PEN TESTER
San Jose, CA · On-site
Experience using vulnerability assessment tools/platforms such as IBM Appscan Enterprise, Coverity, CheckMarx, Nessus, Qualys, GFI, HP Fortify, Veracode, Burp Suite, MS Threat Modeler, Codenomicon ...
San Jose, CA · On-site
Experience using vulnerability assessment tools/platforms such as IBM Appscan Enterprise, Coverity, CheckMarx, Nessus, Qualys, GFI, HP Fortify, Veracode, Burp Suite, MS Threat Modeler, Codenomicon ...
San Jose, CA · On-site
Experience using vulnerability assessment tools/platforms such as IBM Appscan Enterprise, Coverity, CheckMarx, Nessus, Qualys, GFI, HP Fortify, Veracode, Burp Suite, MS Threat Modeler, Codenomicon ...
San Francisco, CA · On-site
$69.25 - $92.50/hr
Grype, Syft, Checkmarx, Cycode, Wiz Environment: Public Cloud (Azure/AWS/GCP), On-Prem K8s distributions (OpenShift, Tanzu) What You'll Bring * Developer DNA: You are a competent developer in Go ...
San Francisco, CA · On-site
$69.25 - $92.50/hr
Grype, Syft, Checkmarx, Cycode, Wiz Environment: Public Cloud (Azure/AWS/GCP), On-Prem K8s distributions (OpenShift, Tanzu) What You'll Bring * Developer DNA: You are a competent developer in Go ...
... Checkmarx Continuous Integration - Jenkins, Cruise Control, Bamboo, Teamcity Continuous Deployment - uDeploy, Liquibase, Chef, Puppet, Automic ARA Release automation - xlRelease, uRelease, CA Release ...
... Checkmarx Continuous Integration - Jenkins, Cruise Control, Bamboo, Teamcity Continuous Deployment - uDeploy, Liquibase, Chef, Puppet, Automic ARA Release automation - xlRelease, uRelease, CA Release ...
Experience selling SCA or AppSec platforms (e.g., Black Duckstyle solutions, Snyk, Veracode, Checkmarx, GitHub Advanced Security). * Familiarity with CI/CD ecosystems (GitHub, GitLab, Jenkins, Azure ...
Experience selling SCA or AppSec platforms (e.g., Black Duckstyle solutions, Snyk, Veracode, Checkmarx, GitHub Advanced Security). * Familiarity with CI/CD ecosystems (GitHub, GitLab, Jenkins, Azure ...
Checkmarx, Veracode, DAST: Burp Suite, SCA: Snyk, Black Duck, CI/CD: Jenkins, GitHub Actions • Familiarity with Kubernetes, Docker, and service mesh security • Certifications: CISSP, CSSLP, CISM ...
Checkmarx, Veracode, DAST: Burp Suite, SCA: Snyk, Black Duck, CI/CD: Jenkins, GitHub Actions • Familiarity with Kubernetes, Docker, and service mesh security • Certifications: CISSP, CSSLP, CISM ...
Costa Mesa, CA · On-site
$131K - $173K/yr
Hands-on experience with security scanning tools (e.g., Snyk, Checkmarx, SonarQube, Nessus) and the vulnerability management lifecycle
Costa Mesa, CA · On-site
$131K - $173K/yr
Hands-on experience with security scanning tools (e.g., Snyk, Checkmarx, SonarQube, Nessus) and the vulnerability management lifecycle
Seaside, CA · On-site
$62.75 - $84/hr
Experience with GitLab, Jenkins, Azure DevOps, GitHub, SonarQube, Checkmarx, Fortify, Veracode, or similar security tools * Experience supporting container security, Kubernetes, Docker, or ...
Seaside, CA · On-site
$62.75 - $84/hr
Experience with GitLab, Jenkins, Azure DevOps, GitHub, SonarQube, Checkmarx, Fortify, Veracode, or similar security tools * Experience supporting container security, Kubernetes, Docker, or ...
Manhattan Beach, CA · On-site
Since inception of the firm, K1 has partnered with over 123 enterprise software companies including industry leaders such as Apttus, Buildium, Checkmarx, ChiroTouch, Clarizen, ControlUp, Emburse ...
Manhattan Beach, CA · On-site
Since inception of the firm, K1 has partnered with over 123 enterprise software companies including industry leaders such as Apttus, Buildium, Checkmarx, ChiroTouch, Clarizen, ControlUp, Emburse ...
San Jose, CA · On-site
$164K - $305K/yr
Hands‑on experience with tools such as SAST (Checkmarx, Veracode), DAST (Burp Suite), SCA (Snyk, Black Duck), CI/CD (Jenkins, GitHub Actions) * Familiarity with Kubernetes, Docker, and service mesh ...
San Jose, CA · On-site
$164K - $305K/yr
Hands‑on experience with tools such as SAST (Checkmarx, Veracode), DAST (Burp Suite), SCA (Snyk, Black Duck), CI/CD (Jenkins, GitHub Actions) * Familiarity with Kubernetes, Docker, and service mesh ...
