Similar Jobs

See all

Position Summary:

  • Drives applied product security work across Black Duck’s portfolio, protecting products and supporting customer security inquiries to the Security Operations team.
  • Operates with broad autonomy under general guidance, leading complex security projects and partnering with the Director of Security Operations and engineering.

Essential Functions/Responsibilities:

  • Partners with engineering teams on architecture reviews, threat models, and security design feedback for products like SCA and Coverity.
  • Triages internally discovered and externally reported product vulnerabilities, coordinates fixes, and supports customer-facing communications.
  • Maintains and tunes detection content in CrowdStrike NG-SIEM and Sumo Logic, and contributes to SOAR automations to reduce manual toil.

Required Education/Experience & Skills:

  • At least 7-8 years of applicable experience in product security, application security, or security engineering with hands-on depth in secure SDLC or threat modeling.
  • Working knowledge of application security tooling (SCA, SAST, DAST, secret scanning) and familiarity with at least one major cloud platform (AWS, Azure, GCP).
  • Strong written and verbal communication skills, ability to work independently, and practical use of AI/LLM tools to accelerate security work.

Black Duck Software, Inc.

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. A recognized pioneer in application security with industry-leading tools and services, they partner with teams to maximize security and quality in DevSecOps.

Apply for This Position