--- title: 'Lead Product Security at Black Duck Software, Inc.' canonical: 'https://feeny.ai/job/lead-product-security-black-duck-software-inc-canada-ygvjnrag8r0z' type: 'job' last_seen: '2026-09-05' --- # Lead Product Security at Black Duck Software, Inc. - **Company:** Black Duck Software, Inc. - **Location:** Canada - **Compensation:** $117k–$150k - **Work type:** remote - **Posted:** 2026-07-24 - **Last confirmed live:** 2026-09-05 - **Apply:** https://job-boards.greenhouse.io/blackduck/jobs/5287108008 ## Job description Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle. Lead Product Security Job Title:  Lead Product Security Reports to (Direct Title):  Director of Security Operations Department:  Cybersecurity Position Summary The Lead Product Security is the senior technical authority for how security is designed into Black Duck products. Operating with broad autonomy under general guidance, the role will lead secure architecture and design reviews, contribute to the threat modeling methodology, and set the standards and design gates that define what secure-by-default means for our engineering teams. A core part of the role is scaling security capability rather than absorbing security work: the role will help mature and evolve the Security Champions program, mentor engineers and less experienced security staff, and build the enablement content that lets product teams reason about security themselves. The Lead Product Security will also drive deep secure code review in high-risk areas, support external security assessments, partner with PSIRT on product vulnerability response, and measure product security maturity to guide a prioritized improvement roadmap. Essential Functions/Responsibilities - Lead security architecture and design reviews for Black Duck SCA, Coverity, and adjacent product lines, delivering actionable feedback before implementation begins. - Contribute to the threat modeling methodology and help scale its adoption: coach engineers to run their own models and review outputs, rather than serving as the sole modeler. - Define security requirements, design gates, and product security baselines that give engineering a testable definition of secure-by-default. - Build and measure the secure development lifecycle across SCA, SAST, secret scanning (GitGuardian), dependency hygiene, and build pipeline integrity. - Perform deep secure code review on high-risk areas including authentication, authorization, cryptography, secrets handling, and input validation. - Secure the product supply chain and release process, including SBOM generation and the integrity of build and distribution artifacts. - Help mature and evolve the Security Champions program: recruit champions across product teams, grow the training and enablement curriculum, run office hours, and report on participation and outcomes. - Mentor engineers and less experienced security staff on secure design, secure code review, and threat modeling, growing capability across the organization rather than absorbing the work. - Assist with the scoping and coordination of penetration tests and third-party security assessments; triage findings and drive remediation to closure with engineering owners. - Partner with PSIRT on triage and fix coordination for internally discovered and externally reported product vulnerabilities, feeding root causes back into design and SDLC controls. - Measure product security maturity using BSIMM or SAMM style assessment and drive a prioritized improvement roadmap. - Support EU Cyber Resilience Act secure-by-design and vulnerability handling obligations with the technical evidence and process changes engineering needs. - Provide technical subject matter expertise on customer security questionnaires, audit requests, and security escalations, drafting accurate answers, gathering evidence from engineering, and building a reusable knowledge base of vetted responses. - Support incident response for issues that touch product code, build systems, or product infrastructure, contributing product-specific context and remediation guidance. - Lead discrete workstreams within larger product security initiatives, track milestones in Jira, and provide technical input into application security tooling evaluations and POCs. - Other tasks and activities as assigned. Required Education/Experience & Skills - Awareness of AI and LLM security risks such as prompt injection, sensitive data exposure, and the OWASP Top 10 for LLM Applications. - Bachelor’s degree in Computer Science, Information Security, Information Technology, or equivalent practical experience. - 8+ years of experience in product security, application security, or software security engineering, with hands-on depth in secure design review, threat modeling, and secure code review. - Demonstrated experience building or running a security champions program, developer enablement initiative, or equivalent effort that scaled security capability across engineering teams. - Working knowledge of application security tooling (SCA, SAST, DAST, secret scanning), the vulnerability classes each detects, and where each produces false positives. - Practical secure coding and review experience in at least one language used in commercial software products, with the ability to read unfamiliar