Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

Spectraforce

Senior Product Security Engineer (Black Duck & Application Security)

Career Insights for Cyber Security Engineer

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on Pennsylvania data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

A Cyber Security Engineer designs systems that protect the security of large databases, including databases with customer information and patient files. Examines client computer systems, identifies weak points in security, develops and implements new systems, monitors and responds to security issues.

$108,974 / year median in Pennsylvania

-0% projected decline

Explore Career

Job Description

Senior Product Security Engineer (Black Duck & Application Security)
Location:
Philadelphia. Hybrid (3 days in-person,2 days remote)
Duration:
1+ Years Role Summary We are seeking a highly experienced Senior Product Security Engineer with strong expertise in Black Duck, software composition analysis (SCA), and product security. The ideal candidate will possess deep technical knowledge of application and product security practices and have hands-on experience integrating and automating security solutions using Black Duck APIs. This role requires close collaboration with R D, development, and security teams to identify, assess, and remediate security risks across software products. Key Responsibilities
  • Administer, configure, and optimize Black Duck for software composition analysis and open-source governance.
  • Develop and maintain integrations leveraging Black Duck APIs and security automation workflows.
  • Partner with development and R D teams to embed security best practices throughout the software development lifecycle (SDLC).
  • Analyze security vulnerabilities, recommend remediation strategies, and track resolution.
  • Conduct security assessments, reviews, and risk evaluations for product releases.
  • Provide expertise in one or more of the following areas: o Memory Leak and Memory Soak Testing o Mobile Application Security o Security Patching and Vulnerability Remediation Strategies o Cryptographic Agility and Modern Encryption Concepts
  • Support threat modeling, secure design reviews, and security architecture discussions.
  • Drive continuous improvement of product security processes, tools, and governance. Required Qualifications
  • 8+ years of experience in Cybersecurity, Product Security, or Application Security.
  • Strong hands-on experience with Black Duck and Software Composition Analysis (SCA).
  • Experience working with Black Duck APIs and security tool integrations.
  • Deep understanding of secure software development and product security principles.
  • Knowledge of vulnerability management, CVE analysis, and remediation practices.
  • Experience with DevSecOps and integrating security into CI/CD pipelines.
  • Strong communication and stakeholder management skills. Preferred Qualifications
  • Experience with secure coding practices and application security testing.
  • Knowledge of OWASP Top 10, SBOM, Open-Source Risk Management, and Supply Chain Security.
  • Familiarity with cloud security environments (AWS, Azure, or GCP).
  • Relevant security certifications such as CISSP, CSSLP, GWAPT, GSEC, or equivalent.

Benefits

  • Dental Insurance