Lead Incident Security Responder
Black Duck Software, Inc.Responsibilities
- Partner with engineering teams on architecture reviews, threat models, and security design feedback for Black Duck SCA, Coverity, and adjacent products.
- Improve the secure development lifecycle across SCA, SAST, secret scanning, dependency hygiene, and build pipeline security.
- Triage internally discovered and externally reported product vulnerabilities and coordinate fixes with engineering teams.
- Support customer security questionnaires, audit requests, product security questions, and customer security calls.
- Maintain and tune detection content in CrowdStrike NG-SIEM and Sumo Logic and work escalations from ReliaQuest.
- Contribute to SOAR automations and runbooks that reduce manual security operations work.
- Lead discrete security workstreams or coordinate small project teams and track milestones through Jira.
- Provide technical input into vendor evaluations and proofs of concept across the SecOps and AppSec stack.
- Mentor less experienced team members and document security knowledge in runbooks, SOPs, and onboarding materials.
Requirements
- At least 7–8 years of applicable experience in product security, application security, or security engineering.
- Hands-on depth in at least two areas including secure SDLC, threat modeling, secure code review, vulnerability management, product incident response, or customer-facing product security.
- Working knowledge of SCA, SAST, DAST, secret scanning, and the vulnerabilities they identify.
- Familiarity with AWS, Azure, or GCP from a security perspective.
- Awareness of AI and LLM security risks, including prompt injection, sensitive data exposure, and the OWASP Top 10 for LLM Applications.
- Experience working independently and leading workstreams or small project teams without formal direct-report authority.
- Practical experience using AI and LLM tools for security work with appropriate human validation.
- Strong written and verbal communication skills for technical and non-technical audiences.
- Bachelor’s degree in Computer Science, Information Security, Information Technology, or equivalent practical experience.
- Experience contributing to a PSIRT or equivalent product vulnerability response process.
- Familiarity with CVSS, embargo handling, and coordinated disclosure.
- Experience supporting customer security questionnaires, RFPs, or third-party risk assessments.
- Certifications such as CISSP, CSSLP, GWAPT, GPEN, OSCP, OSWE, or cloud security equivalents are preferred.
Benefits
- Pay range of $100,000–$150,000 CAD annually
- General office environment with occasional travel as needed
- Equal opportunity employer with reasonable disability accommodations
Tech Stack
Categories
About Black Duck Software, Inc.
Black Duck® meets the board-level risks of modern software with True Scale Application Security, ensuring uncompromised trust in software for the regulated, AI-powered world. Only Black Duck solutions free organizations from tradeoffs between speed, accuracy, and compliance at scale while eliminating security, regulatory, and licensing risks. Whether in the cloud or on premises, Black Duck is the only choice for securing mission-critical software everywhere code happens. With Black Duck, security leaders can make smarter decisions and unleash business innovation with confidence. Learn more at www.blackduck.com. Disclaimer: Please watch out for hiring fraud. Black Duck will never make initial contact with candidates through text or WhatsApp. Emails will come from an @blackduck.com address. You can verify openings and apply for roles through the Black Duck Careers page (https://www.blackduck.com/company/careers.html)