code and reason about security impact. - Experience defining security requirements, standards, or design gates that engineering teams actually adopted. - Familiarity with at least one major cloud platform (AWS, Azure, or GCP) from a product security perspective, including container and infrastructure-as-code security. - Experience coordinating penetration tests or third-party security assessments and driving findings through to remediation. - Demonstrated ability to mentor engineers and lead technical workstreams without formal direct-report authority. - Practical use of AI and LLM tools to accelerate day-to-day security work (secure code review, investigation, documentation), with sound judgment about when AI-generated output requires human validation before it is shared, shipped, or acted on. - Strong written and verbal communication skills, including the ability to explain technical security topics to engineers, security peers, and non-technical stakeholders. - Experience contributing to a Product Security Incident Response Team (PSIRT) or equivalent product vulnerability response process, including CVSS scoring and coordinated disclosure, is a plus. - Familiarity with product security maturity models (BSIMM, SAMM) or secure-by-design regulatory requirements such as the EU Cyber Resilience Act is a plus. - Industry certifications such as CSSLP, CISSP, GWAPT, OSWE, or cloud security equivalents are a plus. - Experience supporting customer security questionnaires, RFPs, or third-party risk assessments is a plus. Physical Requirements General office environment and responsibilities requiring: - Extensive use of the computer which involves viewing a monitor and keyboarding for most of the workday - Placing and receiving phone calls - Occasionally moving and lifting objects up to 20 pounds May require some travel as needed Pay Range $117,000—$150,000 CAD Black Duck is an equal opportunity employer. We consider all applicants for employment without regard to race, color, national origin, religion, sex, gender identity or expression, age, disability, sexual orientation, veteran or military service status, or any other characteristic protected by applicable law. Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law. ## About Black Duck Software, Inc. ## Company Overview - **One-liner**: Black Duck provides a comprehensive application security testing (AST) platform that helps organizations build secure, high-quality software by identifying and remediating vulnerabilities, license risks, and code quality issues across proprietary, open-source, and AI-generated code. - **Entity Type**: Private (backed by private equity firms Clearlake Capital and Francisco Partners; spun out from Synopsys in October 2024) - **Headquarters**: Burlington, Massachusetts, USA - **Founded**: 2015 (as the Synopsys Software Integrity Group); became an independent company in October 2024 - **Founders**: Not applicable (formed from Synopsys); key leadership includes CEO Greg Hughes, CPTO Dipto Chakravarty, CISO Dom Glavach, CRO Roman Telerman, CFO Jim Ivers, CMO Sean Forkan, and CHRO & General Counsel Joy Meier ## Core Business - **Primary industry**: Application Security Testing (AST), DevSecOps, Software Supply Chain Security - **Target customers**: B2B; enterprise organizations, development teams, security teams, and DevOps engineers across industries including finance, healthcare, automotive, aerospace, and government - **Mission or purpose statement**: “To enable organizations to build trust in their software by providing True Scale Application Security – the ability to secure code of any size, in any environment, without compromising speed, accuracy, or compliance.” ## Products & Services - **Black Duck Polaris Platform**: Cloud-native SaaS platform that unifies SAST, SCA, and DAST into a single, integrated solution for enterprise-wide application security testing and policy enforcement. - **Black Duck SCA (Software Composition Analysis)**: Identifies vulnerabilities, license risks, and compliance issues in open-source and third-party components; generates SBOMs; includes AI Model Risk Insights. - **Coverity Static Analysis (SAST)**: Scans proprietary source code for security vulnerabilities and quality defects, with AI-powered remediation suggestions via Black Duck Assist. - **Seeker Interactive Application Security Testing (IAST)**: Combines runtime analysis with automated testing to detect vulnerabilities in running applications. - **Black Duck Signal**: Agentic AI solution that autonomously detects and remediates vulnerabilities in business-critical applications, including AI-generated code. - **Code Sight IDE Plug-in**: Provides real-time security feedback within developers’ IDEs (VS Code, JetBrains, etc.) to catch issues before code is committed. - **Black Duck Hub (on-premises)**: On-premises deployment option for customers with strict data residency or regulatory requirements. - **Hybrid deployment**: Full flexibility to run scans in cloud, on-premises, or across mixed environments. ## Market Standing - **Valuation/Market Cap**: Not disclosed (private equity-backed) - **Key Metric**: Over 4,000 organizations worldwide trust Black Duck; recognized as a Leader in the Gartner® Magic Quadrant™ for Application Security Testing for