Lead Incident Security Responder

1 hour, 42 minutes ago
Full-time
Lead
Cybersecurity
Black Duck Inn

Black Duck Inn

Black Duck Inn provides application security testing tools and services designed to help organizations build high-quality, secure software, and is recognized as a leader in the AppSec industry by Gartner and Forrester.

Internet Software & Services
1K-5K
Founded 2002
$2M raised

Description

  • Partner with engineering teams on architecture reviews, threat models, and security design feedback for Black Duck products.
  • Support the secure development lifecycle across SCA, SAST, secret scanning, dependency hygiene, and build pipeline security.
  • Triage internal and externally reported product vulnerabilities and help drive remediation with engineering teams.
  • Coordinate vulnerability fixes and support customer-facing communications when needed.
  • Handle customer security questionnaires, audit requests, and ad hoc product security questions.
  • Draft technically accurate responses to customer security inquiries and gather supporting evidence from engineering.
  • Join customer security calls as a subject matter expert and contribute reusable responses to the knowledge base.
  • Support detection engineering and incident response activities, especially where they intersect with product security risks.
  • Maintain and tune detection content in CrowdStrike NG-SIEM and Sumo Logic and help resolve MDR escalations.
  • Contribute to SOAR automations, runbooks, project tracking in Jira, vendor evaluations, documentation, and mentoring of less experienced team members.

Requirements

  • 7–8 years of applicable experience in product security, application security, or security engineering.
  • Hands-on depth in at least two areas: secure SDLC, threat modeling, secure code review, vulnerability management, product incident response, or customer-facing product security work.
  • Working knowledge of application security tooling, including SCA, SAST, DAST, and secret scanning.
  • Familiarity with at least one major cloud platform from a security perspective: AWS, Azure, or GCP.
  • Awareness of AI and LLM security risks, including prompt injection, sensitive data exposure, and the OWASP Top 10 for LLM Applications.
  • Ability to work independently under general guidance and lead workstreams or small project teams without formal direct-report authority.
  • Practical use of AI and LLM tools to accelerate security work, with sound judgment on when human validation is required.
  • Strong written and verbal communication skills and the ability to explain technical topics to technical and non-technical stakeholders.
  • Bachelor’s degree in Computer Science, Information Security, Information Technology, or equivalent practical experience.
  • Experience contributing to a PSIRT or equivalent product vulnerability response process (preferred).
  • Familiarity with CVSS, embargo handling, and coordinated disclosure (preferred).
  • Industry certifications such as CISSP, CSSLP, GWAPT, GPEN, OSCP, OSWE, or cloud security equivalents are a plus.
  • Experience supporting customer security questionnaires, RFPs, or third-party risk assessments (preferred).

Benefits

  • Pay range of CAD $100,000 to $150,000.
  • Equal opportunity employer with reasonable accommodations for individuals with disabilities.
  • General office environment with standard computer-based work.
  • Occasional travel may be required.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Junior IT Engineer

Arionkoder 51-250 Internet Software & Services

Arionkoder is hiring a Junior IT Engineer to support internal IT operations for access, equipment, cloud platforms, and compliance-related administration.

AWS Confluence GCP JIRA
1 hour, 27 minutes ago

Security / DevSecOps Engineer (Blockchain-Fintech)

Alloy Internet Software & Services

Index Industries is seeking a DevSecOps engineer to secure its stealth-stage blockchain and cloud infrastructure as it prepares to launch its first technology in 2026.

AWS Blockchain CI/CD DevSecOps Docker GCP Go Kubernetes Python Secrets Management
1 day ago

Senior Software Engineer - Security Libraries

Datadog 5K-10K IT Services

Datadog is hiring a senior polyglot engineer to build and operate security library integrations for its run-time security products, with a primary focus on .NET or Java.

C# C++ Envoy Go HAProxy Java Maven .NET Nginx Node.js PHP Python Ruby WAF
1 day ago

Head of Security Research

Dropzone AI 51-200 computer & network security

Dropzone AI is hiring a Head of Security Research to lead its cybersecurity research and detection team as the company builds agentic AI systems that reimagine threat intelligence, hunting, detection engineering, and alert investigation.

Cybersecurity SOC
1 day ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers