Lead Product Security
Core
Lead product security work across Black Duck's portfolio, protecting products and supporting customer security inquiries.
Role type
Senior IC product security lead
Builds
Secure development lifecycle for SCA, SAST, secret scanning, and build pipeline security
Domain
Application security / DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure
Required skills
product security, application security, secure SDLC, threat modeling, secure code review, vulnerability management, product incident response, customer-facing security, cloud security (AWS/Azure/GCP), AI/LLM security risks, vulnerability scoring (CVSS), coordinated disclosure
Preferred skills
CISSP, CSSLP, GWAPT, GPEN, OSCP, OSWE, cloud security certifications, RFP support, third-party risk assessment
Technologies
SCA, SAST, DAST, GitGuardian, CrowdStrike NG-SIEM, Sumo Logic, Jira
Responsibilities
Partner with engineering on architecture reviews, threat models, and security design feedback; triage and resolve product vulnerabilities; coordinate fixes and customer communications; draft technical answers to security inquiries; join customer security calls as SME; maintain detection content and SOAR automations; lead discrete workstreams and track projects; mentor team members on product security and threat modeling.
Seniority
Senior, hands-on IC with program coordination