JobRaahGet matched free

Jobs

Lead Product Security

Black Duck Software, Inc. · Remote - Canada · Remote

Pay: CAD 117,000 – 150,000 a year

Posted Jul 24, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle. Lead Product Security Job Title: Lead Product Security Reports to (Direct Title): Director of Security Operations Department: Cybersecurity Position Summary The Lead Product Security is the senior technical authority for how security is designed into Black Duck products. Operating with broad autonomy under general guidance, the role will lead secure architecture and design reviews, contribute to the threat modeling methodology, and set the standards and design gates that define what secure-by-default means for our engineering teams. A core part of the role is scaling security capability rather than absorbing security work: the role will help mature and evolve the Security Champions program, mentor engineers and less experienced security staff, and build the enablement content that lets product teams reason about security themselves. The Lead Product Security will also drive deep secure code review in high-risk areas, support external security assessments, partner with PSIRT on product vulnerability response, and measure product security maturity to guide a prioritized improvement roadmap. Essential Functions/Responsibilities Lead security architecture and design reviews for Black Duck SCA, Coverity, and adjacent product lines, delivering actionable feedback before implementation begins. Contribute to the threat modeling methodology and help scale its adoption: coach engineers to run their own models and review outputs, rather than serving as the sole modeler. Define security requirements, design gates, and product security baselines that give engineering a testable definition of secure-by-default. Build and measure the secure development lifecycle across SCA, SAST, secret scanning (GitGuardian), dependency hygiene, and build pipeline integrity. Perform deep secure code review on high-risk areas including authentication, authorization, cryptography, secrets handling, and input validation. Secure the product supply chain and release process, including SBOM generation and the integrity of build and distribution artifacts. Help mature and evolve the Security Champions program: recruit champions across product teams, grow the training and enablement curriculum, run office hours, and report on participation and outcomes. Mentor engineers and less experienced security staff on secure design, secure code review, and threat modeling, growing capability…