Check Your Resume Match Score
Scan your resume against ATS criteria for this Application Security Engineer role at BMC Software.
Apply for this position
Job Description
Basic Information
Job Name
Product Developer III - India
Country
India
State
IN_Maharashtra
City
Pune
Date Published
07-Sep-2026
Job ID
47487
Travel
You may occasionally be required to travel for business
Looking for details about our benefits?
Description and Requirements
CareerArc Code
CA-SB
BMC empowers nearly 80% of the Forbes Global 100 to accelerate business value, faster than humanly possible. Our industry-leading portfolio unlocks human and machine potential to drive business growth, innovation, and sustainable success. BMC does this in a simple and optimized way by connecting people, systems, and data that power the world’s largest organizations so they can seize a competitive advantage.
We are seeking a highly motivated Product Security Engineer with 5+ years of experience in product security, secure SDLC, vulnerability management, open-source governance, and security tooling. This individual contributor role will help strengthen product security practices across modern applications, APIs, mainframe-integrated systems, and emerging AI-enabled technologies.
The ideal candidate will partner closely with Product, Legal, and Compliance teams to ensure secure and compliant software delivery throughout the SDLC while supporting operational excellence across product security programs.
Here is how, through this exciting role, YOU will contribute to BMC's and your own success:
- Perform secure design reviews, penetration testing, threat modeling, and risk based security assessments across web applications, APIs, thick clients, mainframe-integrated systems, and emerging LLM/AI-enabled technologies.
- Execute security testing aligned with OWASP Top 10, OWASP API Top 10, OWASP , LLM/AI Top 10, CWE Top 25, CVSS, and evolving threat landscapes.
- Evaluate open-source components for security, license, and compliance risks, and collaborate with Product, Engineering, Legal, Compliance, and OSPO stakeholders to address findings.
- Operate and support Software Composition Analysis platforms, including dependency analysis, software inventory management, software supply chain visibility, and SBOM generation and maintenance.
- Support open-source governance processes, including intake reviews, approval workflows, exception management, policy enforcement, standards, procedures, and best practices.
- Triage, validate, prioritize, track, and report vulnerabilities identified through manual assessments and security scanning tools, supporting governance and metrics.
- Partner with development teams to drive remediation, perform retesting, improve secure-by-design practices, and advance shift-left security initiatives throughout the SDLC.
- Identify and assess risks related to authentication, authorization, data protection, secure communications, integration patterns, and interactions with RACF, DB2, CICS, MQ, and related mainframe subsystems.
- Administer and improve security tooling across SAST, DAST, SCA, container scanning, and secrets detection, including CI/CD integration, workflow automation, onboarding, reporting, developer adoption, and continuous process
improvement.
To ensure you’re set up for success, you will bring the following skillset & experience:
- Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering, or equivalent practical experience.
- 5+ years of experience in Product Security, Software Security Engineering, or a related discipline.
- Strong understanding of SSDLC, DevSecOps, vulnerability management, secure architecture, and modern software delivery practices.
- Hands-on experience with security testing and tooling across SAST, DAST, SCA, container security, secrets detection, and CI/CD integrations.
- Experience with SCA platforms such as FOSSA, Black Duck, Sonatype, JFrog , Xray, or similar solutions.
- Knowledge of open-source licensing, license compliance, SBOM concepts, software supply chain risks, and related governance processes.
- Deep understanding of OWASP Top 10, OWASP API Top 10, OWASP LLM/AI Top 10, CWE, CVSS, and risk-based vulnerability prioritization.
- Proficiency in at least one programming or scripting language such as Python, Java, JavaScript/TypeScript, Go, Bash, or similar.
- Strong analytical, communication, stakeholder management, and problem?solving skills, with the ability to explain security and compliance concepts clearly to technical and non-technical audiences.
Whilst these are nice to have, our team can help you develop in the following skills:
- Experience with software licensing governance, compliance programs, product
security operations, and open-source review processes.
- Familiarity with supply chain security frameworks such as OpenSSF, NIST SSDF,
and SLSA.
- Relevant certifications such as OSCP, OSCE, CRTP, GPEN, GXPN, CSSLP, CISSP,
or equivalent security credentials.
Our commitment to you!
BMC’s culture is built around its people. We have 6000+ brilliant minds working together across the globe. You won’t be known just by your employee number, but for your true authentic self. BMC lets you be YOU!
If after reading the above, You’re unsure if you meet the qualifications of this role but are deeply excited about BMC and this team, we still encourage you to apply! We want to attract talents from diverse backgrounds and experience to ensure we face the world together with the best ideas!
BMC is committed to equal opportunity employment regardless of race, age, sex, creed, color, religion, citizenship status, sexual orientation, gender, gender expression, gender identity, national origin, disability, marital status, pregnancy, disabled veteran or status as a protected veteran. If you need a reasonable accommodation for any part of the application and hiring process, visit the accommodation request page.
BMC Software maintains a strict policy of not requesting any form of payment in exchange for employment opportunities, upholding a fair and ethical hiring process.
At BMC we believe in pay transparency and have set the midpoint of the salary band for this role at 2,841,000 INR. Actual salaries depend on a wide range of factors that are considered in making compensation decisions, including but not limited to skill sets; experience and training, licensure, and certifications; and other business and organizational needs.
The salary listed is just one component of BMC's employee compensation package. Other rewards may include a variable plan and country specific benefits.
We are committed to ensuring that our employees are paid fairly and equitably, and that we are transparent about our compensation practices.
(
Returnship@BMC)
Had a break in your career? No worries. This role is eligible for candidates who have taken a break in their career and want to re-enter the workforce. If your expertise matches the above job, visit to https://bmcrecruit.avature.net/returnship know more and how to apply.
Min salary
2,130,750
Mid point salary
2,841,000
Max salary
3,551,250
Min Salary - NEW
2,130,750
Max Salary - NEW
3,551,250
Frequently Asked Questions
How to apply for Application Security Engineer at BMC Software?
Click the "Apply via CareerScan" button on this page.
What is the salary for this role?
Salary details will be discussed during the interview.
What experience is required?
13+ years of experience is required.
Is this position still open?
Yes, currently active and accepting applications.
Similar Openings
Explore related active roles in cyber security
Application Security Engineer
BMC Software · Maharashtra
