Black Duck Software, Inc. - Lead Incident Security Responder
Requirements
• At least 7 – 8 years of applicable experience in product security, application security, or security engineering, with hands-on depth in at least two of the following: secure SDLC, threat modeling, secure code review, vulnerability management, product incident response, or customer-facing product security work. • Working knowledge of application security tooling (SCA, SAST, DAST, secret scanning) and the vulnerabilities they catch. • Familiarity with at least one major cloud platform (AWS, Azure, or GCP) from a security perspective. • Awareness of AI and LLM security risks such as prompt injection, sensitive data exposure, and the OWASP Top 10 for LLM Applications. • Demonstrated ability to work independently under general guidance and to lead workstreams or small project teams without formal direct-report authority. • Practical use of AI and LLM tools to accelerate day-to-day security work (investigation, query drafting, secure code review, documentation), with sound judgment about when AI-generated output requires human validation before it is shared, shipped, or acted on. • Strong written and verbal communication skills, including the ability to explain technical security topics to engineers, security peers, and non-technical stakeholders; calm and steady under incident, audit, or customer-escalation pressure. • Bachelor’s degree in Computer Science, Information Security, Information Technology, or equivalent practical experience. • Experience contributing to a Product Security Incident Response Team (PSIRT) or equivalent product vulnerability response process. • Familiarity with vulnerability scoring (CVSS), embargo handling, and coordinated disclosure. • Industry certifications such as CISSP, CSSLP, GWAPT, GPEN, OSCP, OSWE, or cloud security equivalents are a plus. • Experience supporting customer security questionnaires, RFPs, or third-party risk assessments.
Responsibilities
• Partner with engineering teams building Black Duck SCA, Coverity, and adjacent products on architecture reviews, threat models, and security design feedback. • Contribute to a measurable secure development lifecycle covering SCA, SAST, secret scanning (GitGuardian), dependency hygiene, and build pipeline security. • Recommend systematic improvements when patterns emerge across the portfolio rather than relying on one-off fixes. • Triage internally discovered and externally reported product vulnerabilities and help drive resolution with engineering teams. • Coordinate vulnerability fixes with engineering and support customer-facing communications when needed. • Help triage customer security questionnaires, audit requests, and ad hoc product security questions in close partnership with the Director of Security Operations. • Draft technically accurate answers to customer security inquiries; gather evidence from engineering when needed. • Support detection engineering and incident response activities across the corporate environment, with a focus on issues that intersect with our products. • Maintain and tune detection content in CrowdStrike NG-SIEM and Sumo Logic related to product security risks; help work escalations from our MDR provider (ReliaQuest). • Contribute to SOAR automations and runbooks that reduce manual toil. • Lead discrete workstreams within larger security initiatives or coordinate small project teams where appropriate. • Track projects through Jira with clear milestones and concise status updates; provide technical input into vendor evaluations and POCs across the SecOps and AppSec stack. • Act as an informal resource and mentor for less experienced team members on product security, secure development, and threat modeling. • Explain difficult or sensitive technical information clearly to engineers, security peers, and non-technical stakeholders. • Document tribal knowledge into runbooks, SOPs, and onboarding materials. • Other tasks and activities as assigned. • Extensive use of the computer which involves viewing a monitor and keyboarding for most of the workday • Placing and receiving phone calls • Occasionally moving and lifting objects up to 20 pounds • May require some travel as needed. • $100,000—$150,000 CAD
Benefits
• $100,000—$150,000 CAD
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT