at 2,841,000 INR. Actual salaries depend on a wide range of factors that are considered in making compensation decisions, including but not limited to skill sets; experience and training, licensure, and certifications; and other business and organizational needs.

The salary listed is just one component of BMC's employee compensation package. Other rewards may include a variable plan and country specific benefits.

We are committed to ensuring that our employees are paid fairly and equitably, and that we are transparent about our compensation practices.

(Returnship@BMC)

Had a break in your career? No worries. This role is eligible for candidates who have taken a break in their career and want to re-enter the workforce. If your expertise matches the above job, visit to https://bmcrecruit.avature.net/returnship know more and how to apply.

Min salary

2,130,750

Mid point salary

2,841,000

Max salary

3,551,250

Min Salary - NEW

2,130,750

Max Salary - NEW

3,551,250

📌 Application Security Engineer (Pune)
🏢 BMC Software
📍 Pune

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: application security engineer (pune) / pune