1

Product Security Code Review Engineer Jobs (NOW HIRING)

Sr Product Security Engineer

$117K - $160K/yr

The Role We're hiring a Senior Product Security Engineer to build and operate the modern security ... This includes automated code review triage, vulnerability pattern detection, fix suggestion ...

... Product Security Engineer, Staff. The role involves participating in product security incident ... Secure code review, analysis and vulnerability assessment; Security testing, e.g. fuzzing and pen ...

As a Product Security Engineer, you will be a hands-on technical leader responsible for ... focused code and infrastructure reviews in languages like Rust, Go, and Python. • Own the ...

Security Architect

San Jose, CA

$76.25 - $98.50/hr

This includes threat modeling, security testing, penetration testing, security code reviews, and ... Work across SW/HW engineering, production, and operations teams and ODM/OEM to identify component ...

The Staff Product Security Engineer Opportunity As a Staff Product Security Engineer, you will play ... Expertise in identifying OWASP Top 10 / CWE Top 25 vulnerabilities through manual code review.

The Role We're seeking a Senior Product Security Engineer who is passionate about building and ... Experience leveraging AI and automation to scale security programs (e.g., LLM-assisted code review ...

Work closely with development teams, conduct code reviews, perform AI Red Teaming assessments, to ... Perform threat modeling for AI-related products, such as chatbots, MCPs implementations, and ...

Work closely with development teams, conduct code reviews, perform AI Red Teaming assessments, to ... Perform threat modeling for AI-related products, such as chatbots, MCPs implementations, and ...

Mobility Application Security

Rancho Cordova, CA · On-site

$62.75 - $83.75/hr

... Code Review, Threat Assessment etc.) • Security Testing standards and checklist , 12+ Years of ... products • Experience with enterprise SSO and familiarity with OAuth, SAML, etc. is preferred.

The Senior Product Security Engineer is a highly skilled practitioner who drives hands-on security ... Lead manual and automated code review efforts to discover vulnerabilities, weaknesses, and anti ...

next page

Showing results 1-20

Product Security Code Review Engineer information

See salary details

$53K

$144.1K

$205K

How much do product security code review engineer jobs pay per year?

As of Jun 26, 2026, the average yearly pay for product security code review engineer in the United States is $144,072.00, according to ZipRecruiter salary data. Most workers in this role earn between $88,000.00 and $205,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Product Security Code Review Engineer, and why are they important?

To thrive as a Product Security Code Review Engineer, you need a deep understanding of secure coding practices, software development lifecycles, and vulnerability assessment, typically backed by a degree in computer science or a related field. Familiarity with static and dynamic analysis tools, code review platforms, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for explaining security findings and collaborating with development teams. These skills and qualities are vital to identify, communicate, and mitigate security risks in code, ensuring the overall resilience of software products.

What are some typical challenges faced by Product Security Code Review Engineers when coordinating with development teams?

Product Security Code Review Engineers often encounter challenges in balancing security priorities with project timelines and developer workflows. Effective communication is essential, as engineers must clearly explain vulnerabilities and remediation steps to developers who may have varying levels of security expertise. Additionally, they need to ensure that security recommendations are practical and align with the product's architecture, all while fostering a collaborative environment rather than creating bottlenecks. Building strong relationships with development teams and understanding their processes helps streamline secure code adoption and continuous improvement.

What is the difference between Product Security Code Review Engineer vs Software Security Engineer?

AspectProduct Security Code Review EngineerSoftware Security Engineer
Primary FocusReviewing and analyzing source code for security vulnerabilities in productsDesigning and implementing security measures across software systems
Skills & CertificationsSecure coding, code review, security standards (e.g., OWASP), certifications like CSSLPSecurity architecture, threat modeling, secure coding, certifications like CISSP
Work EnvironmentCollaborates with development teams during product developmentWorks on system-wide security strategies and architecture
Industry UsageCommon in product-based companies, especially in tech and cybersecurityFound in organizations focusing on overall security infrastructure

While both roles focus on security, the Product Security Code Review Engineer primarily reviews source code for vulnerabilities in specific products, whereas the Software Security Engineer develops and implements security strategies across software systems. The roles often overlap but differ in scope and focus.

What is a Product Security Code Review Engineer?

