
Lead Incident Security Responder
Posted Jul 24

Posted Jul 24
This is a fully remote position, open to applicants in Canada.
• Collaborate with engineering teams developing Black Duck SCA, Coverity, and related products to conduct architecture reviews, threat modeling, and provide feedback on security design.
• Contribute to a measurable secure development lifecycle encompassing SCA, SAST, secret scanning (GitGuardian), dependency management, and build pipeline security.
• Suggest systematic enhancements when recurring patterns are identified across the portfolio instead of implementing one-off solutions.
• Assess both internally discovered and externally reported product vulnerabilities and assist engineering teams in driving resolutions.
• Coordinate vulnerability remediation with engineering teams and facilitate customer-facing communications as necessary.
• Assist in evaluating customer security questionnaires, audit requests, and ad hoc product security inquiries in close collaboration with the Director of Security Operations.
• Prepare technically accurate responses to customer security questions; collect evidence from engineering when required.
• Participate in customer security discussions as a subject matter expert when necessary and contribute to a growing repository of reusable responses.
• Support detection engineering and incident response efforts across the corporate environment, focusing on issues that intersect with our products.
• Maintain and optimize detection content in CrowdStrike NG-SIEM and Sumo Logic related to product security risks; assist with escalations from our MDR provider (ReliaQuest).
• Contribute to SOAR automations and runbooks that minimize manual effort.
• Lead specific workstreams within broader security initiatives or coordinate small project teams as appropriate.
• Monitor projects using Jira with clear milestones and concise status updates; provide technical input into vendor assessments and proofs of concept across the SecOps and AppSec spectrum.
• Serve as an informal resource and mentor for less experienced team members on product security, secure development, and threat modeling.
• Clearly communicate complex or sensitive technical information to engineers, security colleagues, and non-technical stakeholders.
• Document essential knowledge into runbooks, standard operating procedures (SOPs), and onboarding materials.
• Perform other tasks and responsibilities as assigned.
• A minimum of 7 to 8 years of relevant experience in product security, application security, or security engineering, with hands-on expertise in at least two of the following areas: secure SDLC, threat modeling, secure code review, vulnerability management, product incident response, or customer-facing product security roles.
• Proficient understanding of application security tools (SCA, SAST, DAST, secret scanning) and the vulnerabilities they identify.
• Familiarity with at least one major cloud platform (AWS, Azure, or GCP) from a security perspective.
• Awareness of AI and LLM security threats such as prompt injection, sensitive data exposure, and the OWASP Top 10 for LLM Applications.
• Proven ability to work independently under general guidance and lead workstreams or small project teams without formal direct-report authority.
• Practical experience using AI and LLM tools to enhance daily security tasks (investigation, query creation, secure code review, documentation), with sound judgment about when AI-generated outputs need human validation before being shared or acted upon.
• Excellent written and verbal communication skills, including the capability to articulate technical security topics to engineers, security peers, and non-technical stakeholders; composed and steady under incident, audit, or customer escalation pressures.
• Bachelor’s degree in Computer Science, Information Security, Information Technology, or equivalent practical experience.
• Experience contributing to a Product Security Incident Response Team (PSIRT) or a similar product vulnerability response process.
• Familiarity with vulnerability scoring (CVSS), embargo handling, and coordinated disclosure practices.
• Industry certifications such as CISSP, CSSLP, GWAPT, GPEN, OSCP, OSWE, or cloud security equivalents are advantageous.
• Experience assisting with customer security questionnaires, requests for proposals (RFPs), or third-party risk assessments.
• Comprehensive health benefits package.
• Flexible working hours and remote work options.
• Opportunities for continuous professional development and training.
• Collaborative and innovative work environment.
• Competitive salary and performance-based bonuses.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.