San Jose, CA · On-site
$164K - $305K/yr
Checkmarx, Veracode * DAST: Burp Suite * SCA: Snyk, Black Duck * CI/CD: Jenkins, GitHub Actions * Familiarity with Kubernetes, Docker, and service mesh security * Certifications: * CISSP, CSSLP
San Jose, CA · On-site
$164K - $305K/yr
Checkmarx, Veracode * DAST: Burp Suite * SCA: Snyk, Black Duck * CI/CD: Jenkins, GitHub Actions * Familiarity with Kubernetes, Docker, and service mesh security * Certifications: * CISSP, CSSLP
$164K - $305K/yr
Checkmarx, Veracode * DAST: Burp Suite * SCA: Snyk, Black Duck * CI/CD: Jenkins, GitHub Actions * Familiarity with Kubernetes, Docker, and service mesh security * Certifications: * CISSP, CSSLP
$164K - $305K/yr
Checkmarx, Veracode * DAST: Burp Suite * SCA: Snyk, Black Duck * CI/CD: Jenkins, GitHub Actions * Familiarity with Kubernetes, Docker, and service mesh security * Certifications: * CISSP, CSSLP
San Jose, CA · On-site
$164.50 - $305.50/hr
Hands‑on experience with tools such as SAST (Checkmarx, Veracode), DAST (Burp Suite), SCA (Snyk, Black Duck), CI/CD (Jenkins, GitHub Actions) * Familiarity with Kubernetes, Docker, and service mesh ...
San Jose, CA · On-site
$164.50 - $305.50/hr
Hands‑on experience with tools such as SAST (Checkmarx, Veracode), DAST (Burp Suite), SCA (Snyk, Black Duck), CI/CD (Jenkins, GitHub Actions) * Familiarity with Kubernetes, Docker, and service mesh ...
San Jose, CA · On-site
$164K - $305K/yr
Checkmarx, Veracode * DAST: Burp Suite * SCA: Snyk, Black Duck * CI/CD: Jenkins, GitHub Actions * Familiarity with Kubernetes, Docker, and service mesh security * Certifications: * CISSP, CSSLP
San Jose, CA · On-site
$164K - $305K/yr
Checkmarx, Veracode * DAST: Burp Suite * SCA: Snyk, Black Duck * CI/CD: Jenkins, GitHub Actions * Familiarity with Kubernetes, Docker, and service mesh security * Certifications: * CISSP, CSSLP
Sonarqube, Checkmarx, Coverity, Fortify * DAST: OWASP ZAP, Burp Suite, Acunetix * Dependency/SCA: Snyk, Black Duck, WhiteSource, Dependabot * Container Security: Trivy, Twistlock, Aqua Security
Sonarqube, Checkmarx, Coverity, Fortify * DAST: OWASP ZAP, Burp Suite, Acunetix * Dependency/SCA: Snyk, Black Duck, WhiteSource, Dependabot * Container Security: Trivy, Twistlock, Aqua Security
San Jose, CA · Hybrid
$170K - $210K/yr
Sonarqube, Checkmarx, Coverity, Fortify * DAST: OWASP ZAP, Burp Suite, Acunetix * Dependency/SCA: Snyk, Black Duck, WhiteSource, Dependabot * Container Security: Trivy, Twistlock, Aqua Security
Quick apply
San Jose, CA · Hybrid
$170K - $210K/yr
Sonarqube, Checkmarx, Coverity, Fortify * DAST: OWASP ZAP, Burp Suite, Acunetix * Dependency/SCA: Snyk, Black Duck, WhiteSource, Dependabot * Container Security: Trivy, Twistlock, Aqua Security
Foster City, CA · On-site
$210K - $270K/yr
Hands-on experience operating SAST, SCA, and Secret Scanning tools (such as Snyk, Socket, Wiz Code, Semgrep, or Checkmarx). * Compliance Awareness: Understanding of how vulnerability management maps ...
Foster City, CA · On-site
$210K - $270K/yr
Hands-on experience operating SAST, SCA, and Secret Scanning tools (such as Snyk, Socket, Wiz Code, Semgrep, or Checkmarx). * Compliance Awareness: Understanding of how vulnerability management maps ...
San Diego, CA · On-site
$95.72 - $169.90/hr
Experience with GIT (source‑code management), Maven (build automation), Jenkins, Artifactory, SonarQube, CheckMarx. * Experience with Eclipse, NetBeans, or IntelliJ IDE. * Working experience with ...
San Diego, CA · On-site
$95.72 - $169.90/hr
Experience with GIT (source‑code management), Maven (build automation), Jenkins, Artifactory, SonarQube, CheckMarx. * Experience with Eclipse, NetBeans, or IntelliJ IDE. * Working experience with ...
Sonarqube, Checkmarx, Coverity, Fortify * DAST: OWASP ZAP, Burp Suite, Acunetix * Dependency/SCA: Snyk, Black Duck, WhiteSource, Dependabot * Container Security: Trivy, Twistlock, Aqua Security
Sonarqube, Checkmarx, Coverity, Fortify * DAST: OWASP ZAP, Burp Suite, Acunetix * Dependency/SCA: Snyk, Black Duck, WhiteSource, Dependabot * Container Security: Trivy, Twistlock, Aqua Security
Experience selling SCA or AppSec platforms (e.g., Black Duck-style solutions, Snyk, Veracode, Checkmarx, GitHub Advanced Security). * Familiarity with CI/CD ecosystems (GitHub, GitLab, Jenkins, Azure ...
