Lead Product Security

Location
Remote - Canada
Workplace
Remote ok
Compensation
CA$100k – CA$150k

About this role

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.

Lead Product Security

Job Title:  Lead Product Security

Reports to (Direct Title):  Director of Security Operations

Department:  Cybersecurity

 

Position Summary

The Lead Product Security is the senior technical authority for how security is designed into Black Duck products. Operating with broad autonomy under general guidance, the role will lead secure architecture and design reviews, contribute to the threat modeling methodology, and set the standards and design gates that define what secure-by-default means for our engineering teams. A core part of the role is scaling security capability rather than absorbing security work: the role will help mature and evolve the Security Champions program, mentor engineers and less experienced security staff, and build the enablement content that lets product teams reason about security themselves. The Lead Product Security will also drive deep secure code review in high-risk areas, support external security assessments, partner with PSIRT on product vulnerability response, and measure product security maturity to guide a prioritized improvement roadmap.

 

Essential Functions/Responsibilities

  • Lead security architecture and design reviews for Black Duck SCA, Coverity, and adjacent product lines, delivering actionable feedback before implementation begins.
  • Contribute to the threat modeling methodology and help scale its adoption: coach engineers to run their own models and review outputs, rather than serving as the sole modeler.
  • Define security requirements, design gates, and product security baselines that give engineering a testable definition of secure-by-default.
  • Build and measure the secure development lifecycle across SCA, SAST, secret scanning (GitGuardian), dependency hygiene, and build pipeline integrity.
  • Perform deep secure code review on high-risk areas including authentication, authorization, cryptography, secrets handling, and input validation.
  • Secure the product supply chain and release process, including SBOM generation and the integrity of build and distribution artifacts.
  • Help mature and evolve the Security Champions program: recruit champions across product teams, grow the training and enablement curriculum, run office hours, and report on participation and outcomes.
  • Mentor engineers and less experienced security staff on secure design, secure code review, and threat modeling, growing capability across the organization rather than absorbing the work.
  • Assist with the scoping and coordination of penetration tests and third-party security assessments; triage findings and drive remediation to closure with engineering owners.
  • Partner with PSIRT on triage and fix coordination for internally discovered and externally reported product vulnerabilities, feeding root causes back into design and SDLC controls.
  • Measure product security maturity using BSIMM or SAMM style assessment and drive a prioritized improvement roadmap.
  • Support EU Cyber Resilience Act secure-by-design and vulnerability handling obligations with the technical evidence and process changes engineering needs.
  • Provide technical subject matter expertise on customer security questionnaires, audit requests, and security escalations, drafting accurate answers, gathering evidence from engineering, and building a reusable knowledge base of vetted responses.
  • Support incident response for issues that touch product code, build systems, or product infrastructure, contributing product-specific context and remediation guidance.
  • Lead discrete workstreams within larger product security initiatives, track milestones in Jira, and provide technical input into application security tooling evaluations and POCs.
  • Other tasks and activities as assigned.

 

 

Required Education/Experience & Skills

  • Awareness of AI and LLM security risks such as prompt injection, sensitive data exposure, and the OWASP Top 10 for LLM Applications.
  • Bachelor’s degree in Computer Science, Information Security, Information Technology, or equivalent practical experience.
  • 8+ years of experience in product security, application security, or software security engineering, with hands-on depth in secure design review, threat modeling, and secure code review.
  • Demonstrated experience building or running a security champions program, developer enablement initiative, or equivalent effort that scaled security capability across engineering teams.
  • Working knowledge of application security tooling (SCA, SAST, DAST, secret scanning), the vulnerability classes each detects, and where each produces false positives.
  • Practical secure coding and review experience in at least one language used in commercial software products, with the ability to read unfamiliar code and reason about security impact.
  • Experience defining security requirements, standards, or design gates that engineering teams actually adopted.
  • Familiarity with at least one major cloud platform (AWS, Azure, or GCP) from a product security perspective, including container and infrastructure-as-code security.
  • Experience coordinating penetration tests or third-party security assessments and driving findings through to remediation.
  • Demonstrated ability to mentor engineers and lead technical workstreams without formal direct-report authority.
  • Practical use of AI and LLM tools to accelerate day-to-day security work (secure code review, investigation, documentation), with sound judgment about when AI-generated output requires human validation before it is shared, shipped, or acted on.
  • Strong written and verbal communication skills, including the ability to explain technical security topics to engineers, security peers, and non-technical stakeholders.
  • Experience contributing to a Product Security Incident Response Team (PSIRT) or equivalent product vulnerability response process, including CVSS scoring and coordinated disclosure, is a plus.
  • Familiarity with product security maturity models (BSIMM, SAMM) or secure-by-design regulatory requirements such as the EU Cyber Resilience Act is a plus.
  • Industry certifications such as CSSLP, CISSP, GWAPT, OSWE, or cloud security equivalents are a plus.
  • Experience supporting customer security questionnaires, RFPs, or third-party risk assessments is a plus.

 

Physical Requirements

General office environment and responsibilities requiring:

  • Extensive use of the computer which involves viewing a monitor and keyboarding for most of the workday
  • Placing and receiving phone calls
  • Occasionally moving and lifting objects up to 20 pounds

May require some travel as needed

Pay Range
$117,000$150,000 CAD

Black Duck is an equal opportunity employer. We consider all applicants for employment without regard to race, color, national origin, religion, sex, gender identity or expression, age, disability, sexual orientation, veteran or military service status, or any other characteristic protected by applicable law. Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law.

Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?