C++/Rust Software Engineer (Senior)
Join Black Duck's Static Analysis team and help advance industry-leading application security technology. In this role, you will enhance our static analysis engine by expanding vulnerability coverage, deepening analysis capabilities, and improving scalability and performance in cloud-native environments. You will also help integrate static analysis into AI-driven development workflows, enabling intelligent security automation and AI-assisted vulnerability detection and remediation.
The ideal candidate is passionate about software security and quality, has experience in static analysis, compilers, or programming language technologies, and enjoys solving complex engineering problems at scale.
Responsibilities
• Design and develop scalable static analysis solutions for large-scale cloud environments.
• Enhance and maintain core analysis infrastructure to improve performance, reliability, and scalability.
• Develop new analysis algorithms, techniques, and security detection capabilities to expand vulnerability coverage and accuracy.
• Research emerging software security vulnerabilities and create, test, and optimize detection rules in Rust.
• Integrate static analysis into AI-assisted development workflows, enabling automated security insights, triage, and remediation.
• Collaborate with security researchers, language experts, and product teams to advance state-of-the-art application security technology.
Key Qualifications
• 5+ years of professional software development experience in C/C++ and/or Rust
• MS or PhD in Computer Science, Software Engineering, Programming Languages, Static Analysis, Compilers, or a related field; equivalent industry experience considered
• Strong experience developing on Linux/UNIX platforms
• Deep understanding of programming language theory, compiler design, parsers, abstract syntax trees (ASTs), and language analysis frameworks
• Experience with static analysis, dataflow analysis, control-flow analysis, taint analysis, symbolic execution, or related program analysis techniques
• Experience designing scalable, high-performance systems and cloud-native services
• Knowledge of AI-assisted software development workflows and an interest in applying static analysis to AI-powered code generation, review, and remediation workflows
• Strong problem-solving, debugging, and analytical skills with the ability to work on complex technical challenges
• Excellent written and verbal communication skills and a collaborative mindset
Preferred Qualifications
• Experience building commercial or open-source static application security testing (SAST) products
• Contributions to programming language, compiler, developer tooling, or security-related open-source projects
• Familiarity with common software security weaknesses (e.g., CWE, OWASP Top 10, secure coding practices)
• Experience researching software vulnerabilities and developing techniques to detect security defects
• Experience developing analysis rules, checkers, or vulnerability detection engines
• Familiarity with modern languages such as Java, C#, JavaScript/TypeScript, Python, Go, Kotlin, or others