Full-Time

Performance Engineer 2

Updated on 9/4/2026

Black Duck

Black Duck

1,001-5,000 employees

Open source risk management and audits

No salary listed

Bengaluru, Karnataka, India

In Person

Category
QA & Testing (1)
Required Skills
Datadog
RabbitMQ
Bash
Kubernetes
Python
JavaScript
Grafana
Software Testing
SQL
Postgres
RDBMS
Docker
AWS
Perl
Prometheus
New Relic
Jenkins
Linux/Unix
Google Cloud Platform

Get referred to Black Duck

See people who can refer or advise you

Requirements
  • At least 3 years of dedicated performance engineering experience, preferably with complex, containerized, distributed products in the cloud.
  • Strong experience with Linux.
  • Strong experience with Docker and Kubernetes.
  • Strong experience with Google Cloud Platform and/or Amazon Web Services.
  • Strong experience with LoadRunner, JMeter, or other performance testing tools.
  • Strong scripting experience, such as with Bash, Perl, or Python.
  • Strong experience diagnosing bottlenecks in PostgreSQL queries or other relational database queries.
  • Strong experience with performance monitoring tools such as New Relic, Prometheus, Grafana, or Datadog.
Responsibilities
  • Deploy and set up test instances and PostgreSQL or other databases on-premises on Linux and in the cloud using Amazon Web Services or Google Cloud Platform, leveraging Docker, Kubernetes, and Jenkins and working heavily in the command line.
  • Troubleshoot deployment issues, test issues, and product issues.
  • Develop performance tests using LoadRunner, DevWeb, Apache Benchmark, Cypress, and custom tools and scripts written in Python, Perl, Bash, and SQL.
  • Monitor and analyze test results, Jenkins logs, application logs, PostgreSQL logs, Docker, Kubernetes, NetData, Prometheus, Grafana, New Relic, Datadog, cloud monitoring, RabbitMQ, and custom database queries to diagnose issues and bottlenecks and gain insights.

Black Duck Software helps organizations manage open source risk by offering Software Composition Analysis (SCA) and Open Source Audits. Its products scan software to find security vulnerabilities and license compliance issues in open source components and provide fixes. The Open Source Audits support due diligence for mergers and acquisitions and internal audits. Revenue comes from licenses for the tools plus professional services for audits and consultations. The platform relies on a large database of open source components, vulnerabilities, and licenses to enable fast, accurate analysis. The goal is to help security, development, and legal teams ensure software is secure and legally compliant throughout the software development lifecycle and during M&A.

Company Size

1,001-5,000

Company Stage

Acquired

Total Funding

$87.5M

Headquarters

Burlington, Massachusetts

Founded

2002

Get referred to Black Duck

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Polaris scan volumes rose over 100% in early 2026, signaling demand acceleration.
  • CRA deadlines beginning September 11, 2026 expand Black Duck’s compliance-selling window.
  • The 2026 OSSRA report showed 107% higher vulnerabilities per codebase, boosting urgency.

What critics are saying

  • Aikido, Snyk, and GitHub Advanced Security commoditize Black Duck’s developer workflows by 2026.
  • Black Duck still carries legacy on-prem complexity, slowing wins against faster SaaS competitors.
  • If AI-native rivals own open-source governance, Clearlake and Francisco Partners face a stranded asset.

What makes Black Duck unique

  • Black Duck’s 2026 Gartner Leader status validates its enterprise supply-chain security depth.
  • Its BDSA enrichment offsets NIST’s April 2026 NVD deprioritization.
  • ContextAI and Signal fuse deterministic analysis with AI governance for regulated codebases.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Flexible Work Hours

Professional Development Budget

Paid Vacation

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

-1%

2 year growth

48%
PR Newswire
Sep 8th, 2026
Black Duck joins Anthropic's Project Glasswing to secure critical software with AI

Black Duck has joined Anthropic's Project Glasswing, an industry initiative aimed at securing critical software infrastructure using advanced AI for defensive cybersecurity. The application security company will apply Mythos, Anthropic's AI system, across its full security portfolio. This will combine AI-accelerated vulnerability discovery with remediation workflows, risk-based prioritisation, and compliance-driven governance. "AI is transforming the economics and speed of vulnerability discovery and exploit development," said Dipto Chakravarty, Black Duck's Chief Product & Technology Officer. He explained that pairing Mythos with Black Duck's existing capabilities will enable faster risk reduction whilst maintaining the transparency and auditability required by enterprise security teams. Black Duck specialises in application security, combining deterministic analysis with AI reasoning to identify and fix security issues in code written by developers, generated by AI, or assembled from open source.

