Jobs Companies Black Duck Software, Inc. Lead Incident Security Responder

Sobre este puesto de Lead Incident Security Responder en Black Duck Software, Inc.

Black Duck Software, Inc. · Remoto · Remote - Canada

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.

Lead Incident Security Responder

Position Summary

The Lead Incident Security Responder drives applied product security work across Black Duck’s portfolio, protecting our products and supporting the customer security inquiries that come into our Security Operations team. Operating with broad autonomy under general guidance, you lead portions of complex security projects, partner with the Director of Security Operations and the broader engineering organization, and serve as an informal technical resource for less experienced team members. The role requires hands-on product security depth combined with program coordination: delivering architecture reviews, threat models, vulnerability triage, and customer-facing security work, while also maintaining detection content, contributing to SOAR automations, and tracking projects through to measurable outcomes.

 

Essential Functions/Responsibilities

  • Partner with engineering teams building Black Duck SCA, Coverity, and adjacent products on architecture reviews, threat models, and security design feedback.
  • Contribute to a measurable secure development lifecycle covering SCA, SAST, secret scanning (GitGuardian), dependency hygiene, and build pipeline security.
  • Recommend systematic improvements when patterns emerge across the portfolio rather than relying on one-off fixes.
  • Triage internally discovered and externally reported product vulnerabilities and help drive resolution with engineering teams.
  • Coordinate vulnerability fixes with engineering and support customer-facing communications when needed.
  • Help triage customer security questionnaires, audit requests, and ad hoc product security questions in close partnership with the Director of Security Operations.
  • Draft technically accurate answers to customer security inquiries; gather evidence from engineering when needed.
  • Join customer security calls as a subject matter expert when called upon and contribute to a growing knowledge base of reusable responses.
  • Support detection engineering and incident response activities across the corporate environment, with a focus on issues that intersect with our products.
  • Maintain and tune detection content in CrowdStrike NG-SIEM and Sumo Logic related to product security risks; help work escalations from our MDR provider (ReliaQuest).
  • Contribute to SOAR automations and runbooks that reduce manual toil.
  • Lead discrete workstreams within larger security initiatives or coordinate small project teams where appropriate.
  • Track projects through Jira with clear milestones and concise status updates; provide technical input into vendor evaluations and POCs across the SecOps and AppSec stack.
  • Act as an informal resource and mentor for less experienced team members on product security, secure development, and threat modeling.
  • Explain difficult or sensitive technical information clearly to engineers, security peers, and non-technical stakeholders.
  • Document tribal knowledge into runbooks, SOPs, and onboarding materials.
  • Other tasks and activities as assigned.

 

Required Education/Experience & Skills

  • At least 7 – 8 years of applicable experience in product security, application security, or security engineering, with hands-on depth in at least two of the following: secure SDLC, threat modeling, secure code review, vulnerability management, product incident response, or customer-facing product security work.
  • Working knowledge of application security tooling (SCA, SAST, DAST, secret scanning) and the vulnerabilities they catch.
  • Familiarity with at least one major cloud platform (AWS, Azure, or GCP) from a security perspective.
  • Awareness of AI and LLM security risks such as prompt injection, sensitive data exposure, and the OWASP Top 10 for LLM Applications.
  • Demonstrated ability to work independently under general guidance and to lead workstreams or small project teams without formal direct-report authority.
  • Practical use of AI and LLM tools to accelerate day-to-day security work (investigation, query drafting, secure code review, documentation), with sound judgment about when AI-generated output requires human validation before it is shared, shipped, or acted on.
  • Strong written and verbal communication skills, including the ability to explain technical security topics to engineers, security peers, and non-technical stakeholders; calm and steady under incident, audit, or customer-escalation pressure.
  • Bachelor’s degree in Computer Science, Information Security, Information Technology, or equivalent practical experience.
  • Experience contributing to a Product Security Incident Response Team (PSIRT) or equivalent product vulnerability response process.
  • Familiarity with vulnerability scoring (CVSS), embargo handling, and coordinated disclosure.
  • Industry certifications such as CISSP, CSSLP, GWAPT, GPEN, OSCP, OSWE, or cloud security equivalents are a plus.
  • Experience supporting customer security questionnaires, RFPs, or third-party risk assessments.

