Lead Incident Security Responder

1 month, 2 weeks ago
Full-time
Lead
Cybersecurity
Black Duck Inn

Black Duck Inn

Black Duck Inn provides application security testing tools and services designed to help organizations build high-quality, secure software, and is recognized as a leader in the AppSec industry by Gartner and Forrester.

Internet Software & Services
1K-5K
Founded 2002
$2M raised

Description

  • Partner with engineering teams on architecture reviews, threat models, and security design feedback for Black Duck products.
  • Support the secure development lifecycle across SCA, SAST, secret scanning, dependency hygiene, and build pipeline security.
  • Triage internal and externally reported product vulnerabilities and help drive remediation with engineering teams.
  • Coordinate vulnerability fixes and support customer-facing communications when needed.
  • Handle customer security questionnaires, audit requests, and ad hoc product security questions.
  • Draft technically accurate responses to customer security inquiries and gather supporting evidence from engineering.
  • Join customer security calls as a subject matter expert and contribute reusable responses to the knowledge base.
  • Support detection engineering and incident response activities, especially where they intersect with product security risks.
  • Maintain and tune detection content in CrowdStrike NG-SIEM and Sumo Logic and help resolve MDR escalations.
  • Contribute to SOAR automations, runbooks, project tracking in Jira, vendor evaluations, documentation, and mentoring of less experienced team members.

Requirements

  • 7–8 years of applicable experience in product security, application security, or security engineering.
  • Hands-on depth in at least two areas: secure SDLC, threat modeling, secure code review, vulnerability management, product incident response, or customer-facing product security work.
  • Working knowledge of application security tooling, including SCA, SAST, DAST, and secret scanning.
  • Familiarity with at least one major cloud platform from a security perspective: AWS, Azure, or GCP.
  • Awareness of AI and LLM security risks, including prompt injection, sensitive data exposure, and the OWASP Top 10 for LLM Applications.
  • Ability to work independently under general guidance and lead workstreams or small project teams without formal direct-report authority.
  • Practical use of AI and LLM tools to accelerate security work, with sound judgment on when human validation is required.
  • Strong written and verbal communication skills and the ability to explain technical topics to technical and non-technical stakeholders.
  • Bachelor’s degree in Computer Science, Information Security, Information Technology, or equivalent practical experience.
  • Experience contributing to a PSIRT or equivalent product vulnerability response process (preferred).
  • Familiarity with CVSS, embargo handling, and coordinated disclosure (preferred).
  • Industry certifications such as CISSP, CSSLP, GWAPT, GPEN, OSCP, OSWE, or cloud security equivalents are a plus.
  • Experience supporting customer security questionnaires, RFPs, or third-party risk assessments (preferred).

Benefits

  • Pay range of CAD $100,000 to $150,000.
  • Equal opportunity employer with reasonable accommodations for individuals with disabilities.
  • General office environment with standard computer-based work.
  • Occasional travel may be required.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Information Security Infrastructure Engineer - Security Architecture - InfoSec

Elastic 1K-5K Internet Software & Services

Elastic is hiring a Senior Information Security Infrastructure Engineer to operate security telemetry ingestion pipelines and Elasticsearch infrastructure that support detection, incident response, and consulting teams.

Elasticsearch GitHub GitHub Actions Helm Kubernetes Python REST API Terraform
5 hours, 57 minutes ago

Senior Information Security Infrastructure Engineer - Security Architecture - InfoSec

Elastic 1K-5K Internet Software & Services

Elastic is hiring a Senior Information Security Infrastructure Engineer for its InfoSec Security Architecture team to own security telemetry ingestion, Elasticsearch infrastructure, and data reliability supporting detection, incident response, and consulting teams.

Elasticsearch GitHub GitHub Actions Helm Kubernetes Python REST API Terraform
6 hours, 12 minutes ago

Senior Information Security Infrastructure Engineer - Security Architecture - InfoSec

Elastic 1K-5K Internet Software & Services

Elastic is hiring a Senior Information Security Infrastructure Engineer for its InfoSec Security Architecture team to operate security telemetry ingestion pipelines and maintain the Elasticsearch infrastructure supporting detection, incident response, and security consulting.

Elasticsearch GitHub GitHub Actions Helm Kubernetes Python REST API Terraform
6 hours, 27 minutes ago

Cybersecurity Engineer

Business Wire 251-1K Media

Business Wire is seeking a Cybersecurity Engineer to protect its applications, cloud infrastructure, and IT systems by identifying vulnerabilities and integrating security practices throughout software development and operations.

AWS CI/CD Cybersecurity Penetration Testing
7 hours, 27 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers