Lead product security work across Black Duck's portfolio, driving architecture reviews, threat models, vulnerability triage, and customer-facing security operations. Hands-on role combining AppSec depth with program coordination, detection engineering, and team mentorship.
7-8 years experience in product security, application security, or security engineering
Hands-on depth in at least two of: secure SDLC, threat modeling, secure code review, vulnerability management, product incident response, or customer-facing product security work
Working knowledge of application security tooling including SCA, SAST, DAST, and secret scanning
Familiarity with at least one major cloud platform from a security perspective
Awareness of AI and LLM security risks such as prompt injection and sensitive data exposure
Experience contributing to a PSIRT or equivalent product vulnerability response process
Familiarity with CVSS scoring, embargo handling, and coordinated disclosure
Bachelor's degree in Computer Science, Information Security, or equivalent practical experience
Partner with engineering teams on architecture reviews, threat models, and security design feedback for SCA, Coverity, and adjacent products
Contribute to measurable secure development lifecycle covering SCA, SAST, secret scanning, dependency hygiene, and build pipeline security
Triage internally discovered and externally reported product vulnerabilities and drive resolution with engineering teams
Coordinate vulnerability fixes with engineering and support customer-facing communications when needed
Triage customer security questionnaires, audit requests, and ad hoc product security questions
Draft technically accurate answers to customer security inquiries and gather evidence from engineering when needed
Join customer security calls as a subject matter expert and contribute to reusable response knowledge base
Maintain and tune detection content in CrowdStrike NG-SIEM and Sumo Logic related to product security risks
Work escalations from MDR provider ReliaQuest
Contribute to SOAR automations and runbooks that reduce manual toil
Lead discrete workstreams within larger security initiatives or coordinate small project teams
Track projects through Jira with clear milestones and concise status updates
Provide technical input into vendor evaluations and POCs across SecOps and AppSec stack
Act as informal resource and mentor for less experienced team members on product security and threat modeling
Document tribal knowledge into runbooks, SOPs, and onboarding materials
Reports to Director of Security Operations
Operates with broad autonomy under general guidance
Serves as informal technical resource for less experienced team members
May require occasional travel as needed
Black Duck is an equal opportunity employer
190,000 – 237,000 USD
/ year
90,000 – 110,000 CAD
/ year
150,000 – 200,000 USD
/ year
165,000 – 210,000 USD
/ year
120,000 – 160,000 USD
/ year