
5001 - 10000 employees
🔒 Cybersecurity
☁️ SaaS
📋 Compliance
Cybersecurity • SaaS • Compliance
Black Duck is a leader in application security testing and software composition analysis. Now part of Synopsys Software Integrity Group, it offers a unified SaaS platform optimized for DevSecOps. Their solutions enable businesses to automate security testing across the entire software development life cycle, manage open source licenses and compliance, and secure the software supply chain. Recognized as a leader by Gartner and Forrester, Black Duck provides a range of services including static, dynamic, and interactive application security testing, as well as open source audits and risk management solutions.
🕒 July 24
🇨🇦 Canada – Remote
💵 $100k - $150k / year
⏰ Full Time
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
👻 Ghost score 1%
Improve your chances of getting an interview by checking your resume score before you apply.

5001 - 10000 employees
🔒 Cybersecurity
☁️ SaaS
📋 Compliance
Cybersecurity • SaaS • Compliance
Black Duck is a leader in application security testing and software composition analysis. Now part of Synopsys Software Integrity Group, it offers a unified SaaS platform optimized for DevSecOps. Their solutions enable businesses to automate security testing across the entire software development life cycle, manage open source licenses and compliance, and secure the software supply chain. Recognized as a leader by Gartner and Forrester, Black Duck provides a range of services including static, dynamic, and interactive application security testing, as well as open source audits and risk management solutions.
• Partner with engineering teams building Black Duck SCA, Coverity, and adjacent products on architecture reviews, threat models, and security design feedback. • Contribute to a measurable secure development lifecycle covering SCA, SAST, secret scanning (GitGuardian), dependency hygiene, and build pipeline security. • Recommend systematic improvements when patterns emerge across the portfolio rather than relying on one-off fixes. • Triage internally discovered and externally reported product vulnerabilities and help drive resolution with engineering teams. • Coordinate vulnerability fixes with engineering and support customer-facing communications when needed. • Help triage customer security questionnaires, audit requests, and ad hoc product security questions in close partnership with the Director of Security Operations. • Draft technically accurate answers to customer security inquiries; gather evidence from engineering when needed. • Join customer security calls as a subject matter expert when called upon and contribute to a growing knowledge base of reusable responses. • Support detection engineering and incident response activities across the corporate environment, with a focus on issues that intersect with our products. • Maintain and tune detection content in CrowdStrike NG-SIEM and Sumo Logic related to product security risks; help work escalations from our MDR provider (ReliaQuest). • Contribute to SOAR automations and runbooks that reduce manual toil. • Lead discrete workstreams within larger security initiatives or coordinate small project teams where appropriate. • Track projects through Jira with clear milestones and concise status updates; provide technical input into vendor evaluations and POCs across the SecOps and AppSec stack. • Act as an informal resource and mentor for less experienced team members on product security, secure development, and threat modeling. • Explain difficult or sensitive technical information clearly to engineers, security peers, and non-technical stakeholders. • Document tribal knowledge into runbooks, SOPs, and onboarding materials. • Other tasks and activities as assigned.
• At least 7 – 8 years of applicable experience in product security, application security, or security engineering, with hands-on depth in at least two of the following: secure SDLC, threat modeling, secure code review, vulnerability management, product incident response, or customer-facing product security work. • Working knowledge of application security tooling (SCA, SAST, DAST, secret scanning) and the vulnerabilities they catch. • Familiarity with at least one major cloud platform (AWS, Azure, or GCP) from a security perspective. • Awareness of AI and LLM security risks such as prompt injection, sensitive data exposure, and the OWASP Top 10 for LLM Applications. • Demonstrated ability to work independently under general guidance and to lead workstreams or small project teams without formal direct-report authority. • Practical use of AI and LLM tools to accelerate day-to-day security work (investigation, query drafting, secure code review, documentation), with sound judgment about when AI-generated output requires human validation before it is shared, shipped, or acted on. • Strong written and verbal communication skills, including the ability to explain technical security topics to engineers, security peers, and non-technical stakeholders; calm and steady under incident, audit, or customer-escalation pressure. • Bachelor’s degree in Computer Science, Information Security, Information Technology, or equivalent practical experience. • Experience contributing to a Product Security Incident Response Team (PSIRT) or equivalent product vulnerability response process. • Familiarity with vulnerability scoring (CVSS), embargo handling, and coordinated disclosure. • Industry certifications such as CISSP, CSSLP, GWAPT, GPEN, OSCP, OSWE, or cloud security equivalents are a plus. • Experience supporting customer security questionnaires, RFPs, or third-party risk assessments.
Apply Now🕒 July 21
Senior Security Engineer integrated in product security team at Lime. Responsible for security reviews, tool development, and incident response in a remote capacity.
🇨🇦 Canada – Remote
💵 CA$120k - CA$165k / year
💰 $418M Convertible Note on 2021-11
⏰ Full Time
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
🕒 July 20
Senior Security Engineer at Mozilla managing the Web Bug Bounty program while ensuring product privacy and safety. Collaborating with security teams on incidents and vulnerability remediation.
🕒 June 26
1001 - 5000
Lead Information Security Engineer at Arctic Wolf responsible for designing, implementing, and operating security capabilities. Focusing on building and integrating security systems with high growth and innovative technologies.
🕒 June 26
Information Security Specialist enhancing security posture across systems and cloud environments for Teladoc Health Canada. Championing corporate IT security strategy and regulatory compliance efforts.
🇨🇦 Canada – Remote
💵 $175k - $200k / year
💰 $80M Post-IPO Debt - Teladoc Health on 2016-07
⏰ Full Time
🟠 Senior
🔴 Lead
👮♂️ Cybersecurity / Security Engineer
🕒 June 18
Key security engineer conducting offensive security techniques to strengthen Instacart's products. Collaborating with cross-functional teams and mentoring for continuous growth.
🇨🇦 Canada – Remote
💵 $196k - $207k / year
💰 $232M Venture Round on 2021-11
⏰ Full Time
🟠 Senior
👮♂️ Cybersecurity / Security Engineer