Lead Incident Security Responder @Black Duck Software, Inc.
All Others
Salary cad 100,000 - 1..
Remote Location
Employment Type full-time
Posted 2mths ago

[Hiring] Lead Incident Security Responder @Black Duck Software, Inc.

2mths ago - Black Duck Software, Inc. is hiring a remote Lead Incident Security Responder. πŸ’Έ Salary: cad 100,000 - 150,000 per year πŸ“Location: Canada

Role Description

The Lead Incident Security Responder drives applied product security work across Black Duck’s portfolio, protecting our products and supporting the customer security inquiries that come into our Security Operations team. Operating with broad autonomy under general guidance, you lead portions of complex security projects, partner with the Director of Security Operations and the broader engineering organization, and serve as an informal technical resource for less experienced team members. The role requires hands-on product security depth combined with program coordination:

  • Delivering architecture reviews, threat models, and vulnerability triage.
  • Supporting customer-facing security work.
  • Maintaining detection content and contributing to SOAR automations.
  • Tracking projects through to measurable outcomes.

Qualifications

  • At least 7 – 8 years of applicable experience in product security, application security, or security engineering.
  • Hands-on depth in at least two of the following: secure SDLC, threat modeling, secure code review, vulnerability management, product incident response, or customer-facing product security work.
  • Working knowledge of application security tooling (SCA, SAST, DAST, secret scanning) and the vulnerabilities they catch.
  • Familiarity with at least one major cloud platform (AWS, Azure, or GCP) from a security perspective.
  • Awareness of AI and LLM security risks such as prompt injection, sensitive data exposure, and the OWASP Top 10 for LLM Applications.
  • Demonstrated ability to work independently under general guidance and to lead workstreams or small project teams without formal direct-report authority.
  • Practical use of AI and LLM tools to accelerate day-to-day security work.
  • Strong written and verbal communication skills.
  • Bachelor’s degree in Computer Science, Information Security, Information Technology, or equivalent practical experience.
  • Experience contributing to a Product Security Incident Response Team (PSIRT) or equivalent product vulnerability response process.
  • Familiarity with vulnerability scoring (CVSS), embargo handling, and coordinated disclosure.
  • Industry certifications such as CISSP, CSSLP, GWAPT, GPEN, OSCP, OSWE, or cloud security equivalents are a plus.
  • Experience supporting customer security questionnaires, RFPs, or third-party risk assessments.

Requirements

  • Partner with engineering teams building Black Duck SCA, Coverity, and adjacent products on architecture reviews, threat models, and security design feedback.
  • Contribute to a measurable secure development lifecycle covering SCA, SAST, secret scanning (GitGuardian), dependency hygiene, and build pipeline security.
  • Recommend systematic improvements when patterns emerge across the portfolio.
  • Triage internally discovered and externally reported product vulnerabilities and help drive resolution with engineering teams.
  • Coordinate vulnerability fixes with engineering and support customer-facing communications when needed.
  • Help triage customer security questionnaires, audit requests, and ad hoc product security questions.
  • Draft technically accurate answers to customer security inquiries.
  • Join customer security calls as a subject matter expert when called upon.
  • Support detection engineering and incident response activities across the corporate environment.
  • Maintain and tune detection content in CrowdStrike NG-SIEM and Sumo Logic related to product security risks.
  • Contribute to SOAR automations and runbooks that reduce manual toil.
  • Lead discrete workstreams within larger security initiatives or coordinate small project teams.
  • Track projects through Jira with clear milestones and concise status updates.
  • Act as an informal resource and mentor for less experienced team members on product security.
  • Document tribal knowledge into runbooks, SOPs, and onboarding materials.
  • Other tasks and activities as assigned.

Benefits

  • Pay Range: $100,000 β€” $150,000 CAD

Company Description

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior.

Before You Apply
️
remote Be aware of the location restriction for this remote position: Canada
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Lead Incident Security Responder @Black Duck Software, Inc.
All Others
Salary cad 100,000 - 1..
Remote Location
Employment Type full-time
Posted 2mths ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 120,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Canada
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 120,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 120,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 121,713+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later