1

Checkmarx Jobs (NOW HIRING)

Establish and govern security architecture standards across the software development lifecycle, including static code analysis (Sonar), SAST (Checkmarx), SCA (Black Duck), secret scanning (GitHub ...

Java Full Stack Developer

Chandler, AZ · On-site

$51.75 - $66.75/hr

J2EE, Java, SQL, Oracle, JavaScript, React, Bootstrap, J Unit, Spring based application, JSP code, controllers, Unit Testing, checkmarx/sonarqube, microservices, springboot

Lead DevOps Engineer

Chicago, IL · On-site

$54.25 - $74.50/hr

Integrate "shift-left" security tools (Checkmarx, SonarQube, Prisma Cloud) * Align DevOps processes with Agile delivery and support ADO configurations * Provide technical leadership, mentoring, and ...

Help operationalize Wiz, Checkmarx, JFrog/Xray, AppScan, Prisma Cloud, GCP Model Armor, and related security capabilities. * Support Azure/GCP/AWS cloud security controls, policy development ...

Help operationalize Wiz, Checkmarx, JFrog/Xray, AppScan, Prisma Cloud, GCP Model Armor, and related security capabilities. * Support Azure/GCP/AWS cloud security controls, policy development ...

Help operationalize Wiz, Checkmarx, JFrog/Xray, AppScan, Prisma Cloud, GCP Model Armor, and related security capabilities. * Support Azure/GCP/AWS cloud security controls, policy development ...

Help operationalize Wiz, Checkmarx, JFrog/Xray, AppScan, Prisma Cloud, GCP Model Armor, and related security capabilities. * Support Azure/GCP/AWS cloud security controls, policy development ...

Help operationalize Wiz, Checkmarx, JFrog/Xray, AppScan, Prisma Cloud, GCP Model Armor, and related security capabilities. * Support Azure/GCP/AWS cloud security controls, policy development ...

Help operationalize Wiz, Checkmarx, JFrog/Xray, AppScan, Prisma Cloud, GCP Model Armor, and related security capabilities. * Support Azure/GCP/AWS cloud security controls, policy development ...

Help operationalize Wiz, Checkmarx, JFrog/Xray, AppScan, Prisma Cloud, GCP Model Armor, and related security capabilities. * Support Azure/GCP/AWS cloud security controls, policy development ...

Help operationalize Wiz, Checkmarx, JFrog/Xray, AppScan, Prisma Cloud, GCP Model Armor, and related security capabilities. * Support Azure/GCP/AWS cloud security controls, policy development ...

Help operationalize Wiz, Checkmarx, JFrog/Xray, AppScan, Prisma Cloud, GCP Model Armor, and related security capabilities. * Support Azure/GCP/AWS cloud security controls, policy development ...

Showing results 21-40

Checkmarx information

See salary details

$17

$51

$83

How much do checkmarx jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for checkmarx in the United States is $51.09, according to ZipRecruiter salary data. Most workers in this role earn between $43.75 and $61.30 per hour, depending on experience, location, and employer.

What is Checkmarx?

Checkmarx is a software security platform that specializes in application security testing. It helps developers and security teams identify vulnerabilities in their code through automated static and interactive application security testing (SAST and IAST). Checkmarx integrates with development pipelines to scan source code, open-source libraries, and APIs, enabling teams to find and fix security issues early in the software development lifecycle. The platform supports a wide range of programming languages and frameworks, making it a popular choice for organizations focused on secure software development.

What are the key skills and qualifications needed to thrive as a Checkmarx application security engineer?

To thrive as a Checkmarx Application Security Engineer, you need a solid understanding of secure software development, vulnerability assessment, and application security principles, often supported by a degree in computer science or related field. Experience with the Checkmarx SAST platform, knowledge of CI/CD pipelines, and relevant certifications such as CISSP or CEH are typically required. Strong analytical thinking, communication skills, and the ability to work collaboratively with development teams make someone stand out in this position. These skills are vital for effectively identifying and mitigating security risks in the software development lifecycle, ensuring robust protection of organizational assets.

What are some common challenges faced by professionals working with Checkmarx in an application security role?

