About the Role
About the Role
As a C++/Rust Software Engineer at Black Duck, you will enhance the static analysis engine to improve vulnerability coverage and performance in cloud-native environments. This role involves integrating static analysis into AI-driven workflows and collaborating with various teams to advance application security technology.
What You'll Do
- Design and develop scalable static analysis solutions for large-scale cloud environments.
- Enhance and maintain core analysis infrastructure to improve performance, reliability, and scalability.
- Develop new analysis algorithms, techniques, and security detection capabilities to expand vulnerability coverage and accuracy.
- Research emerging software security vulnerabilities and create, test, and optimize detection rules in Rust.
- Integrate static analysis into AI-assisted development workflows, enabling automated security insights, triage, and remediation.
- Collaborate with security researchers, language experts, and product teams to advance state-of-the-art application security technology.
Who You Are
- 5+ years of professional software development experience in C/C++ and/or Rust.
- MS or PhD in Computer Science, Software Engineering, Programming Languages, Static Analysis, Compilers, or a related field; equivalent industry experience considered.
- Strong experience developing on Linux/UNIX platforms.
- Deep understanding of programming language theory, compiler design, parsers, abstract syntax trees (ASTs), and language analysis frameworks.
- Experience with static analysis, dataflow analysis, control-flow analysis, taint analysis, symbolic execution, or related program analysis techniques.
- Experience designing scalable, high-performance systems and cloud-native services.
- Knowledge of AI-assisted software development workflows and an interest in applying static analysis to AI-powered code generation, review, and remediation workflows.
- Strong problem-solving, debugging, and analytical skills with the ability to work on complex technical challenges.
- Excellent written and verbal communication skills and a collaborative mindset.
Bonus Points
- Experience building commercial or open-source static application security testing (SAST) products.
- Contributions to programming language, compiler, developer tooling, or security-related open-source projects.
- Familiarity with common software security weaknesses (e.g., CWE, OWASP Top 10, secure coding practices).
- Experience researching software vulnerabilities and developing techniques to detect security defects.
- Experience developing analysis rules, checkers, or vulnerability detection engines.
- Familiarity with modern languages such as Java, C#, JavaScript/TypeScript, Python, Go, Kotlin, or others.
Compensation
Pay Range: $110,600 CAD - $145,000 CAD
Requirements
C/C++ and Rust experience
5+ years of professional software development experience in C/C++ and/or Rust.
Linux/UNIX development
Strong experience developing on Linux/UNIX platforms.
Programming language theory
Deep understanding of programming language theory, compiler design, and language analysis frameworks.
Static analysis techniques
Experience with static analysis, dataflow analysis, and related program analysis techniques.
Scalable systems design
Experience designing scalable, high-performance systems and cloud-native services.
Nice to Have
Experience building commercial or open-source static application security testing (SAST) products.
Contributions to programming language, compiler, or security-related open-source projects.
Familiarity with common software security weaknesses and secure coding practices.
Experience researching software vulnerabilities and developing detection techniques.
Benefits
Equal opportunity employer
Black Duck is an equal opportunity employer.