Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.
Sr. DevOps Engineer, Cloud Operations
Staff. DevOps Engineer will be a key player on the Cloud Operations team responsible for all SaaS and Hosted services across the company's product portfolio. They will proactively work with Engineering, Product, IT, and other functional departments to design, implement, and operate our global customer-facing infrastructure on Google Cloud Platform (GCP). The ideal candidate brings deep hands-on Kubernetes expertise, is a self-starter who thrives in a fast-paced environment, excels at problem solving, and is committed to delivering seamless, highly available service experiences to enterprise customers worldwide.
Key responsibilities:
- Design, build, and maintain resilient, secure, and highly available infrastructure for all SaaS and Hosted services on GCP to meet established SLAs
- Deploy, manage, and scale Kubernetes clusters (GKE) across multiple regions; own cluster lifecycle, upgrades, and capacity planning
- Automate deployment pipelines, monitoring, alerting, and incident response using modern CI/CD and GitOps practices
- Monitor site stability and performance using GCP-native observability tooling (Cloud Monitoring, Cloud Logging, Error Reporting) and troubleshoot issues across the stack
- Scale infrastructure to meet rapidly increasing demand using GCP autoscaling, load balancing, and cost-optimization best practices
- Own end-to-end operational responsibility for all customer-facing SaaS and Hosted environments, including availability, performance, and change management
- Manage cross-functional requirements working with Engineering, Product, Services, and other departments
- Collaborate with developers to bring new features and services into production via containerized, Kubernetes-native deployment patterns
- Develop and improve operational practices, runbooks, and procedures
- Proactively meet standards for information security and compliance, such as ISO, SOX, SSAE 16, etc.
Key requirements:
- Hands-on Google Cloud Platform expertise: GKE, Cloud Run, Cloud Storage, VPC networking, IAM, Cloud Monitoring/Logging
- Deep Kubernetes expertise: deploy and operate production clusters at scale, including control plane management, multi-cluster networking, RBAC, and Helm chart authoring
- Cloud and networking expertise: design and operate cloud network infrastructure (VPC, subnets, firewalls, load balancing, PSC, private connectivity) with strong fundamentals in DNS, TLS, service mesh, and network troubleshooting
- Cloud security controls: encryption (CMEK), secrets management (Vault, Cloud Secret Manager), and audit logging
- CI/CD pipeline experience (GitHub Actions, GitOps/ ArgoCD, or equivalent)
- Scripting proficiency (Python, Bash, or Go); infrastructure-as-code tools (Terraform or equivalent)
- Experience supporting Java/J2EE applications in production (understanding deployments, JVM tuning, debugging)
- Proven ability to establish process, influence cross-functionally, and operate independently
Education:
- Bachelor's degree in Computer Scienceor other technical discipline, or equivalent experience
Black Duck is an equal opportunity employer. We consider all applicants for employment without regard to race, color, national origin, religion, sex, gender identity or expression, age, disability, sexual orientation, veteran or military service status, or any other characteristic protected by applicable law. Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law.
Skills Required
- Hands-on Google Cloud Platform expertise (GKE, Cloud Run, Cloud Storage, VPC, IAM, Cloud Monitoring/Logging, Error Reporting)
- Deep Kubernetes expertise: deploy and operate production clusters, control plane management, multi-cluster networking, RBAC, Helm chart authoring
- Cloud and networking expertise: VPC, subnets, firewalls, load balancing, Private Service Connect, private connectivity, DNS, TLS, service mesh, network troubleshooting
- Cloud security controls: CMEK, secrets management (Vault, Cloud Secret Manager), and audit logging
- CI/CD and GitOps experience (GitHub Actions, ArgoCD or equivalent)
- Scripting proficiency (Python, Bash, or Go)
- Infrastructure-as-code experience (Terraform or equivalent)
- Experience supporting Java/J2EE applications in production (deployments, JVM tuning, debugging)
- Proven ability to establish processes, influence cross-functionally, and operate independently
- Familiarity with observability, monitoring, alerting, incident response, and runbook development
- Bachelor's degree in Computer Science or related technical discipline, or equivalent experience
Black Duck Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Black Duck and has not been reviewed or approved by Black Duck.
-
Healthcare Strength — Medical, dental, and vision coverage provide multiple plan choices with transparent costs, with carrier updates noted for 2026. Vision via VSP and dental plan options offer defined tiers and network access.
-
Retirement Support — Retirement programs include a 401(k) with company matching alongside an employee stock purchase plan with a discount and lookback. These features support longer‑term savings and wealth building.
-
Leave & Time Off Breadth — Exempt employees use a manager‑approved, no‑cap time‑off model, while non‑exempt employees accrue flexible time off alongside sick time. Paid leaves include parental and family care leave, with additional protections under applicable leave laws.
Black Duck Insights
What We Do
Organizations worldwide use Black Duck Software’s industry-leading products to secure and manage open source software, eliminating the pain related to security vulnerabilities, compliance and operational risk. Black Duck is headquartered in Burlington, MA, and has offices in San Jose, London, Frankfurt, Hong Kong, Tokyo, Vancouver, Seoul & Beijing
Why Work With Us
We pride ourselves on cultivating an environment of collaboration, creativity, and fun! We know where you work can influence how you work, which is why our collaborative office space focuses on community and continuous learning. Our work-hard, play-hard attitude even got us named a Top Place to Work in Massachusetts by The Boston Globe!
Gallery