PR Newswire
Jul 14th, 2026
Black Duck launches AI-powered Coverity with EU CRA compliance features

Black Duck has launched new AI-powered features for its Coverity static analysis solution, designed to support modern development workflows and emerging regulatory compliance requirements. The updates include AI-assisted vulnerability triage, support for the EU Cyber Resilience Act (CRA), and analysis capabilities for Rust 1.92. Coverity's AI features run on customers' own large language models, allowing organisations to maintain control over code and scan data processing — a requirement for regulated industries with strict data governance policies. The solution now offers streamlined navigation and improved issue filtering to help teams manage large volumes of security findings more efficiently. According to Chief Product & Technology Officer Dipto Chakravarty, the enhancements combine deterministic precision with AI speed whilst maintaining auditability. All announced capabilities are now generally available for customer deployment. Existing Coverity customers receive these AI-powered features whilst retaining the deterministic, auditable scan results required by regulated industries.

PR Newswire
Jun 16th, 2026
Black Duck launches AI-powered security tools to combat surge in software vulnerabilities

Black Duck has announced significant enhancements to its Polaris Platform, designed to help organisations defend against AI-driven cyberattacks and manage the surge in supply chain vulnerabilities. The updates focus on three areas: eliminating application security testing gaps, preparing for increased vulnerability disclosures, and automating remediation pipelines. The enhancements address threats from sophisticated AI models that enable attackers to exploit multiple vulnerabilities rapidly. Polaris scan volumes have increased over 100% in the first five months of 2026 as organisations accelerate security testing. New capabilities include improved vulnerability detection, rapid response tools for supply chain components, and AI-enabled application security features. Black Duck expects vulnerability disclosures to exceed 50,000 in 2026, potentially reaching 200,000 by 2028, as maintainers use AI to identify and patch security flaws.

PR Newswire
Mar 23rd, 2026
Black Duck launches Signal, AI-powered security solution for AI-generated code

Black Duck has launched Signal, an AI-powered application security solution designed to secure AI-generated code in autonomous development workflows. The platform uses an agentic AI architecture where specialised agents analyse vulnerabilities, validate exploitability and recommend fixes. Signal is powered by ContextAI, Black Duck's application security model containing over 20 years of security intelligence. This enables the system to assess risk with higher accuracy than solutions built solely on general-purpose AI models. The platform integrates directly into modern software development through model context protocol and APIs that support AI coding assistants and automated pipelines. CEO Jason Schmitt said AI is "actively authoring software", and Signal brings intelligence and governance to that reality. The solution is now generally available and will be showcased at RSA Conference in San Francisco from 23–26 May.

PR Newswire
Feb 12th, 2026
Black Duck expands Polaris integrations for automated DevSecOps across GitHub, GitLab, Azure DevOps, and Bitbucket

Black Duck has launched enhanced integrations for its Polaris Platform across major source code management systems including GitHub, GitLab, Azure DevOps and Bitbucket. The updates enable automated repository onboarding, continuous monitoring and event-based scanning for enterprises managing thousands of code repositories. The enhancements allow organisations to automatically onboard repositories without manual configuration and trigger scans during pull requests. The platform includes Black Duck Signal for AI-powered security insights and Code Sight, an IDE plugin providing real-time feedback to developers. The integrations support customisable scanning options and automatically synchronise security policies and user access controls across repositories. The features are immediately available to existing customers through Polaris Platform settings, aiming to streamline DevSecOps operations at enterprise scale.