Full-Time

Lead Product Security

Black Duck

Black Duck

1,001-5,000 employees

Open source risk management and audits

Compensation Overview

CA$117k - CA$150k/yr

Remote in Canada

Remote

May require some travel as needed.

Bachelor's

Category
Cybersecurity (1)
Required Skills
LLM
Microsoft Azure
Threat modeling
Infrastructure as Code (IaC)
ISC2 CSSLP
AWS
JIRA
Cryptography
Penetration Testing
Google Cloud Platform

Get referred to Black Duck

See people who can refer or advise you

Requirements
  • Awareness of artificial intelligence and large language model security risks, including prompt injection, sensitive data exposure, and the OWASP Top 10 for LLM Applications.
  • A bachelor’s degree in Computer Science, Information Security, Information Technology, or equivalent practical experience.
  • At least 8 years of experience in product security, application security, or software security engineering, with hands-on depth in secure design review, threat modeling, and secure code review.
  • Demonstrated experience building or running a security champions program, developer enablement initiative, or equivalent effort that scaled security capability across engineering teams.
  • Working knowledge of application security tooling, including software composition analysis, static application security testing, dynamic application security testing, and secret scanning, as well as the vulnerability classes each detects and where each produces false positives.
  • Practical secure coding and review experience in at least one language used in commercial software products, with the ability to read unfamiliar code and reason about security impact.
  • Experience defining security requirements, standards, or design gates that engineering teams adopted.
  • Familiarity with at least one major cloud platform—Amazon Web Services, Azure, or Google Cloud Platform—from a product security perspective, including container and infrastructure-as-code security.
  • Experience coordinating penetration tests or third-party security assessments and driving findings through remediation.
  • Demonstrated ability to mentor engineers and lead technical workstreams without formal direct-report authority.
  • Practical use of artificial intelligence and large language model tools to accelerate security work, with judgment about when AI-generated output requires human validation before it is shared, shipped, or acted on.
  • Strong written and verbal communication skills, including the ability to explain technical security topics to engineers, security peers, and non-technical stakeholders.
  • Extensive computer use involving monitor viewing and keyboarding for most of the workday.
  • Ability to place and receive phone calls.
  • Ability to occasionally move and lift objects up to 20 pounds.
Responsibilities
  • Lead security architecture and design reviews for Black Duck software composition analysis, Coverity, and adjacent product lines, delivering actionable feedback before implementation begins.
  • Contribute to the threat modeling methodology, coach engineers to run their own models, and review model outputs.
  • Define security requirements, design gates, and product security baselines that provide engineering with a testable definition of secure-by-default.
  • Build and measure the secure development lifecycle across software composition analysis, static application security testing, secret scanning using GitGuardian, dependency hygiene, and build pipeline integrity.
  • Perform deep secure code reviews in high-risk areas, including authentication, authorization, cryptography, secrets handling, and input validation.
  • Secure the product supply chain and release process, including software bill of materials generation and the integrity of build and distribution artifacts.
  • Mature and evolve the Security Champions program by recruiting champions across product teams, growing the training and enablement curriculum, running office hours, and reporting on participation and outcomes.
  • Mentor engineers and less experienced security staff on secure design, secure code review, and threat modeling.
  • Assist with the scoping and coordination of penetration tests and third-party security assessments, triage findings, and drive remediation to closure with engineering owners.
  • Partner with the Product Security Incident Response Team on triage and fix coordination for internally discovered and externally reported product vulnerabilities, feeding root causes back into design and secure development lifecycle controls.
  • Measure product security maturity using Building Security In Maturity Model or Software Assurance Maturity Model-style assessments and drive a prioritized improvement roadmap.
  • Support European Union Cyber Resilience Act secure-by-design and vulnerability-handling obligations with technical evidence and process changes for engineering.
  • Provide technical subject matter expertise on customer security questionnaires, audit requests, and security escalations by drafting answers, gathering engineering evidence, and building a reusable knowledge base of vetted responses.
  • Support incident response for issues involving product code, build systems, or product infrastructure, contributing product-specific context and remediation guidance.
  • Lead discrete workstreams within larger product security initiatives, track milestones in Jira, and provide technical input into application security tooling evaluations and proof-of-concepts.
  • Perform other assigned tasks and activities.
Desired Qualifications
  • Experience contributing to a Product Security Incident Response Team or equivalent product vulnerability response process, including Common Vulnerability Scoring System scoring and coordinated disclosure.
  • Familiarity with product security maturity models such as Building Security In Maturity Model and Software Assurance Maturity Model, or secure-by-design regulatory requirements such as the European Union Cyber Resilience Act.
  • Industry certifications such as Certified Secure Software Lifecycle Professional, Certified Information Systems Security Professional, GIAC Web Application Penetration Tester, Offensive Security Web Expert, or cloud security equivalents.
  • Experience supporting customer security questionnaires, requests for proposals, or third-party risk assessments.

Black Duck Software helps organizations manage open source risk by offering Software Composition Analysis (SCA) and Open Source Audits. Its products scan software to find security vulnerabilities and license compliance issues in open source components and provide fixes. The Open Source Audits support due diligence for mergers and acquisitions and internal audits. Revenue comes from licenses for the tools plus professional services for audits and consultations. The platform relies on a large database of open source components, vulnerabilities, and licenses to enable fast, accurate analysis. The goal is to help security, development, and legal teams ensure software is secure and legally compliant throughout the software development lifecycle and during M&A.