Professionals working with Checkmarx often encounter challenges such as integrating the tool into existing CI/CD pipelines, managing false positives in scan results, and maintaining clear communication between security and development teams. Staying up-to-date with evolving vulnerabilities and ensuring that all codebases are consistently scanned can also be demanding. However, these challenges are typically addressed through strong collaboration, continuous learning, and leveraging Checkmarx's robust reporting and integration features.

What is the difference between Checkmarx vs SAST Developer?

AspectCheckmarxSAST Developer
CredentialsSecurity certifications, coding knowledgeSecurity certifications, coding knowledge
Work EnvironmentSecurity teams, development teamsDevelopment teams, security teams
Industry UsageApplication security testing toolsDeveloping and integrating SAST tools
Search IntentCompare security tools and rolesRoles involving static application security testing

Checkmarx professionals focus on using security testing tools like Checkmarx to identify vulnerabilities, while SAST Developers develop and maintain static application security testing (SAST) tools and integrations. Both roles require security and coding expertise but differ in their primary focus—one on utilizing security solutions, the other on creating them.

What cities are hiring for Checkmarx jobs?

Cities with the most Checkmarx job openings:

What states have the most Checkmarx jobs?

States with the most job openings for Checkmarx jobs include:

Infographic showing various Checkmarx job openings in the United States as of August 2026, with employment types broken down into 89% Full Time, and 11% Contract. Highlights an 57% Physical, 15% Hybrid, and 28% Remote job distribution, with an average salary of $106,258 per year, or $51.1 per hour.

Principal Architect

1 point system

Irving, TX • On-site

Contractor

Re-posted 18 days ago


Job description

  • risk.

Key Responsibilities:
Enterprise Architecture Vision and Strategy:

  • Define and own the technical vision, architecture roadmap, and technology strategy for the Cross Platform Engineering and Reference Architecture team operating under the Chief Data Office
  • Lead the design, governance, and evolution of reference architectures for web services, APIs, data pipelines, CMS platforms, and enterprise integration patterns
  • Establish and chair architecture review boards; evaluate designs for alignment with enterprise standards, scalability, and security posture
  • Create comprehensive architectural decision records (ADRs), technology radar publications, and multi-year technology roadmaps
  • Drive architectural consistency and coherence across multiple product teams and technology domains
  • Mentor and guide Principal Engineers, Lead Engineers, and Senior Engineers in applying architectural patterns and making sound technical trade-offs

DevSecOps Architecture and Governance:

  • Define the target-state architecture for enterprise-grade CI/CD pipelines with integrated security controls and compliance automation
  • Establish and govern security architecture standards across the software development lifecycle, including static code analysis (Sonar), SAST (Checkmarx), SCA (Black Duck), secret scanning (GitHub Secret Scanning), DAST (dynamic application security testing), and supply chain security
  • Design infrastructure-as-code reference patterns, container security frameworks, and platform architecture blueprints
  • Own the architectural vision for automated compliance validation, vulnerability management, and remediation processes.
  • Lead architectural alignment of DevSecOps tooling across GitHub Actions (reusable workflows), static code analysis (Sonar), SAST (Checkmarx), SCA (Black Duck), secret scanning (GitHub Secret Scanning), and Harness CD deployments to OpenShift (OCP) platforms.
  • Architect and maintain standardized GitHub Actions workflow templates and reusable workflows that encode enterprise best practices for build, test, security scanning, and release governance.
  • Define and implement pipeline security gates and evidence collection by integrating static code analysis (Sonar), SAST (Checkmarx), SCA (Black Duck), secret scanning (GitHub Secret Scanning), and DAST (dynamic application security testing) into CI/CD workflows with automated enforcement and reporting
  • Design and govern Harness CD pipeline patterns for progressive delivery and environment promotion to OpenShift (OCP), including approvals, rollbacks, and audit-ready traceability
  •  

Technical Leadership, Innovation and Influence:

  • Evaluate, select, and champion emerging technologies in the Python ecosystem, DevOps, cloud-native platforms, and AI-enabled development
  • Lead proof-of-concept and proof-of-architecture initiatives for new tools, frameworks, and platforms; translate findings into architectural recommendations
  • Build and maintain strategic partnerships with Platform Engineering, Security, Cloud Operations, and Enterprise Architecture teams
  • Drive cultural transformation toward DevSecOps, SRE practices, and engineering excellence through architectural leadership and evangelism
  • Represent the Chief Data Office as the senior technical voice in cross-organizational architecture forums, governance boards, and technology councils
  • Influence enterprise-wide technology decisions and contribute to firm-level architectural standards

