1

Checkmarx Jobs in California (NOW HIRING)

Experience using vulnerability assessment tools/platforms such as IBM Appscan Enterprise, Coverity, CheckMarx, Nessus, Qualys, GFI, HP Fortify, Veracode, Burp Suite, MS Threat Modeler, Codenomicon ...

... Checkmarx Continuous Integration - Jenkins, Cruise Control, Bamboo, Teamcity Continuous Deployment - uDeploy, Liquibase, Chef, Puppet, Automic ARA Release automation - xlRelease, uRelease, CA Release ...

Checkmarx, Veracode, DAST: Burp Suite, SCA: Snyk, Black Duck, CI/CD: Jenkins, GitHub Actions • Familiarity with Kubernetes, Docker, and service mesh security • Certifications: CISSP, CSSLP, CISM ...

Since inception of the firm, K1 has partnered with over 123 enterprise software companies including industry leaders such as Apttus, Buildium, Checkmarx, ChiroTouch, Clarizen, ControlUp, Emburse ...

Showing results 21-40

Checkmarx information

See California salary details

$17

$50

$82

How much do checkmarx jobs pay per hour?

As of Aug 23, 2026, the average hourly pay for checkmarx in California is $50.42, according to ZipRecruiter salary data. Most workers in this role earn between $43.17 and $60.48 per hour, depending on experience, location, and employer.

What is Checkmarx?

Checkmarx is a software security platform that specializes in application security testing. It helps developers and security teams identify vulnerabilities in their code through automated static and interactive application security testing (SAST and IAST). Checkmarx integrates with development pipelines to scan source code, open-source libraries, and APIs, enabling teams to find and fix security issues early in the software development lifecycle. The platform supports a wide range of programming languages and frameworks, making it a popular choice for organizations focused on secure software development.

What are the key skills and qualifications needed to thrive as a Checkmarx application security engineer?

To thrive as a Checkmarx Application Security Engineer, you need a solid understanding of secure software development, vulnerability assessment, and application security principles, often supported by a degree in computer science or related field. Experience with the Checkmarx SAST platform, knowledge of CI/CD pipelines, and relevant certifications such as CISSP or CEH are typically required. Strong analytical thinking, communication skills, and the ability to work collaboratively with development teams make someone stand out in this position. These skills are vital for effectively identifying and mitigating security risks in the software development lifecycle, ensuring robust protection of organizational assets.

What are some common challenges faced by professionals working with Checkmarx in an application security role?

Professionals working with Checkmarx often encounter challenges such as integrating the tool into existing CI/CD pipelines, managing false positives in scan results, and maintaining clear communication between security and development teams. Staying up-to-date with evolving vulnerabilities and ensuring that all codebases are consistently scanned can also be demanding. However, these challenges are typically addressed through strong collaboration, continuous learning, and leveraging Checkmarx's robust reporting and integration features.

What is the difference between Checkmarx vs SAST Developer?

AspectCheckmarxSAST Developer
CredentialsSecurity certifications, coding knowledgeSecurity certifications, coding knowledge
Work EnvironmentSecurity teams, development teamsDevelopment teams, security teams
Industry UsageApplication security testing toolsDeveloping and integrating SAST tools
Search IntentCompare security tools and rolesRoles involving static application security testing

Checkmarx professionals focus on using security testing tools like Checkmarx to identify vulnerabilities, while SAST Developers develop and maintain static application security testing (SAST) tools and integrations. Both roles require security and coding expertise but differ in their primary focus—one on utilizing security solutions, the other on creating them.

What cities in California are hiring for Checkmarx jobs?

Cities in California with the most Checkmarx job openings:

Infographic showing various Checkmarx job openings in California as of August 2026, with employment types broken down into 91% Full Time, and 9% Contract. Highlights an 57% Physical, 15% Hybrid, and 28% Remote job distribution, with an average salary of $104,866 per year, or $50.4 per hour.

Contractor

Re-posted 11 days ago


Job description

Job Description

Responsibilities

Conduct black box ,white box security and penetration testing to assess and validate application security

Perform manual pen-tests, ability to setup threat models and fuzzers. Be able to work in an ethical lab for hackers

Participate in architecture and design reviews with developers (all levels)/DevOps staff

Design, implement and support security tools and services

Influence and measure security policies and share best practices and recommendations 

Being able to track and monitor and use vulnerability tracking methods and tools

Explain and demonstrate vulnerabilities to application/system owners, and provide recommendations for mitigation

Issue reports on assigned application and system scans

Perform Secure Code Development Training to developers and relevant staffs

Support security policies and procedures

Participate in security compliance efforts

Participate in security operations support

Evaluate new and emerging security products and technologies


Required Skills and Experience 

5+ years of experience in web or mobile application security

5+ years of application development

Passion for security, and a deep technical understanding of enterprise systems architecture

Expert knowledge of information security principles, ethical hacking standards, along with a thorough knowledge of the current threat landscape and recent hacks and malware

Knowledge of cloud-based infrastructures/software and how they affect security needs

Familiarity and hands-on knowledge of with multiple languages and platforms (Java, Python, C/C++, Ruby, Perl and frameworks like Node.js, DoJo, and Angular.js ).

Experience with HTML and Javascript along with a solid understanding of HTTP protocol

Working Knowledge of SQL, Oracle, Mongo DB and PostgreSQL 

Coding knowledge in one or more front end and web technologies like Java & Ruby, Python, Perl; mobile code development is a plus

In-depth knowledge and experience in OWASP 2013, SANS 25 and CWE

In-depth Experience in providing vulnerability remediation, with code examples, both web and mobile applications

Experience in working on AGILE projects and Waterfall Projects, along with fundamental project management and time management skills

Experience in the all parts of the SDLC, such as coding, integration testing, security analysis and audits, code reviews, designing etc.

Experience using vulnerability assessment tools/platforms such as IBM Appscan Enterprise, Coverity, CheckMarx, Nessus, Qualys, GFI, HP Fortify, Veracode, Burp Suite, MS Threat Modeler, Codenomicon etc.

Hands-on knowledge of cryptographic and encryption, PCI knowledge is a plus

Understanding of malware by device type

Expert problem solving and analytical skills; Advanced communication skills both spoken and written, to all levels of management

Self-driven and the ability to work with minimal supervision is required


Qualifications

Bachelor's degree in an Information Technology/Computer Science/Computer Engineering

Additional Information

This is IMMEDIATE requirement