Company Size

1,001-5,000

Company Stage

Acquired

Total Funding

$87.5M

Headquarters

Burlington, Massachusetts

Founded

2002

Get referred to Black Duck

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Polaris scan volumes rose over 100% in early 2026, signaling demand acceleration.
  • CRA deadlines beginning September 11, 2026 expand Black Duck’s compliance-selling window.
  • The 2026 OSSRA report showed 107% higher vulnerabilities per codebase, boosting urgency.

What critics are saying

  • Aikido, Snyk, and GitHub Advanced Security commoditize Black Duck’s developer workflows by 2026.
  • Black Duck still carries legacy on-prem complexity, slowing wins against faster SaaS competitors.
  • If AI-native rivals own open-source governance, Clearlake and Francisco Partners face a stranded asset.

What makes Black Duck unique

  • Black Duck’s 2026 Gartner Leader status validates its enterprise supply-chain security depth.
  • Its BDSA enrichment offsets NIST’s April 2026 NVD deprioritization.
  • ContextAI and Signal fuse deterministic analysis with AI governance for regulated codebases.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Flexible Work Hours

Professional Development Budget

Paid Vacation

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

-1%

2 year growth

48%
PR Newswire
Sep 8th, 2026
Black Duck joins Anthropic's Project Glasswing to secure critical software with AI

Black Duck has joined Anthropic's Project Glasswing, an industry initiative aimed at securing critical software infrastructure using advanced AI for defensive cybersecurity. The application security company will apply Mythos, Anthropic's AI system, across its full security portfolio. This will combine AI-accelerated vulnerability discovery with remediation workflows, risk-based prioritisation, and compliance-driven governance. "AI is transforming the economics and speed of vulnerability discovery and exploit development," said Dipto Chakravarty, Black Duck's Chief Product & Technology Officer. He explained that pairing Mythos with Black Duck's existing capabilities will enable faster risk reduction whilst maintaining the transparency and auditability required by enterprise security teams. Black Duck specialises in application security, combining deterministic analysis with AI reasoning to identify and fix security issues in code written by developers, generated by AI, or assembled from open source.

PR Newswire
Jul 14th, 2026
Black Duck launches AI-powered Coverity with EU CRA compliance features

Black Duck has launched new AI-powered features for its Coverity static analysis solution, designed to support modern development workflows and emerging regulatory compliance requirements. The updates include AI-assisted vulnerability triage, support for the EU Cyber Resilience Act (CRA), and analysis capabilities for Rust 1.92. Coverity's AI features run on customers' own large language models, allowing organisations to maintain control over code and scan data processing — a requirement for regulated industries with strict data governance policies. The solution now offers streamlined navigation and improved issue filtering to help teams manage large volumes of security findings more efficiently. According to Chief Product & Technology Officer Dipto Chakravarty, the enhancements combine deterministic precision with AI speed whilst maintaining auditability. All announced capabilities are now generally available for customer deployment. Existing Coverity customers receive these AI-powered features whilst retaining the deterministic, auditable scan results required by regulated industries.

PR Newswire
Jun 16th, 2026
Black Duck launches AI-powered security tools to combat surge in software vulnerabilities

Black Duck has announced significant enhancements to its Polaris Platform, designed to help organisations defend against AI-driven cyberattacks and manage the surge in supply chain vulnerabilities. The updates focus on three areas: eliminating application security testing gaps, preparing for increased vulnerability disclosures, and automating remediation pipelines. The enhancements address threats from sophisticated AI models that enable attackers to exploit multiple vulnerabilities rapidly. Polaris scan volumes have increased over 100% in the first five months of 2026 as organisations accelerate security testing. New capabilities include improved vulnerability detection, rapid response tools for supply chain components, and AI-enabled application security features. Black Duck expects vulnerability disclosures to exceed 50,000 in 2026, potentially reaching 200,000 by 2028, as maintainers use AI to identify and patch security flaws.

PR Newswire
Mar 23rd, 2026
Black Duck launches Signal, AI-powered security solution for AI-generated code

Black Duck has launched Signal, an AI-powered application security solution designed to secure AI-generated code in autonomous development workflows. The platform uses an agentic AI architecture where specialised agents analyse vulnerabilities, validate exploitability and recommend fixes. Signal is powered by ContextAI, Black Duck's application security model containing over 20 years of security intelligence. This enables the system to assess risk with higher accuracy than solutions built solely on general-purpose AI models. The platform integrates directly into modern software development through model context protocol and APIs that support AI coding assistants and automated pipelines. CEO Jason Schmitt said AI is "actively authoring software", and Signal brings intelligence and governance to that reality. The solution is now generally available and will be showcased at RSA Conference in San Francisco from 23–26 May.

PR Newswire
Feb 12th, 2026
Black Duck expands Polaris integrations for automated DevSecOps across GitHub, GitLab, Azure DevOps, and Bitbucket

Black Duck has launched enhanced integrations for its Polaris Platform across major source code management systems including GitHub, GitLab, Azure DevOps and Bitbucket. The updates enable automated repository onboarding, continuous monitoring and event-based scanning for enterprises managing thousands of code repositories. The enhancements allow organisations to automatically onboard repositories without manual configuration and trigger scans during pull requests. The platform includes Black Duck Signal for AI-powered security insights and Code Sight, an IDE plugin providing real-time feedback to developers. The integrations support customisable scanning options and automatically synchronise security policies and user access controls across repositories. The features are immediately available to existing customers through Polaris Platform settings, aiming to streamline DevSecOps operations at enterprise scale.