Overview
We are seeking a Senior Product Security Engineer to strengthen our product security posture across the software development lifecycle. This role requires deep hands-on expertise with Black Duck (software composition analysis) and API-based integrations, along with strong working knowledge of one or more core security domains: memory leak/soak testing, mobile security, security patch management in R&D environments, and cryptographic agility. The ideal candidate combines technical depth with the ability to embed security practices directly into engineering workflows.
- Location: Lake Forest, CA (Hybrid)/ Philadelphia,
- Employment Type: Full-time W-2
- Compensation: Competitive, based on experience
Company Description
WITS (Wistron ITS) is a global IT services provider with 32+ years of experience and offices across the U.S. and Asia-Pacific. We partner with Fortune Global 500 companies to deliver scalable, high-quality software solutions across cloud, enterprise, and emerging technologies. At WITS, we focus on long-term projects, strong engineering culture, and real business impact.
Key Responsibilities
- Own and drive Black Duck implementation, configuration, and ongoing management across development pipelines
- Build and maintain API-based integrations between Black Duck and CI/CD, ticketing, and reporting systems Triage, prioritize, and remediate open-source vulnerability and license risk findings surfaced through SCA scans
- Partner with R&D and engineering teams to embed security testing (memory leak/soak testing, patching cadence, etc.) into development and release cycles
- Support cryptographic agility initiatives — assessing current cryptographic implementations and planning for algorithm/protocol transitions (e.g., post-quantum readiness, deprecating weak ciphers)
- Define and improve security patch management processes across product lines, balancing velocity with risk exposure
- Stay current on emerging vulnerabilities, CVEs, and industry security standards relevant to the product portfolio
Required Qualifications
- 7+ years in product/application security, security engineering, or related technical security role Strong, demonstrable experience with Black Duck (or comparable SCA tools) including API-level interaction and automation
- Proficiency in at least one scripting/programming language (Python, Java, or similar) for API integration and tooling Working knowledge of one or more of the following: ◦ Memory leak / soak testing methodologies and tools ◦ Security patch management approaches in R&D/product development environments ◦ Cryptographic agility concepts and implementation strategies Solid understanding of the software development lifecycle (SDLC) and how security integrates into CI/CD pipelines Strong communication skills — able to translate technical security findings for both engineering and non technical stakeholders
Pay: $100,000.00 - $140,000.00 per year
Benefits:
- Health insurance
- Paid time off
Application Question(s):
- Do you have a Bachelor's degree or higher in Computer Science or Engineering?
Experience:
- C/C++: 5 years (Required)
- C#/.NET: 5 years (Required)
Ability to Commute:
- Lake Forest, CA 92630 (Required)
Work Location: Hybrid remote in Lake Forest, CA 92630