Full-Time

Principal Data Engineer

Black Duck

Black Duck

1,001-5,000 employees

Open source risk management and audits

No salary listed

Belfast, UK

Hybrid

Hybrid work model; details TBD.

Category
Data & Analytics (1)
Required Skills
Python
Airflow
SQL
Data Engineering
AWS
REST APIs
Google Cloud Platform

Get referred to Black Duck

See people who can refer or advise you

Requirements
  • Significant experience building and operating production data platforms at scale, including on-call and operational ownership.
  • Strong SQL skills and strong Python skills, used to build pipelines, services, and automation.
  • Hands-on experience running cloud systems on AWS and Google Cloud (IaaS level: compute, storage, networking, IAM).
  • Practical experience with both operational databases (RDS-style) and analytics stores (columnar/OLAP), including performance tuning.
  • Strong data modeling ability, including schema evolution, conformed dimensions, and “one source of truth” metric definitions.
  • Track record of delivering data products that other teams or customers depend on, with clear contracts and reliability expectations.
  • Ability to make sound engineering tradeoffs across latency, accuracy, cost, and security without creating brittle complexity.
  • Experience with lakehouse patterns and open table formats (or similar), including governance and table maintenance.
  • Experience with orchestration and streaming systems used in production (batch + real-time), and managing backfills safely.
  • Familiarity with ML data needs (training/serving splits, feature-ready datasets, evaluation datasets) and AI-adjacent workflows.
Responsibilities
  • Lead the design and build-out of cross-product data services for multiple product lines from one governed data plane.
  • Define the “customer data plane” model: canonical customer identifiers, shared dimensions, and consistent facts used across products.
  • Build and operationalize ingestion patterns for batch, streaming, and event data, with repeatable onboarding for new sources.
  • Own the operational playbook for data reliability: data contracts, quality checks, lineage, monitoring, and incident response.
  • Implement and run access methods that make data usable: curated datasets, secure query interfaces, and product-ready data APIs where needed.
  • Productize customer-facing data products (datasets, metrics, exports, and feeds) with versioning, documentation, and clear ownership.
  • Design data models that fit both operational systems (RDS) and analytics stores (columnar/OLAP), including performance and cost tuning.
  • Ensure data products also power ML workflows: trusted training datasets, feature-ready outputs, and consistent definitions for decision-making.
  • Enable AI automation by delivering reliable, low-latency, governed data products that can be used safely in automated workflows.
  • Partner closely with product, engineering, and security stakeholders to align data products to roadmap priorities and customer outcomes.
  • Raise the technical bar through architecture reviews, standards, and mentoring—while staying hands-on in key systems.
Desired Qualifications
  • Experience building self-service data platforms (catalog, discoverability, access controls) used by multiple teams.
  • Experience in regulated or security-sensitive environments, including retention, auditing, and data access controls.

Black Duck Software helps organizations manage open source risk by offering Software Composition Analysis (SCA) and Open Source Audits. Its products scan software to find security vulnerabilities and license compliance issues in open source components and provide fixes. The Open Source Audits support due diligence for mergers and acquisitions and internal audits. Revenue comes from licenses for the tools plus professional services for audits and consultations. The platform relies on a large database of open source components, vulnerabilities, and licenses to enable fast, accurate analysis. The goal is to help security, development, and legal teams ensure software is secure and legally compliant throughout the software development lifecycle and during M&A.

Company Size

1,001-5,000

Company Stage

Acquired

Total Funding

$87.5M

Headquarters

Burlington, Massachusetts

Founded

2002

Get referred to Black Duck

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Polaris integrations expanded across GitHub, GitLab, Azure DevOps, and Bitbucket in February 2026.
  • Signal became generally available in May 2026, addressing AI-generated code security demand.
  • Clearlake and Francisco Partners completed the $2.1 billion acquisition on October 1, 2024.

What critics are saying

  • Snyk and Mend outcompete Black Duck on developer experience and faster remediation.
  • UltraViolet’s September 2025 acquisition of Black Duck AST services shrank its services moat.
  • The 2023 Risk Based Security lawsuit still lingers, threatening trust in data provenance.

What makes Black Duck unique

  • Black Duck’s OSSRA report and database anchor legal-grade open source due diligence.
  • Coverity, Polaris, and Signal unify SAST, SCA, and AI-generated code governance.
  • Its EU CRA compliance features target regulated enterprises with auditable scans and controls.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Flexible Work Hours

Professional Development Budget

Paid Vacation

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

49%
PR Newswire
Jul 14th, 2026
Black Duck launches AI-powered Coverity with EU CRA compliance features

Black Duck has launched new AI-powered features for its Coverity static analysis solution, designed to support modern development workflows and emerging regulatory compliance requirements. The updates include AI-assisted vulnerability triage, support for the EU Cyber Resilience Act (CRA), and analysis capabilities for Rust 1.92. Coverity's AI features run on customers' own large language models, allowing organisations to maintain control over code and scan data processing — a requirement for regulated industries with strict data governance policies. The solution now offers streamlined navigation and improved issue filtering to help teams manage large volumes of security findings more efficiently. According to Chief Product & Technology Officer Dipto Chakravarty, the enhancements combine deterministic precision with AI speed whilst maintaining auditability. All announced capabilities are now generally available for customer deployment. Existing Coverity customers receive these AI-powered features whilst retaining the deterministic, auditable scan results required by regulated industries.

