368,611open jobs
9,439companies
50,719added this week
Browse all
Salary
$90k – $221k per year (Estimated)
Location
Remote (Canada)
Seniority
Staff · 8+ years exp
Overview
Company
Impact
Profile match
Black Duck Software is an application security company that specializes in automated solutions for securing and managing software code. The platform automates Software Composition Analysis (SCA), helping development and security teams detect security vulnerabilities, license compliance risks, and operational defects across open-source and third-party software components.

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.

Lead Product Security

Job Title:  Lead Product Security

Reports to (Direct Title):  Director of Security Operations

Department:  Cybersecurity

Position Summary

The Lead Product Security is the senior technical authority for how security is designed into Black Duck products. Operating with broad autonomy under general guidance, the role will lead secure architecture and design reviews, contribute to the threat modeling methodology, and set the standards and design gates that define what secure-by-default means for our engineering teams. A core part of the role is scaling security capability rather than absorbing security work: the role will help mature and evolve the Security Champions program, mentor engineers and less experienced security staff, and build the enablement content that lets product teams reason about security themselves. The Lead Product Security will also drive deep secure code review in high-risk areas, support external security assessments, partner with PSIRT on product vulnerability response, and measure product security maturity to guide a prioritized improvement roadmap.

Essential Functions/Responsibilities

  • Lead security architecture and design reviews for Black Duck SCA, Coverity, and adjacent product lines, delivering actionable feedback before implementation begins.
  • Contribute to the threat modeling methodology and help scale its adoption: coach engineers to run their own models and review outputs, rather than serving as the sole modeler.
  • Define security requirements, design gates, and product security baselines that give engineering a testable definition of secure-by-default.
  • Build and measure the secure development lifecycle across SCA, SAST, secret scanning (GitGuardian), dependency hygiene, and build pipeline integrity.
  • Perform deep secure code review on high-risk areas including authentication, authorization, cryptography, secrets handling, and input validation.
  • Secure the product supply chain and release process, including SBOM generation and the integrity of build and distribution artifacts.
  • Help mature and evolve the Security Champions program: recruit champions across product teams, grow the training and enablement curriculum, run office hours, and report on participation and outcomes.
  • Mentor engineers and less experienced security staff on secure design, secure code review, and threat modeling, growing capability across the organization rather than absorbing the work.
  • Assist with the scoping and coordination of penetration tests and third-party security assessments; triage findings and drive remediation to closure with engineering owners.
  • Partner with PSIRT on triage and fix coordination for internally discovered and externally reported product vulnerabilities, feeding root causes back into design and SDLC controls.
  • Measure product security maturity using BSIMM or SAMM style assessment and drive a prioritized improvement roadmap.
  • Support EU Cyber Resilience Act secure-by-design and vulnerability handling obligations with the technical evidence and process changes engineering needs.
  • Provide technical subject matter expertise on customer security questionnaires, audit requests, and security escalations, drafting accurate answers, gathering evidence from engineering, and building a reusable knowledge base of vetted responses.
  • Support incident response for issues that touch product code, build systems, or product infrastructure, contributing product-specific context and remediation guidance.
  • Lead discrete workstreams within larger product security initiatives, track milestones in Jira, and provide technical input into application security tooling evaluations and POCs.
  • Other tasks and activities as assigned.