A Product Security Code Review Engineer is a cybersecurity professional responsible for analyzing and reviewing application source code to identify and mitigate security vulnerabilities. They work closely with development teams to ensure secure coding practices, review code for compliance with security standards, and recommend fixes for potential security issues. Their goal is to prevent security breaches by catching vulnerabilities early in the software development lifecycle.
More about Product Security Code Review Engineer jobs
What cities are hiring for Product Security Code Review Engineer jobs? Cities with the most Product Security Code Review Engineer job openings:
What states have the most Product Security Code Review Engineer jobs? States with the most job openings for Product Security Code Review Engineer jobs include:
What job categories do people searching Product Security Code Review Engineer jobs look for? The top searched job categories for Product Security Code Review Engineer jobs are:
Software Developer - Security Code Review

Software Developer - Security Code Review

ThreatLocker

Orlando, FL

Other

Posted yesterday


ThreatLocker rating

7.0

Company rating: 7.0 out of 10

Based on 6 frontline employees who took The Breakroom Quiz

145th of 191 rated software companies


Job description

COMPANY OVERVIEW

ThreatLocker is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker platform with Application Allowlisting, Ringfencing, Storage Control, Elevation Control, Endpoint Network Control, Configuration Management, and Operational Alert solutions are leading the cybersecurity market toward a more secure approach of blocking the exploits of application vulnerabilities.

POSITION OVERVIEW

We are looking for a Security-Focused Software Developer to join our onsite team, specializing exclusively in manual and automated code review for security vulnerabilities. In this role, you will not be writing production code but will be deeply involved in reviewing application code to identify security issues, enforce secure coding practices, and ensure compliance with industry security standards.

The role will be based in Orlando, FL and is an in-office position.

KEY RESPONSIBILITIES

  • Perform in-depth security-focused code reviews across various codebases and languages
  • Identify common and advanced security vulnerabilities (e.g., injection, XSS, insecure deserialization, insecure APIs).
  • Work closely with developers to educate and guide them in secure coding practices.
  • Recommend fixes and mitigation strategies, ensuring adherence to security standards (e.g., OWASP Top 10, CWE, NIST).
  • Collaborate with security engineers, architects, and DevSecOps teams to enhance code security posture.
  • Maintain documentation of findings and track remediation status.
  • Utilize static and dynamic analysis tools to supplement manual reviews.
  • Participate in security audits, threat modeling, and secure code training sessions.

REQUIRED QUALIFICATIONS

  • Bachelor's degree in Computer Science, Cybersecurity, or a related field (or equivalent experience).
  • 5+ years of experience in software development with at least 2 years in secure code review or application security.
  • Strong understanding of secure software development lifecycle (SSDLC).
  • Experience identifying and remediating vulnerabilities in code written in one or more languages (e.g., C/C++, C#, Swift, Java, JavaScript, Python).
  • Familiarity with security tools such as SonarQube, Fortify, Checkmarx, Veracode, or similar.
  • Knowledge of OWASP Top 10, CWE/SANS 25, and CVSS scoring.
  • Strong analytical, communication, and documentation skills.

PREFERRED QUALIFICATIONS IN

  • Security certifications such as OSCP, CSSLP, CEH, or GWAPT.
  • Experience in regulated environments (e.g., finance, healthcare, defense).
  • Familiarity with threat modeling, penetration testing, or red/blue team operations.

WORKING CONDITIONS

The duties described below are representative of those encountered while performing the essential functions of this position. If necessary, reasonable accommodation may be requested and will be evaluated for its relationship to the essential functions that must be performed.

  • Job will generally be performed in an office environment but may require travel to visit company offices and/or property locations.
  • While performing duties of this job, would occasionally require to stand, walk, sit, reach with hands and arms, climb or balance, stoop or kneel, talk and hear, and use fingers and hands to feel objects and tools.
  • Must occasionally lift and/or move up to 25 pounds.
  • Specific vision abilities required include close vision, distance vision, depth perceptions, and the ability to adjust focus.

A background check and drug/substance screening are required after a conditional offer. Employment will proceed only upon receiving clear results from both.

 ThreatLocker also conducts randomized drug and substance testing approximately every 60 days, in line with the same screening standards.