1

Product Security Code Review Engineer Jobs in California

Review product designs for security defects, perform threat modeling and recommend remediations ... Lead the definition and development of custom Security as Code solutions. * Provide training ...

... Security as Code solutions. • Provide training, guidance, and assistance to development teams ... Required : • Proven experience performing threat modeling and architecture reviews for complex ...

... idea to production with speed, security, and exceptional developer experience. Now, software is ... hoc code review, point-in-time pentests) still make sense at Vercel's scale, and build the agent ...

Senior Product Security Engineer

San Francisco, CA · On-site

$134K - $185K/yr

We're seeking a Senior Product Security Engineer who is first and foremost a skilled software ... Perform security reviews, penetration tests, code reviews, and system design reviews for Crusoe ...

Senior Product Security Engineer

San Francisco, CA · On-site

$134K - $185K/yr

We're seeking a Senior Product Security Engineer who is first and foremost a skilled software ... Perform security reviews, penetration tests, code reviews, and system design reviews for Crusoe ...

Director, Product Security

Santa Clara, CA · On-site

$273K - $286K/yr

Leading a high-performing team of product security engineers, you will partner closely with ... Architect end-to-end vulnerability management, code reviews, and threat modeling protocols to ...

New

Lead Application Security Engineer

San Francisco, CA · On-site

$69.25 - $92.50/hr

Hunt for vulnerabilities in our own product through hands-on testing, code review, and offensive ... engineers to ship the fix. • Lead manual code review for security-sensitive changes ...

Showing results 41-60

Product Security Code Review Engineer information

What are the key skills and qualifications needed to thrive as a product security code review engineer?

To thrive as a Product Security Code Review Engineer, you need a deep understanding of secure coding practices, software development lifecycles, and vulnerability assessment, typically backed by a degree in computer science or a related field. Familiarity with static and dynamic analysis tools, code review platforms, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for explaining security findings and collaborating with development teams. These skills and qualities are vital to identify, communicate, and mitigate security risks in code, ensuring the overall resilience of software products.

What are some typical challenges faced by product security code review engineers when coordinating with development teams?

Product Security Code Review Engineers often encounter challenges in balancing security priorities with project timelines and developer workflows. Effective communication is essential, as engineers must clearly explain vulnerabilities and remediation steps to developers who may have varying levels of security expertise. Additionally, they need to ensure that security recommendations are practical and align with the product's architecture, all while fostering a collaborative environment rather than creating bottlenecks. Building strong relationships with development teams and understanding their processes helps streamline secure code adoption and continuous improvement.

What is the difference between Product Security Code Review Engineer vs Software Security Engineer?

AspectProduct Security Code Review EngineerSoftware Security Engineer
Primary FocusReviewing and analyzing source code for security vulnerabilities in productsDesigning and implementing security measures across software systems
Skills & CertificationsSecure coding, code review, security standards (e.g., OWASP), certifications like CSSLPSecurity architecture, threat modeling, secure coding, certifications like CISSP
Work EnvironmentCollaborates with development teams during product developmentWorks on system-wide security strategies and architecture
Industry UsageCommon in product-based companies, especially in tech and cybersecurityFound in organizations focusing on overall security infrastructure

While both roles focus on security, the Product Security Code Review Engineer primarily reviews source code for vulnerabilities in specific products, whereas the Software Security Engineer develops and implements security strategies across software systems. The roles often overlap but differ in scope and focus.

What is a product security code review engineer?

A Product Security Code Review Engineer is a cybersecurity professional responsible for analyzing and reviewing application source code to identify and mitigate security vulnerabilities. They work closely with development teams to ensure secure coding practices, review code for compliance with security standards, and recommend fixes for potential security issues. Their goal is to prevent security breaches by catching vulnerabilities early in the software development lifecycle.
What are popular job titles related to Product Security Code Review Engineer jobs in California? For Product Security Code Review Engineer jobs in California, the most frequently searched job titles are:
What job categories do people searching Product Security Code Review Engineer jobs in California look for? The top searched job categories for Product Security Code Review Engineer jobs in California are:
What cities in California are hiring for Product Security Code Review Engineer jobs? Cities in California with the most Product Security Code Review Engineer job openings:

Sr. Product Security Engineer

Ekman Associates, Inc

Woodland Hills, CA • On-site

$121K - $166K/yr

Other

Re-posted 5 days ago


Job description

Job Description Title: Sr. Product Security Engineer Location: Remote Ekman Associates is a management consulting firm that specializes in developing business, digital, and technology strategy, delivering solutions, and addressing human resource demands. Summary: The Application and Product Security team is looking for an Sr. Product Security Engineer to lead the protection and defense of digital applications and product ecosystem with an emphasis on securing artificial technology (AI). This role will focus on detecting, mitigating, and responding to AI-related security threats, ensuring that applications and services remain resilient against AI-cyber threats. Responsibilities: Help the team establish, lead, and execute multi-year roadmaps to mature AI security, drawing upon cross-functional partnerships to deliver security posture reviews on a repeatable basis and review new AI systems as they're developed. Conduct application and product security evaluations and lead AI security assessments in a cross-functional environment, driving finding remediations; Secure AI Development Lifecycle: Procure and/or build technical solutions to embed automated security checks into the AI SDLC and ML-Ops; AI Threat Modeling: Threat model complex Agentic and AI systems and design security requirements collaboratively with developers, architects, and business stakeholders; Code Analysis: Review code for security bugs in the context of AI-driven systems; GRC: Provide leadership for AI Security policies and standards in collaboration with technology risk; AI/Agent SME: Provide AI/Agent subject matter expertise for AI Incidents and Security Reviews, and help develop incident response playbooks for AI-related security incidents; and, Assist in the formation of an AI Center of Excellence (ACE). Qualifications: 10+ years experience in product security, application security, and/or DevSecOps; You have strong knowledge of security of safety risks of LLMs and AI Agents; You have 5+ Years of experience automating security checks, including SAST, SCA, and DAST, directly into CI/CD pipelines; Extensive experience with STRIDE or other threat modeling frameworks; You have knowledge and experience with technologies including K8s, Containers, CI/CD, and CSPs Familiarity with function and purpose of key AI platform components such as AI gateways (Kong, Databricks Mosaic AI Gateway, custom API orchestration), Model Orchestration (Examples LangChain, LlamaIndex, etc.). Qualified Candidates Only : If you wish to learn more about this opportunity and additional qualifications/responsibilities, please submit your resume. To learn more about Ekman Associates, Inc. please visit our website at www.ekmanassociates.com