....Loading
....Loading
Senior Product Security Engineer (Black Duck & Application Security)
Location: Philadelphia. Hybrid (3 days in-person,2 days remote)
Duration: 1+ Years
Role Summary
We are seeking a highly experienced Senior Product Security Engineer with strong expertise in Black Duck, software composition analysis (SCA), and product security. The ideal candidate will possess deep technical knowledge of application and product security practices and have hands-on experience integrating and automating security solutions using Black Duck APIs. This role requires close collaboration with R&D, development, and security teams to identify, assess, and remediate security risks across software products.
Key Responsibilities
• Administer, configure, and optimize Black Duck for software composition analysis and open-source governance.
Required Qualifications
• 8+ years of experience in Cybersecurity, Product Security, or Application Security.
• Strong hands-on experience with Black Duck and Software Composition Analysis (SCA).
• Experience working with Black Duck APIs and security tool integrations.
• Deep understanding of secure software development and product security principles.
• Knowledge of vulnerability management, CVE analysis, and remediation practices.
• Experience with DevSecOps and integrating security into CI/CD pipelines.
• Strong communication and stakeholder management skills.
Preferred Qualifications
• Experience with secure coding practices and application security testing.
• Knowledge of OWASP Top 10, SBOM, Open-Source Risk Management, and Supply Chain Security.
• Familiarity with cloud security environments (AWS, Azure, or GCP).
• Relevant security certifications such as CISSP, CSSLP, GWAPT, GSEC, or equivalent.