Black Duck Appoints Dom Glavach as Chief Information Security Officer to Lead Global Security Strategy in the Age of AI
Cyber Security / Foundational Security | 4 min read
Black Duck®, the leader in AI-powered application security, has announced the appointment of Dom Glavach as Chief Information Security Officer (CISO). In this role, Glavach will lead Black Duck's global security strategy, overseeing enterprise security, governance, risk and compliance, and product security as the company continues to expand its portfolio for securing modern and AI-driven software development. The appointment comes at a moment of heightened urgency in software security — marked by a steady drumbeat of software supply chain breaches and open source compromises impacting popular developer tools, cloud platforms, and AI-driven systems. Recent incidents tied to dependency abuse, credential misuse, and compromised build pipelines have underscored how quickly software risk can cascade across industries, making CISO leadership with deep supply chain and national-scale security experience increasingly strategic.
"Dom has operated at the intersection of security, software, and national-scale risk for his entire career. His experience leading security programs in high-stakes environments makes him uniquely qualified to help Black Duck scale securely while advancing how the industry approaches application and supply chain security in the age of AI."
— Jason Schmitt, Chief Executive Officer, Black Duck
"Black Duck sits at the center of how modern software is built and secured. As organisations race to adopt AI and accelerate development, security must evolve just as quickly — without slowing innovation. I'm excited to join Black Duck at a pivotal moment and help customers manage risk with greater clarity, automation, and confidence."
— Dom Glavach, Chief Information Security Officer, Black Duck
Dom Glavach's Career: National Defence, SaaS, and Supply Chain Security
Glavach brings more than 20 years of cybersecurity leadership spanning high-growth SaaS organisations, regulated industries, and national defence environments. Most recently, he served as CISO and Chief Security Strategist at CyberSN, where he led enterprise security strategy and operations across a fully remote workforce — integrating governance, risk, and compliance with security operations, vulnerability management, and secure product development. Prior to CyberSN, Glavach spent two decades at Concurrent Technologies Corporation (CTC), serving as CISO for a top-100 Department of Defense contractor. There he architected and led compliance programmes aligned with FedRAMP, DFARS, NIST 800-171, and CMMC, and directed incident response efforts against advanced, nation-state adversaries — work that supported tens of millions of dollars in secured government contracts. Beyond his practitioner credentials, Glavach authored the CyberSN Job Taxonomy, teaches as an Adjunct Professor of Cybersecurity at Indiana University of Pennsylvania, and speaks regularly on AI-enabled defence, cyber workforce risk, and modern CISO leadership.
What Glavach Will Focus on at Black Duck
At Black Duck, Glavach will focus on strengthening the company's security posture as customers navigate increasingly complex risks tied to open source software, software supply chains, and AI-generated code. He will partner closely with engineering, product, and customer-facing teams to ensure security is embedded not only across Black Duck's internal operations but also within the platforms and intelligence delivered to customers. Black Duck's mission is to meet the board-level risks of modern software with what it calls True Scale Application Security — ensuring uncompromised trust in software for the regulated, AI-powered world. The appointment signals that application security, open source risk, and AI-generated code are now being treated as board-level concerns that require dedicated, senior CISO leadership with both technical depth and national-scale risk experience — not simply back-office technical functions.
Key Takeaways
- • Black Duck (leader in AI-powered application security; Burlington, MA) has appointed Dom Glavach as Chief Information Security Officer — leading global security strategy covering enterprise security, governance, risk and compliance, and product security as the company expands its portfolio for securing modern and AI-driven software development.
- • The threat landscape context: software supply chain breaches and open source compromises are hitting developer tools, cloud platforms, and AI-driven systems at increasing frequency and scale. Dependency abuse, credential misuse, and compromised build pipelines are demonstrating how quickly software risk cascades across industries — elevating application and supply chain security from a technical function to a board-level concern.
- • Dom Glavach's career profile: 20+ years of cybersecurity leadership across SaaS, regulated industries, and national defence. Most recently: CISO and Chief Security Strategist at CyberSN (enterprise security, GRC, vulnerability management, secure product development across a fully remote workforce). Prior: two decades at Concurrent Technologies Corporation (CTC) as CISO for a top-100 DoD contractor — compliance programmes in FedRAMP, DFARS, NIST 800-171, and CMMC; incident response against advanced nation-state adversaries; tens of millions in secured government contracts.
- • Glavach's focus at Black Duck: strengthening security posture for customers navigating open source software risk, software supply chain complexity, and AI-generated code; embedding security across Black Duck's internal operations and the platforms and intelligence delivered to customers; partnering with engineering, product, and customer-facing teams. Thought leader context: authored the CyberSN Job Taxonomy; Adjunct Professor of Cybersecurity at Indiana University of Pennsylvania; speaker on AI-enabled defence and CISO leadership.
- • Black Duck's mission — True Scale Application Security — positions the company at the centre of how modern software is built and secured, freeing organisations from tradeoffs between speed, accuracy, and compliance at scale while eliminating security, regulatory, and licensing risks across cloud and on-premises environments. Glavach's appointment is a signal that AI-generated code risk and software supply chain security are now requiring CISO-level leadership with national-scale defence credentials.
