Senior Application Security Engineer (Black Duck / SCA) - Onsite

Cognizant

Philadelphia (Philadelphia County)

On-site

USD 90,000 - 130,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical/Dental/Vision/Life Insurance
Paid holidays plus Paid Time Off
401(k) plan and contributions
Long-term/Short-term Disability
Paid Parental Leave
Employee Stock Purchase Plan

Job summary

Cognizant IoT Practice is seeking a Senior Product Security Engineer with deep expertise in Black Duck, SCA, and security automation. You will collaborate with R&D and security teams to identify and remediate risks across software products, embedding security into the development lifecycle.

The role emphasizes threat modeling, secure design reviews, and governance of security tooling, with a focus on OSS management and vulnerability remediation strategies.

Qualifications

  • 8+ years of experience in Cybersecurity, Product Security, or Application Security.
  • Strong hands-on experience with Black Duck and Software Composition Analysis (SCA).
  • Experience working with Black Duck APIs and security tool integrations.
  • Deep understanding of secure software development and product security principles.
  • Knowledge of vulnerability management, CVE analysis, and remediation practices.
  • Experience with DevSecOps and integrating security into CI/CD pipelines.
  • Strong communication and stakeholder management skills.

Responsibilities

  • Administer, configure, and optimize Black Duck for software composition analysis and open-source governance.
  • Develop and maintain integrations leveraging Black Duck APIs and security automation workflows.
  • Partner with development and R&D teams to embed security best practices throughout the SDLC.
  • Analyze security vulnerabilities, recommend remediation strategies, and track resolution.
  • Conduct security assessments, reviews, and risk evaluations for product releases.
  • Provide expertise in memory testing, mobile app security, vulnerability remediation, and cryptographic agility.
  • Support threat modeling, secure design reviews, and security architecture discussions.
  • Drive continuous improvement of product security processes, tools, and governance.

Skills

Cybersecurity experience
Software security
DevSecOps
CI/CD security
Stakeholder management

Tools

Black Duck API
Security automation tools

Job description

*Please note, this role is not able to offer visa transfer or sponsorship now or in the future*

About Us:

Cognizant is one of the world's leading professional services companies, transforming clients' business, operating, and technology models for the digital era. Our unique industry-based, consultative approach helps clients envision, build, and run more innovative and efficient businesses. Headquartered in the U.S., Cognizant, a member of the NASDAQ-100, is ranked 195 on the Fortune 500 and is consistently listed among the most admired companies in the world. Learn how Cognizant helps clients lead with digital at www.cognizant.com.

About Cognizant’s IoT Practice:

Intelligent, IoT-enabled products will soon result in the proliferation of data and disrupt virtually all industries. To be successful, both large and small companies must leverage IoT capabilities by designing modern products that fundamentally connect people with processes. Within Cognizant IOT, we engineer industry-aligned, IoT-enabled products that merge industry needs with human drivers. Our intelligent products will revolutionize experiences and result in exciting, transformative outcomes. Without human-centered thinking, connected products are just standalone things—but with it, our modern connected products facilitate a unified way of life enjoyed by all.

Senior Product Security Engineer (Black Duck & Application Security)

Role Summary

We are seeking a highly experienced Senior Product Security Engineer with strong expertise in Black Duck, software composition analysis (SCA), and product security. The ideal candidate will possess deep technical knowledge of application and product security practices and have hands-on experience integrating and automating security solutions using Black Duck APIs. This role requires close collaboration with R&D, development, and security teams to identify, assess, and remediate security risks across software products.

Key Responsibilities
  • Administer, configure, and optimize Black Duck for software composition analysis and open-source governance.
  • Develop and maintain integrations leveraging Black Duck APIs and security automation workflows.
  • Partner with development and R&D teams to embed security best practices throughout the software development lifecycle (SDLC).
  • Analyze security vulnerabilities, recommend remediation strategies, and track resolution.
  • Conduct security assessments, reviews, and risk evaluations for product releases.
  • Provide expertise in one or more of the following areas:
    • Memory Leak and Memory Soak Testing
    • Mobile Application Security
    • Security Patching and Vulnerability Remediation Strategies
    • Cryptographic Agility and Modern Encryption Concepts
  • Support threat modeling, secure design reviews, and security architecture discussions.
  • Drive continuous improvement of product security processes, tools, and governance.
Required Qualifications
  • 8+ years of experience in Cybersecurity, Product Security, or Application Security.
  • Strong hands-on experience with Black Duck and Software Composition Analysis (SCA).
  • Experience working with Black Duck APIs and security tool integrations.
  • Deep understanding of secure software development and product security principles.
  • Knowledge of vulnerability management, CVE analysis, and remediation practices.
  • Experience with DevSecOps and integrating security into CI/CD pipelines.
  • Strong communication and stakeholder management skills.
Preferred Qualifications
  • Experience with secure coding practices and application security testing.
  • Knowledge of OWASP Top 10, SBOM, Open-Source Risk Management, and Supply Chain Security.
  • Familiarity with cloud security environments (AWS, Azure, or GCP).
  • Relevant security certifications such as CISSP, CSSLP, GWAPT, GSEC, or equivalent.
Compensation:

$90,000 to $130,000 + COLA and this position is also eligible for Cognizant’s discretionary annual incentive program, based on performance and subject to the terms of Cognizant’s applicable plans. Application will be accepted by 9/30/2026

Benefits
  • Medical/Dental/Vision/Life Insurance
  • Paid holidays plus Paid Time Off
  • 401(k) plan and contributions
  • Long-term/Short-term Disability
  • Paid Parental Leave
  • Employee Stock Purchase Plan

#LI-CT1

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Strategic Services Consultant (Application Security)
Lead Strategic Services Consultant (Application Security)

Blackduck • Burlington (MA)

On-site
USD 124,000 - 185,000
Senior Product Security Engineer: Black Duck & AppSec
Senior Product Security Engineer: Black Duck & AppSec

Cognizant • Philadelphia

On-site
USD 90,000 - 130,000
Medical/Dental/Vision/Life Insurance
Paid holidays plus Paid Time Off
401(k) plan and contributions
+3
Lead Strategic Services Consultant (Application Security)
Lead Strategic Services Consultant (Application Security)

Black Duck • Chicago (IL)

On-site
USD 124,000 - 185,000
Regional Field CTO
Regional Field CTO

Talanto • Northern (KY)

Hybrid
USD 180,000 - 240,000
Sr. Manager, IT Network & Datacenters
Sr. Manager, IT Network & Datacenters

Black Duck • Burlington (VT)

On-site
USD 153,000 - 192,000
Sr Director, Technology Partner Alliances Development New
Sr Director, Technology Partner Alliances Development New

Black Duck • Northern (KY)

Hybrid
USD 160,000 - 230,000
Lead Enterprise Account Executive-Strategic Account Management
Lead Enterprise Account Executive-Strategic Account Management

Black Duck Software, Inc. • Chicago (IL)

On-site
USD 130,000 - 196,000
Sr Director, Technology Partner Alliances Development
Sr Director, Technology Partner Alliances Development

Blackduck • United States

On-site
USD 180,000 - 280,000
Lead Sales Engineer (West)
Lead Sales Engineer (West)

Black Duck • Austin (TX)

On-site
USD 141,200 - 211,800
Sr. Manager, Sales Engineering (Enterprise, West Coast)
Sr. Manager, Sales Engineering (Enterprise, West Coast)

Francisco Partners • Washington

On-site
USD 174,000 - 261,000