eight consecutive years (2025). - **Notable Investors/Partners**: Clearlake Capital Group, Francisco Partners (majority owners); technology partners include GitHub, GitLab, Jenkins, Azure DevOps, and major cloud providers. - **Growth Signals**: Spun out as an independent company in October 2024 to focus exclusively on application security; launched Black Duck Signal (agentic AI AppSec); expanding SaaS platform with unified SAST+SCA+DAST; hiring across sales and engineering roles (remote positions available). ## Competitive Advantages - **Comprehensive portfolio**: Only vendor offering SAST, SCA, DAST, IAST, and agentic AI in a single unified platform (Polaris). - **20+ years of human-verified intelligence**: Proprietary KnowledgeBase™ with curated vulnerability data and context, powering high-precision detection with low false positives. - **Flexible deployment**: Supports cloud (SaaS), on-premises, and hybrid models – customers choose without compromising capabilities. - **Developer-first approach**: Integrates directly into CI/CD pipelines and IDEs, enabling developers to find and fix issues within their workflow. - **AI-native security**: Built to secure AI-generated code (e.g., from GitHub Copilot, ChatGPT) with specialized detection and remediation capabilities. - **Regulatory expertise**: Supports compliance with ISO 27001, GDPR, HIPAA, PCI DSS, FedRAMP, EU Cyber Resilience Act, US Executive Order 14028, and industry-specific standards (automotive ISO/SAE 21434, aerospace, defense). ## Strategic Focus - **Securing AI-generated code**: Developing and enhancing agentic AI tools (Signal) to address the unique risks of AI-assisted development. - **Expanding SaaS adoption**: Driving migration to the Polaris cloud platform for scalability, continuous updates, and reduced overhead. - **Deepening compliance automation**: Building automated policy enforcement and audit-ready reporting for evolving regulations (e.g., EU Cyber Resilience Act, US supply chain security mandates). - **Growing market share**: Targeting new enterprise customers through a hunter sales model and competitive displacement of legacy AST vendors. - **Customer success and innovation**: Investing in AI-powered developer assistants (Black Duck Assist) and contextual intelligence (ContextAI™) to reduce mean-time-to-remediate. ## Why Work Here - **Mission-driven impact**: Work on critical security infrastructure that protects software used by thousands of organizations worldwide. - **Remote-friendly culture**: Open roles (e.g., Lead Enterprise Account Executive in Canada) explicitly support remote work; the company values flexibility and results. - **Values**: “We Scale Up” (ambition and growth), “We Lead with Integrity” (honesty and transparency), “We Put Customers First” (empathy and value delivery), and “We Are Bold” (challenge convention, take smart risks). - **Engineering culture**: Developer-first mindset; teams build tools that developers love to use. Focus on innovation in AI, cloud-native architecture, and security research. - **Career growth**: Independent company with PE backing offers agility and resources; opportunity to shape the future of a market-leading security platform. - **Notable perks**: Not explicitly listed, but the company emphasizes professional development, a collaborative environment, and the chance to work on cutting-edge security challenges. ## Sources 1. [Black Duck About Us](https://www.blackduck.com/company.html) 2. [Black Duck Main Site](https://www.blackduck.com/) 3. [Black Duck Careers](https://www.blackduck.com/company/careers.html) 4. [Black Duck Leadership](https://www.blackduck.com/company/leadership.html) 5. [Greenhouse Job Posting (Lead Enterprise Account Executive Canada)](https://job-boards.greenhouse.io/blackduck/jobs/5226170008) ## Other roles at Black Duck Software, Inc. - [Server Engineer](https://feeny.ai/job/server-engineer-black-duck-software-inc-calgary-d8a0ve98xk6e) — Calgary, Canada - [Sr Director, Technology Partner Alliances Development](https://feeny.ai/job/sr-director-technology-partner-alliances-development-black-duck-software-inc-e7qewkcbn7ep) — United States - [Lead Sales Engineer - Mandarin](https://feeny.ai/job/lead-sales-engineer-mandarin-black-duck-software-inc-singapore-jjyv23hd0b8z) — Singapore - [Director, Accounting](https://feeny.ai/job/director-accounting-black-duck-software-inc-burlington-yy1303z5fvsw) — Burlington, MA - [Application Engineer 3](https://feeny.ai/job/application-engineer-3-black-duck-software-inc-tokyo-5n80hjgp31hy) — Tokyo, Japan - [Regional Field CTO](https://feeny.ai/job/regional-field-cto-black-duck-software-inc-united-states-xs2z0cznftpv) — United States - [Application Engineer 4](https://feeny.ai/job/application-engineer-4-black-duck-software-inc-tokyo-qew8seh2skz5) — Tokyo, Japan - [Lead Sales Engineer - Enterprise/Commercial](https://feeny.ai/job/lead-sales-engineer-enterprise-commercial-black-duck-software-inc-atlanta-4ab1d9fcfgj8) — Atlanta, United States / Burlington, United States - [Implementation Consultant](https://feeny.ai/job/implementation-consultant-black-duck-software-inc-singapore-h8z0s1gy4dvt) — Singapore - [Implementation Consultation](https://feeny.ai/job/implementation-consultation-black-duck-software-inc-singapore-f5tqew96grbj) — Singapore