You need to set the ldapgroups setting on the app object instead of the ldapsearch setting. Set this to the DN of your LDAP group and your assignment should work. If you have a group inside a group then setting the nested group depth to 1 should be adequate for this to work.
Setting an ldapsearch query to an app object will not evaluate nested groups. If you want to do nested group assignments, you have to assign the application to the LDAP group object explicitly. This can be done from the command line by setting the --ldapgroups parameter on the application object. You can also do this from the SGD Admin Console by browsing your LDAP directory and assigning the LDAP group object to your application. For more details, have a look at the SGD admin guide: