Senior Product Security Engineer, Black Duck & Application Security

Cognizant

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Philadelphia, PA
Salary
$90,000–$130,000 / yr
Posted
9 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $182k
This role $110k
$74k most similar roles pay here $235k

This role pays less than 97% of similar roles. Most pay $151,475–$212,625 — the shaded band above. At the midpoint, this role pays about $110k versus about $182k for comparable roles.

Based on 240 similar postings.

Employer

About Cognizant

Cognizant is a multinational IT services and consulting company offering digital transformation, technology, and business process services. It serves clients across financial services, healthcare, manufacturing, and other industries worldwide.

Cognizant currently has 37 open roles on FindRole.

Listed pay typically runs $124,500–$151,250 across 28 roles with salary data.

Most-posted roles

View all roles at Cognizant

At a glance

TL;DR · Senior Product Security Engineer, Black Duck & Application Security

Senior Product Security Engineer (Black Duck & Application Security) joins the team to manage, configure, and optimize Black Duck for software composition analysis and open-source governance. This role involves developing and maintaining integrations using Black Duck APIs and security automation workflows while collaborating with R&D and development teams to embed security best practices throughout the software development lifecycle. The engineer will analyze vulnerabilities, recommend remediation strategies, conduct risk evaluations for product releases, and support threat modeling and secure design reviews. Key technical competencies include experience in DevSecOps, CI/CD pipeline integration, CVE analysis, and vulnerability management. Specialized knowledge areas include memory leak testing, mobile application security, cryptographic agility, and supply chain security. The role addresses the critical challenge of securing software products through robust SCA practices and automated security tool integrations within complex development environments.

What you'll do

  • Administer, configure, and optimize Black Duck for software composition analysis and open-source governance.
  • Develop and maintain integrations using Black Duck APIs and security automation workflows.
  • Partner with R&D teams to embed security best practices throughout the software development lifecycle.
  • Analyze security vulnerabilities and recommend specific remediation strategies to track resolution.
  • Conduct security assessments, reviews, and risk evaluations for product releases.
  • Support threat modeling, secure design reviews, and security architecture discussions.
  • Drive continuous improvement of product security processes, tools, and governance.

What we're looking for

  • At least 8 years of experience in Cybersecurity, Product Security, or Application Security.
  • Strong hands-on experience with Black Duck and Software Composition Analysis (SCA).
  • Experience working with Black Duck APIs and security tool integrations.
  • Deep understanding of secure software development and product security principles.
  • Knowledge of vulnerability management, CVE analysis, and remediation practices.
  • Experience with DevSecOps and integrating security into CI/CD pipelines.
  • Strong communication and stakeholder management skills.
  • Relevant security certifications such as CISSP, CSSLP, GWAPT, GSEC, or equivalent are preferred.

More like this

Similar roles

Senior Application Security Engineer

Cognizant

Philadelphia, PA 9 days ago $90,000$130,000
Black Duck SCA Application Security Product Security DevSecOps CI/CD SBOM OWASP Top 10 Vulnerability Management CVE Analysis Security Automation AWS Azure GCP Mobile Application Security
8+ yrs exp

Senior Security Engineer

Chime

New York, NY +1 101 days ago
Python Go Ruby AWS GCP Terraform infrastructure-as-code API Mobile Security Penetration Testing Threat Modeling SDLC GRC AI Automation
2+ yrs exp Hybrid

Senior Security Engineer

Oracle

Reston, VA +2 51 days ago $82,200$187,000
Encryption Hashing Masking Access Management Security Monitoring Data Security Disaster Recovery
3+ yrs exp

Senior Application Security Engineer

AbbVie

Chicago, IL 41 days ago $109,500$208,500
SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python AWS Azure Terraform CloudFormation OWASP Top 10 CWE CSPM Snyk Endor Labs
7+ yrs exp

Senior Application Security Engineer

AbbVie

Irvine, CA 41 days ago $109,500$208,500
SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python AWS Azure Terraform CloudFormation CSPM Snyk Endor Labs OWASP Top 10 CWE
7+ yrs exp

Senior Application Security Engineer

Upstart

Remote (Canada) 6 days ago $166,900$230,900
Application Security Threat Modeling SAST DAST SCA CI/CD Python Java Go Ruby API Security Microservices GraphQL REST GenAI Secrets Management Cloud-Native AWS CISSP CSSLP CCSP
5+ yrs exp Remote