--- title: 'Application Security Engineer (West Coast) at Black Duck Software, Inc.' canonical: 'https://feeny.ai/job/application-security-engineer-west-coast-black-duck-software-inc-california-mfxx9vj7skmy' type: 'job' last_seen: '2026-09-12' --- # Application Security Engineer (West Coast) at Black Duck Software, Inc. - **Company:** Black Duck Software, Inc. - **Location:** California Oregon, WA - **Compensation:** $136k–$204k - **Work type:** remote - **Posted:** 2026-05-12 - **Last confirmed live:** 2026-09-12 - **Apply:** https://job-boards.greenhouse.io/blackduck/jobs/5209706008 ## Job description Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle. Are you interested in joining a fast-growing organization in the application security space, which is in the top spot of Gartner's Magic Quadrant for application security? Are you a technologist who wants to make a massive impact on Customers and help them develop high-quality, secure software faster? We want to speak to you! Black Duck seeks an experienced Technologist to help our Implementation and Services Team drive customer onboarding and adoption. We're looking for someone to help us take our business to the next level of excellence in delivery and customer delight! The Team The Black Duck Technical Services team is dedicated to supporting our customers in developing their AppSec vision and achieving their goals quickly. We accomplish this through the delivery of exemplary product implementations and adoption-focused services that are tailored to their specific needs. Our services are designed to help customers of all sizes and types, from Startup’s to global organizations, build secure, high quality software faster and maximize the value of their Black Duck tools. The Position This position will implement our industry leading Application Security products and solutions within our large enterprise customers environments -> focusing on the WEST COAST (remote). You will work alongside our sales, sales engineering, customer success managers, product development, support, solution architect, and project management team members to ensure that our clients receive most value from our AppSec products and achieve a high level of adoption. For information on our AppSec products please check out our website https://www.blackduck.com! ## Responsibilities - Secure Development: Educate customers on Secure Development processes. Identify opportunities for improvement and help them get the most out of their operations. - Customer enablement: Provide formal client training to constant efforts driving self-sufficiency within ## your assigned accounts - Solution design: Engage with customers to understand their business needs and solve critical quality, security, and compliance problems. - Delivery: Work with the customer from Project initiation to completion with end-to-end ownership of the results. - Custom integrations Develop custom solutions to integrate our tools into SDLC and DevOps workflows - Professional consulting: Be a trusted advisor to our customers, providing solution expertise in the domain of software testing and security. ## Qualifications - Proven ability to deploy both SaaS and On-prem software solutions. - Software development experience with at least two programming languages namely C/C++, C# or Java. - Strong scripting ability in one or more common scripting languages (Perl, Python, PowerShell, Bash). - Experience with project scoping and requirements gathering - Experience with Continuous Integration and DevOps tools - Strong client consultation/onboarding background - Proven ability to prioritize activities, set objectives and meet milestones - Well organized. Able to deliver project milestones and deliver on-time - Understanding of open-source software libraries such as glib, OpenSSL, Boost C++, etc. and their associated licensing - Able and willing to travel up to 20% as the job requires - Bachelor’s Degree in Computer Science, Master’s Degree preferred or equivalent Experience - Must be eligible to work in the United States or Canada (WEST COAST) without requiring sponsorship now or in the future. ## Benefits - Work From Home (Remote in United States or Canada) - Competitive Total Compensation - Annual Performance Bonus - Paid Vacation and Wellness Days - Group Retirement Savings Plans and Employer Contributions - Comprehensive Health Benefits Pay Range $135,900—$203,900 USD Black Duck is an equal opportunity employer. We consider all applicants for employment without regard to race, color, national origin, religion, sex, gender identity or expression, age, disability, sexual orientation, veteran or military service status, or any other characteristic protected by applicable law. Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law. ## About Black Duck Software, Inc. ## Company Overview - **One-liner**: Black Duck provides a comprehensive application security testing (AST) platform that helps organizations build secure, high-quality software by identifying and remediating vulnerabilities, license risks, and code quality issues across proprietary, open-source, and AI-generated code. - **Entity Type**: Private (backed by private equity firms Clearlake Capital and Francisco Partners; spun out from Synopsys in October 2024) - **Headquarters**: Burlington, Massachusetts, USA - **Founded**: 2015 (as the Synopsys Software Integrity Group); became an independent company in October 2024 - **Founders**: Not applicable (formed from Synopsys); key leadership includes CEO Greg Hughes, CPTO Dipto Chakravarty, CISO Dom Glavach, CRO Roman Telerman, CFO Jim Ivers, CMO Sean Forkan, and CHRO & General Counsel Joy Meier ## Core Business - **Primary industry**: Application Security Testing (AST), DevSecOps, Software Supply Chain Security - **Target customers**: B2B; enterprise organizations, development teams, security teams, and DevOps engineers across industries including finance, healthcare, automotive, aerospace, and government - **Mission or purpose statement**: “To enable organizations to build trust in their software by providing True Scale Application Security – the ability to secure code of any size, in any environment, without compromising speed, accuracy, or compliance.” ## Products & Services - **Black Duck Polaris Platform**: Cloud-native SaaS platform that unifies SAST, SCA, and DAST into a single, integrated solution for enterprise-wide application security testing and policy enforcement. - **Black Duck SCA (Software Composition Analysis)**: Identifies vulnerabilities, license risks, and compliance issues in open-source and third-party components; generates SBOMs; includes AI Model Risk Insights. - **Coverity Static Analysis (SAST)**: Scans proprietary source code for security vulnerabilities and quality defects, with AI-powered remediation suggestions via Black Duck Assist. - **Seeker Interactive Application Security Testing (IAST)**: Combines runtime analysis with automated testing to detect vulnerabilities in running applications. - **Black Duck Signal**: Agentic AI solution that autonomously detects and remediates vulnerabilities in business-critical applications, including AI-generated code. - **Code Sight IDE Plug-in**: Provides real-time security feedback within developers’ IDEs (VS Code, JetBrains, etc.) to catch issues before code is committed. - **Black Duck Hub (on-premises)**: On-premises deployment option for customers with strict data residency or regulatory requirements. - **Hybrid deployment**: Full flexibility to run scans in cloud, on-premises, or across mixed environments. ## Market Standing - **Valuation/Market Cap**: Not disclosed (private equity-backed) - **Key Metric**: Over 4,000 organizations worldwide trust Black Duck; recognized as a Leader in the Gartner® Magic Quadrant™ for Application Security Testing for eight consecutive years (2025). - **Notable Investors/Partners**: Clearlake Capital Group, Francisco Partners (majority owners); technology partners include GitHub, GitLab, Jenkins, Azure DevOps, and major cloud providers. - **Growth Signals**: Spun out as an independent company in October 2024 to focus exclusively on application security; launched Black Duck Signal (agentic AI AppSec); expanding SaaS platform with unified SAST+SCA+DAST; hiring across sales and engineering roles (remote positions available). ## Competitive Advantages - **Comprehensive portfolio**: Only vendor offering SAST, SCA, DAST, IAST, and agentic AI in a single unified platform (Polaris). - **20+ years of human-verified intelligence**: Proprietary KnowledgeBase™ with curated vulnerability data and context, powering high-precision detection with low false positives. - **Flexible deployment**: Supports cloud (SaaS), on-premises, and hybrid models – customers choose without compromising