PR Newswire
Jun 16th, 2026
Black Duck launches AI-powered security tools to combat surge in software vulnerabilities

Black Duck has announced significant enhancements to its Polaris Platform, designed to help organisations defend against AI-driven cyberattacks and manage the surge in supply chain vulnerabilities. The updates focus on three areas: eliminating application security testing gaps, preparing for increased vulnerability disclosures, and automating remediation pipelines. The enhancements address threats from sophisticated AI models that enable attackers to exploit multiple vulnerabilities rapidly. Polaris scan volumes have increased over 100% in the first five months of 2026 as organisations accelerate security testing. New capabilities include improved vulnerability detection, rapid response tools for supply chain components, and AI-enabled application security features. Black Duck expects vulnerability disclosures to exceed 50,000 in 2026, potentially reaching 200,000 by 2028, as maintainers use AI to identify and patch security flaws.

PR Newswire
Mar 23rd, 2026
Black Duck launches Signal, AI-powered security solution for AI-generated code

Black Duck has launched Signal, an AI-powered application security solution designed to secure AI-generated code in autonomous development workflows. The platform uses an agentic AI architecture where specialised agents analyse vulnerabilities, validate exploitability and recommend fixes. Signal is powered by ContextAI, Black Duck's application security model containing over 20 years of security intelligence. This enables the system to assess risk with higher accuracy than solutions built solely on general-purpose AI models. The platform integrates directly into modern software development through model context protocol and APIs that support AI coding assistants and automated pipelines. CEO Jason Schmitt said AI is "actively authoring software", and Signal brings intelligence and governance to that reality. The solution is now generally available and will be showcased at RSA Conference in San Francisco from 23–26 May.

PR Newswire
Feb 12th, 2026
Black Duck expands Polaris integrations for automated DevSecOps across GitHub, GitLab, Azure DevOps, and Bitbucket

Black Duck has launched enhanced integrations for its Polaris Platform across major source code management systems including GitHub, GitLab, Azure DevOps and Bitbucket. The updates enable automated repository onboarding, continuous monitoring and event-based scanning for enterprises managing thousands of code repositories. The enhancements allow organisations to automatically onboard repositories without manual configuration and trigger scans during pull requests. The platform includes Black Duck Signal for AI-powered security insights and Code Sight, an IDE plugin providing real-time feedback to developers. The integrations support customisable scanning options and automatically synchronise security policies and user access controls across repositories. The features are immediately available to existing customers through Polaris Platform settings, aiming to streamline DevSecOps operations at enterprise scale.

PR Newswire
Jun 3rd, 2025
Bluevoyant Unveils New Sbom Capabilities As Part Of Its Leading Third-Party Cyber Risk Management Solution

BlueVoyant's new Software Bill of Materials (SBOM) management offering, powered by SBOM leader Manifest, enables organizations to efficiently analyze and reduce third-party risks from commercial softwareNEW YORK, June 3, 2025 /PRNewswire/ -- BlueVoyant, the leader in integrated cybersecurity, today launched its Software Bill of Materials (SBOM) management offering, which helps organizations reduce risk related to software by automating the ingestion, analysis, and tracking of software component information from third-party software vendors. The latest advancements enhance Supply Chain Defense, BlueVoyant's next-generation third-party cyber risk management solution that continuously monitors suppliers, vendors, and other third parties, and then works with them to quickly remediate threats. BlueVoyant's SBOM solution is powered through a partnership with Manifest, a cybersecurity company that specializes in securing software supply chains for corporate and government entities.More than 85% of applications contain at least one software vulnerability, according to the Open Source Software Risk Analysis (OSSRA) Report. Yet, many organizations lack visibility into software design or an efficient way to assess and manage third-party SBOM information, which can leave them open to breaches, business interruption, and regulatory compliance issues. As a result, organizations are looking for solutions.By leveraging the BlueVoyant-Manifest SBOM solution, security teams can proactively gain deep insights into software risk exposure and other dependencies that their businesses may rely on."By combining Manifest's depth of experience in SBOM with BlueVoyant's holistic Supply Chain Defense, clients get continuous monitoring and remediation to solve their biggest third-party cybersecurity challenges," said Marc Frankel, CEO and co-founder of Manifest.The key benefits to utilizing SBOM for third-party risk are:Vendor risk management: Automatically solicit SBOMs from vendors, see intuitive risk levels for vendor products, and incorporate them into comprehensive third-party cyber risk managementSmarter vulnerability management: Prioritize vulnerabilities quickly, and triage issues to reduce false positives and avoid unnecessary mitigation workOpen Source Software (OSS) risk management: Create an enterprise-wide inventory of OSS across first and third-party products, and scan OSS repositories to assess risk before implementing themSimplified compliance: Easily demonstrate compliance and provide evidence for international regulations and standards such as R155, Executive Order 14028, Section 524B , the European Cyber Resilience Act, and the EU's NIS2 and DORA"Organizations in the private and public sectors are realizing that SBOM visibility is a crucial part of a proactive third-party cyber risk management program," said Joel Molinoff, global head of Supply Chain Defense at BlueVoyant. "By enhancing BlueVoyant's Supply Chain Defense with Manifest's SBOM capabilities, our clients are expanding their risk visibility deeper into the software supply chain and ensuring continuous monitoring and remediation of critical threats."BlueVoyant's Supply Chain Defense has garnered multiple industry awards