BMC Software

Application Security Engineer

Maharashtra
13+ years exp
Day Shift
Posted 17h ago
0 views
Actively Hiring Direct 1-Click Apply

Check Your Resume Match Score

Scan your resume against ATS criteria for this Application Security Engineer role at BMC Software.

Apply for this position

Apply on Company Website

Job Description

Basic Information

Job Name

Product Developer III - India

Country

India

State

IN_Maharashtra

City

Pune

Date Published

07-Sep-2026

Job ID

47487

Travel

You may occasionally be required to travel for business

Looking for details about our benefits?

Description and Requirements

CareerArc Code

CA-SB

BMC empowers nearly 80% of the Forbes Global 100 to accelerate business value, faster than humanly possible. Our industry-leading portfolio unlocks human and machine potential to drive business growth, innovation, and sustainable success. BMC does this in a simple and optimized way by connecting people, systems, and data that power the world’s largest organizations so they can seize a competitive advantage.

We are seeking a highly motivated Product Security Engineer with 5+ years of experience in product security, secure SDLC, vulnerability management, open-source governance, and security tooling. This individual contributor role will help strengthen product security practices across modern applications, APIs, mainframe-integrated systems, and emerging AI-enabled technologies.


The ideal candidate will partner closely with Product, Legal, and Compliance teams to ensure secure and compliant software delivery throughout the SDLC while supporting operational excellence across product security programs.


Here is how, through this exciting role, YOU will contribute to BMC's and your own success:
  • Perform secure design reviews, penetration testing, threat modeling, and risk based security assessments across web applications, APIs, thick clients, mainframe-integrated systems, and emerging LLM/AI-enabled technologies.

  • Execute security testing aligned with OWASP Top 10, OWASP API Top 10, OWASP , LLM/AI Top 10, CWE Top 25, CVSS, and evolving threat landscapes.

  • Evaluate open-source components for security, license, and compliance risks, and collaborate with Product, Engineering, Legal, Compliance, and OSPO stakeholders to address findings.

  • Operate and support Software Composition Analysis platforms, including dependency analysis, software inventory management, software supply chain visibility, and SBOM generation and maintenance.

  • Support open-source governance processes, including intake reviews, approval workflows, exception management, policy enforcement, standards, procedures, and best practices.

  • Triage, validate, prioritize, track, and report vulnerabilities identified through manual assessments and security scanning tools, supporting governance and metrics.

  • Partner with development teams to drive remediation, perform retesting, improve secure-by-design practices, and advance shift-left security initiatives throughout the SDLC.

  • Identify and assess risks related to authentication, authorization, data protection, secure communications, integration patterns, and interactions with RACF, DB2, CICS, MQ, and related mainframe subsystems.

  • Administer and improve security tooling across SAST, DAST, SCA, container scanning, and secrets detection, including CI/CD integration, workflow automation, onboarding, reporting, developer adoption, and continuous process

improvement.


To ensure you’re set up for success, you will bring the following skillset & experience:
  • Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering, or equivalent practical experience.
  • 5+ years of experience in Product Security, Software Security Engineering, or a related discipline.
  • Strong understanding of SSDLC, DevSecOps, vulnerability management, secure architecture, and modern software delivery practices.
  • Hands-on experience with security testing and tooling across SAST, DAST, SCA, container security, secrets detection, and CI/CD integrations.
  • Experience with SCA platforms such as FOSSA, Black Duck, Sonatype, JFrog , Xray, or similar solutions.
  • Knowledge of open-source licensing, license compliance, SBOM concepts, software supply chain risks, and related governance processes.
  • Deep understanding of OWASP Top 10, OWASP API Top 10, OWASP LLM/AI Top 10, CWE, CVSS, and risk-based vulnerability prioritization.
  • Proficiency in at least one programming or scripting language such as Python, Java, JavaScript/TypeScript, Go, Bash, or similar.
  • Strong analytical, communication, stakeholder management, and problem?solving skills, with the ability to explain security and compliance concepts clearly to technical and non-technical audiences.

Whilst these are nice to have, our team can help you develop in the following skills:
  • Experience with software licensing governance, compliance programs, product

security operations, and open-source review processes.

  • Familiarity with supply chain security frameworks such as OpenSSF, NIST SSDF,

and SLSA.

  • Relevant certifications such as OSCP, OSCE, CRTP, GPEN, GXPN, CSSLP, CISSP,

or equivalent security credentials.

Our commitment to you!


BMC’s culture is built around its people. We have 6000+ brilliant minds working together across the globe. You won’t be known just by your employee number, but for your true authentic self. BMC lets you be YOU!


If after reading the above, You’re unsure if you meet the qualifications of this role but are deeply excited about BMC and this team, we still encourage you to apply! We want to attract talents from diverse backgrounds and experience to ensure we face the world together with the best ideas!


BMC is committed to equal opportunity employment regardless of race, age, sex, creed, color, religion, citizenship status, sexual orientation, gender, gender expression, gender identity, national origin, disability, marital status, pregnancy, disabled veteran or status as a protected veteran. If you need a reasonable accommodation for any part of the application and hiring process, visit the accommodation request page.

BMC Software maintains a strict policy of not requesting any form of payment in exchange for employment opportunities, upholding a fair and ethical hiring process.


At BMC we believe in pay transparency and have set the midpoint of the salary band for this role at 2,841,000 INR. Actual salaries depend on a wide range of factors that are considered in making compensation decisions, including but not limited to skill sets; experience and training, licensure, and certifications; and other business and organizational needs.


The salary listed is just one component of BMC's employee compensation package. Other rewards may include a variable plan and country specific benefits.


We are committed to ensuring that our employees are paid fairly and equitably, and that we are transparent about our compensation practices.


(

Returnship@BMC

)

Had a break in your career? No worries. This role is eligible for candidates who have taken a break in their career and want to re-enter the workforce. If your expertise matches the above job, visit to https://bmcrecruit.avature.net/returnship know more and how to apply.

Min salary

2,130,750

Mid point salary

2,841,000

Max salary

3,551,250

Min Salary - NEW

2,130,750

Max Salary - NEW

3,551,250

Frequently Asked Questions

How to apply for Application Security Engineer at BMC Software?

Click the "Apply via CareerScan" button on this page.

What is the salary for this role?

Salary details will be discussed during the interview.

What experience is required?

13+ years of experience is required.

Is this position still open?

Yes, currently active and accepting applications.

Similar Openings

Explore related active roles in cyber security

View all
Actively Hiring
2 to 5 years of experience
Salary not disclosed
Bengaluru, Karnataka
cyber securityRotational Shift
Posted 17h ago
Apply Now
Actively Hiring
13+ years
Salary not disclosed
Mumbai, Maharashtra
cyber securityDay Shift
Posted 17h ago
Apply Now
Actively Hiring
6–8 years
Salary not disclosed
Delhi
cyber securityDay Shift
Posted 17h ago
Apply Now

Application Security Engineer

BMC Software · Maharashtra