Required Education/Experience & Skills

  • Awareness of AI and LLM security risks such as prompt injection, sensitive data exposure, and the OWASP Top 10 for LLM Applications.
  • Bachelor’s degree in Computer Science, Information Security, Information Technology, or equivalent practical experience.
  • 8+ years of experience in product security, application security, or software security engineering, with hands-on depth in secure design review, threat modeling, and secure code review.
  • Demonstrated experience building or running a security champions program, developer enablement initiative, or equivalent effort that scaled security capability across engineering teams.
  • Working knowledge of application security tooling (SCA, SAST, DAST, secret scanning), the vulnerability classes each detects, and where each produces false positives.
  • Practical secure coding and review experience in at least one language used in commercial software products, with the ability to read unfamiliar code and reason about security impact.
  • Experience defining security requirements, standards, or design gates that engineering teams actually adopted.
  • Familiarity with at least one major cloud platform (AWS, Azure, or GCP) from a product security perspective, including container and infrastructure-as-code security.
  • Experience coordinating penetration tests or third-party security assessments and driving findings through to remediation.
  • Demonstrated ability to mentor engineers and lead technical workstreams without formal direct-report authority.
  • Practical use of AI and LLM tools to accelerate day-to-day security work (secure code review, investigation, documentation), with sound judgment about when AI-generated output requires human validation before it is shared, shipped, or acted on.
  • Strong written and verbal communication skills, including the ability to explain technical security topics to engineers, security peers, and non-technical stakeholders.
  • Experience contributing to a Product Security Incident Response Team (PSIRT) or equivalent product vulnerability response process, including CVSS scoring and coordinated disclosure, is a plus.
  • Familiarity with product security maturity models (BSIMM, SAMM) or secure-by-design regulatory requirements such as the EU Cyber Resilience Act is a plus.
  • Industry certifications such as CSSLP, CISSP, GWAPT, OSWE, or cloud security equivalents are a plus.
  • Experience supporting customer security questionnaires, RFPs, or third-party risk assessments is a plus.

Physical Requirements

General office environment and responsibilities requiring:

  • Extensive use of the computer which involves viewing a monitor and keyboarding for most of the workday
  • Placing and receiving phone calls
  • Occasionally moving and lifting objects up to 20 pounds

May require some travel as needed

Pay Range

$117,000—$150,000 CAD

Black Duck is an equal opportunity employer. We consider all applicants for employment without regard to race, color, national origin, religion, sex, gender identity or expression, age, disability, sexual orientation, veteran or military service status, or any other characteristic protected by applicable law. Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,611 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$84k – $178k per year (Estimated) • In office • Full-Time • 10+ years exp • Wellington
Java
Python
DevOps
Ansible
AWS
Azure
CI/CD
Docker
GCP
Helm
Kubernetes
Platform Engineering
Prometheus
Service Mesh
Terraform
GitLab
IAM
Apply
Platform Engineer 1 day ago
$87k – $140k per year • In office • Full-Time • 3+ years exp • Berlin
Databases
PostgreSQL
Redis
DevOps
AWS
Azure
Bicep
CI/CD
Docker
GCP
GitHub Actions
Kubernetes
OpenShift
Terraform
GitHub
Apply
Founding Engineer 1 day ago
$81k – $116k per year • In office • Full-Time • Bachelor's Degree • Munich
JavaScript
Python
TypeScript
Databases
MySQL
PostgreSQL
Frontend
Next.js
React.js
Tailwind CSS
DevOps
AWS
Azure
CI/CD
Docker
GCP
Grafana
Kubernetes
OpenTelemetry
Prometheus
Apply
Staff Engineer 1 day ago
$105k – $233k per year • In office • Full-Time • 8+ years exp • Munich
Python
TypeScript
JavaScript
AI/ML
LLM
Frontend
React.js
DevOps
AWS
Azure
Docker
GCP
Terraform
Apply
$230k – $260k per year • Equity • Remote • Internship • Bachelor's Degree
Python
DevOps
Amazon EKS
AWS
Azure
CI/CD
GCP
Helm
Kubernetes
Terraform
Cybersecurity
FedRAMP
Orca Security
Apply
$128k – $250k per year (Estimated) • Remote • 5+ years exp • Bachelor's Degree
Management
Confluence
Jira
Smartsheet
Marketing
Salesforce
Apply
Regional Field CTO 6 days ago
$164k – $312k per year (Estimated) • In office • Bachelor's Degree
AI/ML
Anomaly Detection
AI Agents
Human-in-the-Loop
Apply
$54k – $97k per year (Estimated) • In office • 7+ years exp • Bachelor's Degree
C#
C++
Java
DevOps
CI/CD
Apply
$13k – $42k per year (Estimated) • In office • 6+ years exp • Bachelor's Degree • Bengaluru
Python
DevOps
Ansible
AWS
CI/CD
Docker
Git
GitHub Actions
Jenkins
Kubernetes
GitHub
QA
Postman
Robot Framework
Selenium
Apply
In office • Bachelor's Degree • Singapore
C#
C++
Java
Perl
PowerShell
Python
DevOps
AWS
Azure
CI/CD
Docker
GCP
Kubernetes
Apply
See all jobs
This is one of many
368,611 more open roles from verified company boards, updated every day.