Lead Incident Security Responder New Remote - Canada

Black Duck Software, Inc.

Canada

Hybrid

CAD 117,000 - 150,000

Full time

11 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Black Duck Software, Inc. is seeking a Lead Product Security to serve as the senior technical authority on secure-by-default design across Black Duck products.

You will drive architecture reviews, threat modeling, and secure development lifecycle, while mentoring engineers and supporting external security assessments. This role partners with PSIRT and product teams to improve security maturity and respond to vulnerabilities.

Qualifications

  • Bachelor’s degree in CS, Info Sec, IT or equivalent.
  • 8+ years in product, application, or software security engineering.
  • Experience building/leading security champions program.
  • Experience with SCA/SAST/DAST and secret scanning.
  • Read unfamiliar code and assess security impact.

Responsibilities

  • Lead security architecture and design reviews for Black Duck products.
  • Define security requirements and secure-by-default design gates.
  • Scale and mature the Security Champions program.
  • Mentor engineers and security staff.
  • Coordinate penetration tests and third-party security assessments.
  • Collaborate with PSIRT on vulnerability response and remediation.
  • Lead discrete workstreams and contribute to tooling evaluations.

Skills

Security architecture
Threat modeling
Secure code review
Mentoring engineers
Product security
PSIRT collaboration
AI/LLM security
Vulnerability assessment

Education

Bachelor’s degree in Computer Science / Information Security / Information Technology

Job description

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.

Lead Product Security

Job Title: Lead Product Security

Reports to (Direct Title): Director of Security Operations

Department: Cybersecurity

Position Summary

The Lead Product Security is the senior technical authority for how security is designed into Black Duck products. Operating with broad autonomy under general guidance, the role will lead secure architecture and design reviews, contribute to the threat modeling methodology, and set the standards and design gates that define what secure-by-default means for our engineering teams. A core part of the role is scaling security capability rather than absorbing security work: the role will help mature and evolve the Security Champions program, mentor engineers and less experienced security staff, and build the enablement content that lets product teams reason about security themselves. The Lead Product Security will also drive deep secure code review in high-risk areas, support external security assessments, partner with PSIRT on product vulnerability response, and measure product security maturity to guide a prioritized improvement roadmap.