capabilities. - **Developer-first approach**: Integrates directly into CI/CD pipelines and IDEs, enabling developers to find and fix issues within their workflow. - **AI-native security**: Built to secure AI-generated code (e.g., from GitHub Copilot, ChatGPT) with specialized detection and remediation capabilities. - **Regulatory expertise**: Supports compliance with ISO 27001, GDPR, HIPAA, PCI DSS, FedRAMP, EU Cyber Resilience Act, US Executive Order 14028, and industry-specific standards (automotive ISO/SAE 21434, aerospace, defense). ## Strategic Focus - **Securing AI-generated code**: Developing and enhancing agentic AI tools (Signal) to address the unique risks of AI-assisted development. - **Expanding SaaS adoption**: Driving migration to the Polaris cloud platform for scalability, continuous updates, and reduced overhead. - **Deepening compliance automation**: Building automated policy enforcement and audit-ready reporting for evolving regulations (e.g., EU Cyber Resilience Act, US supply chain security mandates). - **Growing market share**: Targeting new enterprise customers through a hunter sales model and competitive displacement of legacy AST vendors. - **Customer success and innovation**: Investing in AI-powered developer assistants (Black Duck Assist) and contextual intelligence (ContextAI™) to reduce mean-time-to-remediate. ## Why Work Here - **Mission-driven impact**: Work on critical security infrastructure that protects software used by thousands of organizations worldwide. - **Remote-friendly culture**: Open roles (e.g., Lead Enterprise Account Executive in Canada) explicitly support remote work; the company values flexibility and results. - **Values**: “We Scale Up” (ambition and growth), “We Lead with Integrity” (honesty and transparency), “We Put Customers First” (empathy and value delivery), and “We Are Bold” (challenge convention, take smart risks). - **Engineering culture**: Developer-first mindset; teams build tools that developers love to use. Focus on innovation in AI, cloud-native architecture, and security research. - **Career growth**: Independent company with PE backing offers agility and resources; opportunity to shape the future of a market-leading security platform. - **Notable perks**: Not explicitly listed, but the company emphasizes professional development, a collaborative environment, and the chance to work on cutting-edge security challenges. ## Sources 1. [Black Duck About Us](https://www.blackduck.com/company.html) 2. [Black Duck Main Site](https://www.blackduck.com/) 3. [Black Duck Careers](https://www.blackduck.com/company/careers.html) 4. [Black Duck Leadership](https://www.blackduck.com/company/leadership.html) 5. [Greenhouse Job Posting (Lead Enterprise Account Executive Canada)](https://job-boards.greenhouse.io/blackduck/jobs/5226170008) ## Other roles at Black Duck Software, Inc. - [Sever Engineer](https://feeny.ai/job/sever-engineer-black-duck-software-inc-burlington-j7dtb4599qnb) — Burlington, MA - [Sr Sales Development Representative](https://feeny.ai/job/sr-sales-development-representative-black-duck-software-inc-tokyo-9v9vzyabb3sf) — Tokyo, Japan - [Director of HR - Japan](https://feeny.ai/job/director-of-hr-japan-black-duck-software-inc-tokyo-3vaypjenvp7y) — Tokyo, Japan - [Principal Software Engineer (IAM)](https://feeny.ai/job/principal-software-engineer-iam-black-duck-software-inc-calgary-afs25q8ekrfa) — Calgary, Canada - [Regional Field CTO](https://feeny.ai/job/regional-field-cto-black-duck-software-inc-emea-black-duck-has-entities-in-uk-fxdr0pnsz5hk) — Emea Black Duck Has Entities in UK Germany Netherlands France Italy Ireland Finland, Sweden - [Principle Software Engineer](https://feeny.ai/job/principle-software-engineer-black-duck-software-inc-belfast-jynsznkav9fp) — Belfast, United Kingdom - [Regional Field Chief Technology Officer](https://feeny.ai/job/regional-field-chief-technology-officer-black-duck-software-inc-tokyo-bfh92k0vbhfa) — Tokyo, Japan - [Director Sales Enablement](https://feeny.ai/job/director-sales-enablement-black-duck-software-inc-us-gqf7drynqf4z) — US, OR - [Server Engineer](https://feeny.ai/job/server-engineer-black-duck-software-inc-calgary-d8a0ve98xk6e) — Calgary, Canada - [Sr Director, Technology Partner Alliances Development](https://feeny.ai/job/sr-director-technology-partner-alliances-development-black-duck-software-inc-e7qewkcbn7ep) — United States