Experience selling SCA or AppSec platforms (e.g., Black Duck-style solutions, Snyk, Veracode, Checkmarx, GitHub Advanced Security). * Familiarity with CI/CD ecosystems (GitHub, GitLab, Jenkins, Azure ...
San Ramon, CA · On-site
$77 - $95.50/hr
Build and enforce automated linting, testing, and security review gates (e.g., Checkmarx, security packages) that uphold engineering quality without slowing down delivery. * Define the frameworks and ...
San Ramon, CA · On-site
$77 - $95.50/hr
Build and enforce automated linting, testing, and security review gates (e.g., Checkmarx, security packages) that uphold engineering quality without slowing down delivery. * Define the frameworks and ...
$17.08 - $23.03
8% of jobs
$23.03 - $28.99
7% of jobs
$28.99 - $34.94
8% of jobs
$34.94 - $40.89
0% of jobs
$41.34 is the 25th percentile. Wages below this are outliers.
$40.89 - $46.84
11% of jobs
The median wage is $50.77 / hr.
$46.84 - $52.80
23% of jobs
$57.89 is the 75th percentile. Wages above this are outliers.
$52.80 - $58.75
20% of jobs
$58.75 - $64.70
5% of jobs
$64.70 - $70.65
12% of jobs
$70.65 - $76.61
2% of jobs
$76.61 - $82.56
3% of jobs
$17
$50
$82
| Aspect | Checkmarx | SAST Developer |
|---|---|---|
| Credentials | Security certifications, coding knowledge | Security certifications, coding knowledge |
| Work Environment | Security teams, development teams | Development teams, security teams |
| Industry Usage | Application security testing tools | Developing and integrating SAST tools |
| Search Intent | Compare security tools and roles | Roles involving static application security testing |
Checkmarx professionals focus on using security testing tools like Checkmarx to identify vulnerabilities, while SAST Developers develop and maintain static application security testing (SAST) tools and integrations. Both roles require security and coding expertise but differ in their primary focus—one on utilizing security solutions, the other on creating them.
For Checkmarx jobs in California, the most frequently searched job titles are:
The top searched job categories for Checkmarx jobs in California are:
Cities in California with the most Checkmarx job openings:

Contractor
Re-posted 11 days ago
Responsibilities
Conduct black box ,white box security and penetration testing to assess and validate application security
Perform manual pen-tests, ability to setup threat models and fuzzers. Be able to work in an ethical lab for hackers
Participate in architecture and design reviews with developers (all levels)/DevOps staff
Design, implement and support security tools and services
Influence and measure security policies and share best practices and recommendations
Being able to track and monitor and use vulnerability tracking methods and tools
Explain and demonstrate vulnerabilities to application/system owners, and provide recommendations for mitigation
Issue reports on assigned application and system scans
Perform Secure Code Development Training to developers and relevant staffs
Support security policies and procedures
Participate in security compliance efforts
Participate in security operations support
Evaluate new and emerging security products and technologies
Required Skills and Experience
5+ years of experience in web or mobile application security
5+ years of application development
Passion for security, and a deep technical understanding of enterprise systems architecture
Expert knowledge of information security principles, ethical hacking standards, along with a thorough knowledge of the current threat landscape and recent hacks and malware
Knowledge of cloud-based infrastructures/software and how they affect security needs
Familiarity and hands-on knowledge of with multiple languages and platforms (Java, Python, C/C++, Ruby, Perl and frameworks like Node.js, DoJo, and Angular.js ).
Experience with HTML and Javascript along with a solid understanding of HTTP protocol
Working Knowledge of SQL, Oracle, Mongo DB and PostgreSQL
Coding knowledge in one or more front end and web technologies like Java & Ruby, Python, Perl; mobile code development is a plus
In-depth knowledge and experience in OWASP 2013, SANS 25 and CWE
In-depth Experience in providing vulnerability remediation, with code examples, both web and mobile applications
Experience in working on AGILE projects and Waterfall Projects, along with fundamental project management and time management skills
Experience in the all parts of the SDLC, such as coding, integration testing, security analysis and audits, code reviews, designing etc.
Experience using vulnerability assessment tools/platforms such as IBM Appscan Enterprise, Coverity, CheckMarx, Nessus, Qualys, GFI, HP Fortify, Veracode, Burp Suite, MS Threat Modeler, Codenomicon etc.
Hands-on knowledge of cryptographic and encryption, PCI knowledge is a plus
Understanding of malware by device type
Expert problem solving and analytical skills; Advanced communication skills both spoken and written, to all levels of management
Self-driven and the ability to work with minimal supervision is required
Bachelor's degree in an Information Technology/Computer Science/Computer Engineering
This is IMMEDIATE requirement