Essential Functions/Responsibilities
  • Lead security architecture and design reviews for Black Duck SCA, Coverity, and adjacent product lines, delivering actionable feedback before implementation begins.
  • Contribute to the threat modeling methodology and help scale its adoption: coach engineers to run their own models and review outputs, rather than serving as the sole modeler.
  • Define security requirements, design gates, and product security baselines that give engineering a testable definition of secure-by-default.
  • Build and measure the secure development lifecycle across SCA, SAST, secret scanning (GitGuardian), dependency hygiene, and build pipeline integrity.
  • Perform deep secure code review on high-risk areas including authentication, authorization, cryptography, secrets handling, and input validation.
  • Secure the product supply chain and release process, including SBOM generation and the integrity of build and distribution artifacts.
  • Help mature and evolve the Security Champions program: recruit champions across product teams, grow the training and enablement curriculum, run office hours, and report on participation and outcomes.
  • Mentor engineers and less experienced security staff on secure design, secure code review, and threat modeling, growing capability across the organization rather than absorbing the work.
  • Assist with the scoping and coordination of penetration tests and third-party security assessments; triage findings and drive remediation to closure with engineering owners.
  • Partner with PSIRT on triage and fix coordination for internally discovered and externally reported product vulnerabilities, feeding root causes back into design and SDLC controls.
  • Measure product security maturity using BSIMM or SAMM style assessment and drive a prioritized improvement roadmap.
  • Support EU Cyber Resilience Act secure-by-design and vulnerability handling obligations with the technical evidence and process changes engineering needs.
  • Provide technical subject matter expertise on customer security questionnaires, audit requests, and security escalations, drafting accurate answers, gathering evidence from engineering, and building a reusable knowledge base of vetted responses.
  • Support incident response for issues that touch product code, build systems, or product infrastructure, contributing product-specific context and remediation guidance.
  • Lead discrete workstreams within larger product security initiatives, track milestones in Jira, and provide technical input into application security tooling evaluations and POCs.
  • Other tasks and activities as assigned.
Required Education/Experience & Skills
  • Awareness of AI and LLM security risks such as prompt injection, sensitive data exposure, and the OWASP Top 10 for LLM Applications.
  • Bachelor’s degree in Computer Science, Information Security, Information Technology, or equivalent practical experience.
  • 8+ years of experience in product security, application security or software security engineering, with hands‑on depth in secure design review, threat modeling, and secure code review.
  • Demonstrated experience building or running a security champions program, developer enablement initiative, or equivalent effort that scaled security capability across engineering teams.
  • Working knowledge of application security tooling (SCA, SAST, DAST, secret scanning), the vulnerability classes each detects, and where each produces false positives.
  • Practical secure coding and review experience in at least one language used in commercial software products, with the ability to read unfamiliar code and reason about security impact.
  • Experience defining security requirements, standards, or design gates that engineering teams actually adopted.
  • Familiarity with at least one major cloud platform (AWS, Azure, or GCP) from a product security perspective, including container and infrastructure‑as‑code security.
  • Experience coordinating penetration tests or third‑party security assessments and driving findings through to remediation.
  • Demonstrated ability to mentor engineers and lead technical workstreams without formal direct‑report authority.
  • Practical use of AI and LLM tools to accelerate day‑to‑day security work (secure code review, investigation, documentation), with sound judgment about when AI‑generated output requires human validation before it is shared, shipped, or acted on.
  • Strong written and verbal communication skills, including the ability to explain technical security topics to engineers, security peers, and non‑technical stakeholders.
  • Experience contributing to a Product Security Incident Response Team (PSIRT) or equivalent product vulnerability response process, including CVSS scoring and coordinated disclosure, is a plus.
  • Familiarity with product security maturity models (BSIMM, SAMM) or secure‑by‑design regulatory requirements such as the EU Cyber Resilience Act is a plus.
  • Industry certifications such as CSSLP, CISSP, GWAPT, OSWE, or cloud security equivalents are a plus.
  • Experience supporting customer security questionnaires, RFPs, or third‑party risk assessments is a plus.
Physical Requirements

General office environment and responsibilities requiring:

  • Extensive use of the computer which involves viewing a monitor and keyboarding for most of the workday
  • Placing and receiving phone calls
  • Occasionally moving and lifting objects up to 20 pounds

May require some travel as needed

Pay Range

$117,000 - $150,000 CAD

Black Duck is an equal opportunity employer. We consider all applicants for employment without regard to race, color, national origin, religion, sex, gender identity or expression, age, disability, sexual orientation, veteran or military service status, or any other characteristic protected by applicable law. Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Product Security
Lead Product Security

Black-Duck-Software • Calgary

On-site
CAD 100,000 - 150,000
Principal Software Engineer (IAM)
Principal Software Engineer (IAM)

Francisco Partners • Calgary

On-site
CAD 135,000 - 203,000
Principal Software Engineer (IAM)
Principal Software Engineer (IAM)

Black Duck • Calgary

On-site
CAD 241,000 - 311,000
Principal Software Engineer (Agentic Integration)
Principal Software Engineer (Agentic Integration)

Black Duck • Calgary

On-site
CAD 135,000 - 190,000
Pay range matching market
Senior Financial Analyst
Senior Financial Analyst

Black Duck • Toronto

On-site
CAD 79,800 - 119,700
Competitive total rewards package
Bonus eligibility
Sr Director, Technology Partner Alliances Development
Sr Director, Technology Partner Alliances Development

Black Duck • Toronto

On-site
CAD 180,000 - 240,000
Senior Application Security Analyst
Senior Application Security Analyst

Purolator Inc. • Mississauga

On-site
CAD 110,000 - 140,000
Server Engineer
Server Engineer

Black-Duck-Software • Calgary

On-site
CAD 67,000 - 94,000
Server Engineer
Server Engineer

Black Duck • Calgary

On-site
CAD 67,000 - 94,000
Director of Product Security
Director of Product Security

Motion Recruitment Partners LLC • Toronto

On-site
CAD 180,000 - 220,000
Medical, Dental, Vision Insurance
Vacation Time
Stock Options
+2