Required Qualifications:

  • 12 plus years of software engineering and architecture experience with demonstrated expertise designing systems in Python at enterprise scale
  • 12 plus years of architecting web applications, distributed systems, and platform solutions using industry-standard frameworks (Django, FastAPI, Flask)
  • 12 plus years of designing APIs, frameworks, automation pipelines, and distributed systems with a focus on scalability, resilience, and security
  • 12 plus years with cloud platforms (GCP, Azure, AWS) or on-prem platforms such as Kubernetes or OpenShift, including platform architecture and capacity planning
  • 10 plus years of experience architecting CI/CD pipelines, DevOps platforms, and release engineering systems, including GitHub Actions and reusable workflow design
  • Hands-on experience integrating automated security scans into CI/CD pipelines—static code analysis (Sonar), SAST (Checkmarx), SCA (Black Duck), and secret scanning (GitHub Secret Scanning)—and defining enforceable policy gates for release readiness
  • Experience designing and operating deployment automation to OpenShift (OCP) using Harness CD (or equivalent), including promotion, approvals, and rollback strategies
  • 7 plus years of security architecture experience including DevSecOps, application security, threat modeling, and compliance automation
  • 7 plus years of enterprise architecture leadership defining architecture standards, governance frameworks, and engineering processes across multiple teams
  • Experience utilizing coding assistants (GitHub Copilot) and AI-powered development tools, with ability to define organizational adoption strategies

Desired Qualifications:

  • 15 to 20 years of Python development with deep expertise in modern Python patterns, ecosystem, and large-scale system design
  • 15 plus years of web application architecture with at least 10 plus years using the Django web application framework
  • 5 plus years of architecture and development using Wagtail CMS and Wagtail CRX (CodeRed CMS)
  • 15 plus years of designing and implementing testing strategies including unit testing, integration testing, and test automation using Pytest and related frameworks
  • 15 plus years of code versioning using Git distributed version control system with expertise in branching strategies and repository governance
  • 10 plus years of platform architecture and engineering experience with OpenShift or Kubernetes, including multi-cluster and multi-tenant design
  • 10 plus years of CI/CD platform architecture including GitHub Actions (reusable workflows), and enterprise automation at scale
  • 10 plus years of data pipeline architecture and orchestration (Kedro, MLFlow, Airflow, distributed computing)
  • 7 plus years of infrastructure-as-code and GitOps architecture (Terraform, Ansible) with enterprise governance patterns
  • 7 plus years of experience with security architecture, security tools (SAST, DAST (dynamic application security testing) (dynamic application security testing), SCA), threat modeling, and compliance frameworks
  • 7 plus years partnering with Enterprise Architecture teams to define standards, governance, and technology strategy
  • Experience defining organizational strategies for AI-enabled Integrated Development Environments (Cursor, AWS Kiro)
  • Deep familiarity with Spec-Driven Development (GitHub Spec-Kit), API-first design, and domain-driven design (DDD)
  • Experience with SRE practices, observability platform architecture, and incident management frameworks
  • Proven track record of leading enterprise-scale technical transformations, cultural change initiatives, and architecture modernization programs
  • Experience presenting to and influencing senior technology leadership and executive stakeholders

Job Expectations:

  • Ability to work on-site at approved location
  • Ability to collaborate effectively in a hybrid enterprise environment

Required:

  • 10 plus years of professional software engineering experience with strong proficiency in Python and lead complex engineering initiatives.
  • 10 plus years of building web applications and APIs using industry-standard frameworks (Django, FastAPI,)
  • 8 plus years designing and implementing CI/CD automation and DevOps practices, including GitHub Actions
  • 5 plus years of experience with cloud-native platforms and container orchestration (OpenShift/Kubernetes) including deployment automation.
  • Experience building or operating deployment automation to OpenShift using Harness CD (or equivalent), including promotion, approvals, and rollback strategies.
  •