Lead Incident Security Responder
Black Duck Software, Inc.about 4 hours ago
Remote, CanadaSenior / Staff+
H1B Sponsor
Responsibilities
- Partner with engineering teams on architecture reviews and security design feedback.
- Contribute to a secure development lifecycle covering various security aspects.
- Triage product vulnerabilities and drive resolution with engineering teams.
- Coordinate vulnerability fixes and customer-facing communications.
- Draft accurate responses to customer security inquiries.
- Support detection engineering and incident response activities.
- Maintain detection content related to product security risks.
- Lead discrete workstreams within larger security initiatives.
- Track projects through Jira with clear milestones.
- Act as a mentor for less experienced team members.
- Document knowledge into runbooks and SOPs.
Requirements
- 7-8 years of experience in product security or related fields.
- Hands-on experience in secure SDLC, threat modeling, or vulnerability management.
- Knowledge of application security tooling and vulnerabilities.
- Familiarity with major cloud platforms from a security perspective.
- Understanding of AI and LLM security risks.
- Ability to work independently and lead small project teams.
- Strong written and verbal communication skills.
- Bachelor’s degree in a relevant field or equivalent experience.
- Experience with Product Security Incident Response Teams.
- Familiarity with vulnerability scoring and coordinated disclosure.
- Industry certifications are a plus.