Black Duck Software, Inc.

Lead Incident Security Responder

Remote - CanadaFull timeLead$100,000 - $150,000 / yearPosted 15 days ago
Apply on Black Duck Software, Inc. →

Sign into see who you know at Black Duck Software, Inc..

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.Lead Incident Security Responder Position Summary The Lead Incident Security Responder drives applied product security work across Black Duck’s portfolio, protecting our products and supporting the customer security inquiries that come into our Security Operations team. Operating with broad autonomy under general guidance, you lead portions of complex security projects, partner with the Director of Security Operations and the broader engineering organization, and serve as an informal technical resource for less experienced team members. The role requires hands-on product security depth combined with program coordination: delivering architecture reviews, threat models, vulnerability triage, and customer-facing security work, while also maintaining detection content, contributing to SOAR automations, and tracking projects through to measurable outcomes.   Essential Functions/Responsibilities Partner with engineering teams building Black Duck SCA, Coverity, and adjacent products on architecture reviews, threat models, and security design feedback. Contribute to a measurable secure development lifecycle covering SCA, SAST, secret scanning (GitGuardian), dependency hygiene, and build pipeline security. Recommend systematic improvements when patterns emerge across the portfolio rather than relying on one-off fixes. Triage internally discovered and externally reported product vulnerabilities and help drive resolution with engineering teams. Coordinate vulnerability fixes with engineering and support customer-facing communications when needed. Help triage customer security questionnaires, audit requests, and ad hoc product security questions in close partnership with the Director of Security Operations. Draft technically accurate answers to customer security inquiries; gather evidence from engineering when needed. Join customer security calls as a subject matter expert when called upon and contribute to a growing knowledge base of reusable responses. Support detection engineering and incident response activities across the corporate environment, with a focus on issues that intersect with our products. Maintain and tune detection content in CrowdStrike NG-SIEM and Sumo Logic related to product security risks; help work escalations from our MDR provider (ReliaQuest). Contribute to SOAR automations and runbooks that reduce manual toil. Lead discrete workstreams within larger secur...