Sobre esta vaga de Software Engineer 4 na Black Duck Software, Inc.
Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.
Company Background:
Black Duck Software, Inc. helps organizations build secure, high-quality software while minimizing risk and maximizing speed and productivity. As a recognized pioneer in application security, Black Duck provides SAST, SCA, and DAST solutions that help teams quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. Through industry-leading tools, services, and expertise, Black Duck helps organizations strengthen security and software quality throughout DevSecOps and the software development life cycle.
Key Responsibilities:
- Shape the solution architecture for the Integrations team, defining how agentic workflows, MCP surfaces, APIs, and multi-agent orchestration patterns work together across IDE, CI/CD, and pull request experiences.
- Identify opportunities to bring Black Duck’s SAST, SCA, and DAST capabilities into agentic developer workflows, then prototype, communicate, and deliver the highest-value solutions.
- Design and implement production-grade agentic workflows spanning agents, skills, tools, MCP servers, APIs, and reusable integration components.
- Own the technical evolution of the Black Duck MCP Gateway, expanding the tools and capabilities it provides to AI agents, IDEs, and developer platforms.
- Contribute to existing agentic capabilities, including SAST AI Fix Recommendation, by improving remediation guidance, fix generation, developer experience, and system reliability.
- Establish sound patterns for governance, authorization, permissions, data handling, observability, evaluation, and auditability in agentic systems.
- Build reliable integrations with source control, CI/CD, pull request, IDE, and AI-assisted development platforms.
- Review designs and implementations, raise engineering standards, and mentor engineers in agentic system design, API design, and modern integration patterns.
- Work across Product, Applied AI, and platform engineering to translate customer and developer needs into clear technical direction and deliverable solutions.
Required qualifications:
- Significant professional software engineering experience, including a demonstrated record of technical leadership on complex, cross-team systems.
- Hands-on experience building production agentic AI systems, including multi-agent orchestration, task decomposition, tool use, agent hand-offs, or comparable patterns using frameworks such as LangChain, LangGraph, PydanticAI, or equivalent technologies.
- Experience building or integrating Model Context Protocol servers, AI assistant tools, IDE extensions, plugin architectures, or comparable developer-facing tool systems.
- At least two years of hands-on experience applying LLMs in production workflows, including prompt engineering, retrieval-augmented generation, API-based model integration, structured outputs, or agent evaluation.
- Strong API and systems design skills, with experience shipping integrations, SDKs, reusable connectors, canonical models, or platform capabilities consumed by multiple systems.
- Experience with CI/CD, Git workflows, pull request automation, and modern developer tooling.
- A record of taking initiative and owning technical projects end to end, from identifying an opportunity and proposing a solution through design, implementation, launch, and ongoing improvement.
- Strong cross-functional communication skills and the ability to explain technical trade-offs to engineering, Product, Applied AI, and other stakeholders.
- Broad software engineering experience across one or more of Python, Java, and Go, along with APIs, distributed systems, and modern source control platforms such as GitHub, GitLab, Bitbucket, or Azure DevOps.
Preferred qualifications:
- Experience with application security, including SAST, SCA, DAST, ASPM, vulnerability management, or DevSecOps tooling.
- Experience with AI-assisted development tools such as GitHub Copilot, Claude Code, Cursor, or similar products.
- Deep technical experience with LLM integration, including vector databases and retrieval pipelines such as Pinecone, Weaviate, ChromaDB, Qdrant, or pgvector.
- Experience with function calling, tool schemas, structured output parsing, prompt versioning, model evaluation, and agent observability.
- Experience publishing and maintaining developer-facing packages through ecosystems such as npm or PyPI.
- Background contributing to open-source developer tooling, SDKs, integrations, or platform projects.
Black Duck is an equal opportunity employer. We consider all applicants for employment without regard to race, color, national origin, religion, sex, gender identity or expression, age, disability, sexual orientation, veteran or military service status, or any other characteristic protected by applicable law. Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law.