Our client, a IT Services and Consulting company, is looking for a Senior Product Security Engineer (Black Duck & Application Security) for their Philadelphia, PA/Hybrid location.
Responsibilities:
This role requires close collaboration with R&D, development, and security teams to identify, assess, and remediate security risks across software products.
Administer, configure, and optimize Black Duck for software composition analysis and open-source governance.
Develop and maintain integrations leveraging Black Duck APIs and security automation workflows.
Partner with development and R&D teams to embed security best practices throughout the software development lifecycle (SDLC).
Analyze security vulnerabilities, recommend remediation strategies, and track resolution.
Conduct security assessments, reviews, and risk evaluations for product releases.
Provide expertise in one or more of the following areas:
Memory Leak and Memory Soak Testing
Mobile Application Security
Security Patching and Vulnerability Remediation Strategies
Cryptographic Agility and Modern Encryption Concepts
Support threat modeling, secure design reviews, and security architecture discussions.
Drive continuous improvement of product security processes, tools, and governance.
Requirements:
We are seeking a highly experienced Senior Product Security Engineer with strong expertise in Black Duck, software composition analysis (SCA), and product security.
The ideal candidate will possess deep technical knowledge of application and product security practices and have hands-on experience integrating and automating security solutions using Black Duck APIs.
8+ years of experience in Cybersecurity, Product Security, or Application Security.
Strong hands-on experience with Black Duck and Software Composition Analysis (SCA).
Experience working with Black Duck APIs and security tool integrations.
Deep understanding of secure software development and product security principles.
Knowledge of vulnerability management, CVE analysis, and remediation practices.
Experience with DevSecOps and integrating security into CI/CD pipelines.
Strong communication and stakeholder management skills.
Preferred Qualifications
Experience with secure coding practices and application security testing.
Knowledge of OWASP Top 10, SBOM, Open-Source Risk Management, and Supply Chain Security.
Familiarity with cloud security environments (AWS, Azure, or GCP).
Relevant security certifications such as CISSP, CSSLP, GWAPT, GSEC, or equivalent.
ICONMA is a global information consulting management firm providing Professional Staffing Services and Project-Based Solutions for organizations in a broad range of industries.
Corporate Headquarters in Troy, Michigan; 20+ locations worldwide.
Certified Woman-Owned Business Enterprise (WBE); certified by Women’s Business Enterprise National Council, National Women Business Owners Corporation (NWBOC); and California Public Utilities Commission (CPUC).
Founded in 2000
2000+ Employees
The company was founded on the principle that success is derived from delivering high quality service and resources in the most responsive, flexible, and innovative way. ICONMA invests in people and resources with a single goal: To provide our customers with the highest quality service in the most responsive manner. Through its network of offices, ICONMA provides the resources to help clients maintain their competitive advantage.
Skills
Amazon Web Services (AWS)unmatched
Analysis Skillsunmatched
Application Programming Interface (API)unmatched
Applications Securityunmatched
Automationunmatched
Best Practicesunmatched
CISSP - Certified Information Systems Security Professionalunmatched