 

Physical Requirements

General office environment and responsibilities requiring:

  • Extensive use of the computer which involves viewing a monitor and keyboarding for most of the workday
  • Placing and receiving phone calls
  • Occasionally moving and lifting objects up to 20 pounds
  • May require some travel as needed.

 

Pay Range
$100,000$150,000 CAD

Black Duck is an equal opportunity employer. We consider all applicants for employment without regard to race, color, national origin, religion, sex, gender identity or expression, age, disability, sexual orientation, veteran or military service status, or any other characteristic protected by applicable law. Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law.

¿Listo para postularte en Black Duck Software, Inc.?
Postúlate en Black Duck Software, Inc.

Sobre Black Duck Software, Inc.

Black Duck® offers the most comprehensive, powerful, and trusted portfolio of application security solutions in the industry. We have an unmatched track record of helping organizations around the world secure their software quickly, integrate security efficiently in their development environments, and safely innovate with new technologies. As the recognized leader, experts, and innovators in software security, Black Duck has everything you need to build trust in your software. Learn more at www.blackduck.com

 

For questions about Black Duck Software careers, including our inclusive hiring for people with disabilities or if you need assistance and/or reasonable accommodation during the recruitment process, please contact us at recruiting@blackduck.com

Ver todos los empleos en Black Duck Software, Inc. →

Empleos similares

Black Duck Software, Inc.
Principal Technical Account Manager
Black Duck Software, Inc.
⚡ Postúlate pronto Toronto, CA; Calgary, CA; Otta... Presencial CA$119,700–CA$179,600
● Nuevo 👁 Visto ✓ Postulado hace 10h
Black Duck Software, Inc.
Software Engineer 4 (C#,. Net core, CLR Internals)
Black Duck Software, Inc.
⚡ Postúlate pronto Bangalore Presencial
● Nuevo 👁 Visto ✓ Postulado hace 1d
Black Duck Software, Inc.
Enterprise Account Executive
Black Duck Software, Inc.
⚡ Postúlate pronto New Jersey, New York, Massachu... Presencial
● Nuevo 👁 Visto ✓ Postulado hace 1d
Black Duck Software, Inc.
Lead Enterprise Account Executive
Black Duck Software, Inc.
⚡ Postúlate pronto AL, FL, GA, KY, MS, NC, SC, TN... Presencial
● Nuevo 👁 Visto ✓ Postulado hace 1d
Black Duck Software, Inc.
Implementation Engagement Manager
Black Duck Software, Inc.
⚡ Postúlate pronto Hybrid, Bangalore Híbrido
● Nuevo 👁 Visto ✓ Postulado hace 1d
Black Duck Software, Inc.
Lead Regional Sales Manager-Federal Civilian
Black Duck Software, Inc.
⚡ Postúlate pronto Washington, DC; Virginia, Mary... Presencial $133,800–$200,700
● Nuevo 👁 Visto ✓ Postulado hace 1d
Black Duck Software, Inc.
DevOps Engineer 3
Black Duck Software, Inc.
⚡ Postúlate pronto Bangalore Presencial
● Nuevo 👁 Visto ✓ Postulado hace 1d
Black Duck Software, Inc.
Senior Data Scientist/Engineer
Black Duck Software, Inc.
⚡ Postúlate pronto Belfast, UK Presencial
● Nuevo 👁 Visto ✓ Postulado hace 1d
Black Duck Software, Inc.
Implementation Consultant
Black Duck Software, Inc.
⚡ Postúlate pronto Tokyo Presencial
● Nuevo 👁 Visto ✓ Postulado hace 1d

Regístrate para recibir sugerencias adaptadas a los empleos que abres y las búsquedas que guardas.

Más empleos en Black Duck Software, Inc.

Ver todos los empleos en Black Duck Software, Inc. →

Postúlate ahora
🤖

Un momento — para

JobsRadar se creó para personas reales que están pasando un mal momento en su búsqueda de empleo — no para solicitudes automatizadas. Estás haciendo clic demasiado rápido y ahora estás bloqueado temporalmente.

Vuelve más tarde. Si de verdad estás buscando empleo, cuentas con nosotros — solo compórtate como una persona.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Toma ventaja en tu búsqueda de empleo.

Únete a nuestro canal de Telegram para lo que te ayuda a conseguir el puesto — referencias salariales, el pulso semanal del mercado y avisos de nuevas funciones. Sin spam, solo señal.

Únete al canal — es gratis