1

Product Security Code Review Engineer Jobs in California

Product Security Engineer

Torrance, CA · On-site

$154K - $210K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

... reviews and release gates. Own CVE tracking, vulnerability management, and security baseline ... Establish code signing policies, secure boot chain integrity, and validation procedures. Partner ...

Software Engineer II - Product Security

Los Angeles, CA · On-site

$165K - $200K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Conduct security assessments, code reviews, and penetration tests on web applications, APIs, and mobile apps to identify vulnerabilities and flaws. * Collaborate with development teams to embed ...

Product Security Engineer

San Francisco, CA · On-site

$170K - $200K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

... review of code changes to give engineering teams fast, high-signal feedback. Alongside the program, you'll drive vulnerability remediation across the platform - from finding to verified fix - and ...

Director, Product Security

Santa Clara, CA

$273K - $286K/yr

  • PTO

Leading a high-performing team of product security engineers, you will partner closely with ... Architect end-to-end vulnerability management, code reviews, and threat modeling protocols to ...

Senior Product Security Engineer

San Francisco, CA · On-site

$134K - $185K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

We're seeking a Senior Product Security Engineer who is first and foremost a skilled software ... Perform security reviews, penetration tests, code reviews, and system design reviews for Crusoe ...

Senior Product Security Engineer

San Francisco, CA · On-site

$134K - $185K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

We're seeking a Senior Product Security Engineer who is first and foremost a skilled software ... Perform security reviews, penetration tests, code reviews, and system design reviews for Crusoe ...

Senior Director, Product Security

San Francisco, CA

$182K - $224K/yr

  • Medical

  • Life

  • Retirement

  • PTO

... developer libraries, code reviews, etc.), as well as SDLC and CI/CD processes, gating, and ... Manage product security from design through release and maintenance * Embed with Product ...

Senior Director, Product Security

San Francisco, CA · On-site

$182K - $224K/yr

  • Medical

  • Life

  • Retirement

  • PTO

... developer libraries, code reviews, etc.), as well as SDLC and CI/CD processes, gating, and ... Manage product security from design through release and maintenance * Embed with Product ...

Lead Application Security Engineer

San Francisco, CA · On-site

$69.25 - $92.50/hr

Hunt for vulnerabilities in our own product through hands-on testing, code review, and offensive ... engineers to ship the fix. • Lead manual code review for security-sensitive changes ...

Secure Coding Standards: Develop and deliver training, coding patterns, and security guardrails to help engineering teams build resilient, secure-by-default products. * Incident Response Support ...

Senior Security Engineer, Ads Security

Sunnyvale, CA · On-site

$134K - $184K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... product and engineering teams in designing secure systems ... In this role, you will conduct secure design reviews, code review and penetration testing, develop ...

Product Security Engineer

San Carlos, CA · On-site

$137K - $250K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Audit code and systems across NEO's stack from bootloader and Linux userspace to cloud services and ... product security, offensive security, or a closely related engineering role * Strong experience ...

Showing results 41-60

Product Security Code Review Engineer information

What are the key skills and qualifications needed to thrive as a product security code review engineer?

To thrive as a Product Security Code Review Engineer, you need a deep understanding of secure coding practices, software development lifecycles, and vulnerability assessment, typically backed by a degree in computer science or a related field. Familiarity with static and dynamic analysis tools, code review platforms, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for explaining security findings and collaborating with development teams. These skills and qualities are vital to identify, communicate, and mitigate security risks in code, ensuring the overall resilience of software products.

What are some typical challenges faced by product security code review engineers when coordinating with development teams?

Product Security Code Review Engineers often encounter challenges in balancing security priorities with project timelines and developer workflows. Effective communication is essential, as engineers must clearly explain vulnerabilities and remediation steps to developers who may have varying levels of security expertise. Additionally, they need to ensure that security recommendations are practical and align with the product's architecture, all while fostering a collaborative environment rather than creating bottlenecks. Building strong relationships with development teams and understanding their processes helps streamline secure code adoption and continuous improvement.

What is the difference between Product Security Code Review Engineer vs Software Security Engineer?

AspectProduct Security Code Review EngineerSoftware Security Engineer
Primary FocusReviewing and analyzing source code for security vulnerabilities in productsDesigning and implementing security measures across software systems
Skills & CertificationsSecure coding, code review, security standards (e.g., OWASP), certifications like CSSLPSecurity architecture, threat modeling, secure coding, certifications like CISSP
Work EnvironmentCollaborates with development teams during product developmentWorks on system-wide security strategies and architecture
Industry UsageCommon in product-based companies, especially in tech and cybersecurityFound in organizations focusing on overall security infrastructure

While both roles focus on security, the Product Security Code Review Engineer primarily reviews source code for vulnerabilities in specific products, whereas the Software Security Engineer develops and implements security strategies across software systems. The roles often overlap but differ in scope and focus.

What is a product security code review engineer?

A Product Security Code Review Engineer is a cybersecurity professional responsible for analyzing and reviewing application source code to identify and mitigate security vulnerabilities. They work closely with development teams to ensure secure coding practices, review code for compliance with security standards, and recommend fixes for potential security issues. Their goal is to prevent security breaches by catching vulnerabilities early in the software development lifecycle.

What are popular job titles related to Product Security Code Review Engineer jobs in California?

For Product Security Code Review Engineer jobs in California, the most frequently searched job titles are:

What job categories do people searching Product Security Code Review Engineer jobs in California look for?

The top searched job categories for Product Security Code Review Engineer jobs in California are:

What cities in California are hiring for Product Security Code Review Engineer jobs?

Cities in California with the most Product Security Code Review Engineer job openings:

Product Security Engineer

Opto-Knowledge Systems Inc

Torrance, CA • On-site

$154K - $210K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 28 days ago


Job description

Description:

Position Overview

We are seeking a Product Security Engineer to own product-level security across OKSI's hardware and software systems. You will define and maintain the policies, standards, and architectural practices that protect our systems from design through field deployment. This is a strategic role requiring both the depth to establish security standards company-wide and the hands-on technical background to assess implementation and guide engineering teams.


What You'll Do

  • Lead threat modeling and security analysis across hardware, firmware, and software throughout the product lifecycle. Produce threat matrices, risk assessments, and security requirements traceable through design reviews and release gates. Own CVE tracking, vulnerability management, and security baseline compliance across the product portfolio.
  • Define and implement hardening standards for embedded Linux, RTOS, and bare-metal environments. Establish code signing policies, secure boot chain integrity, and validation procedures. Partner with IT and Engineering to architect and maintain the product signing and key management infrastructure using HSMs, KMS, or equivalent systems.
  • Own OKSI's anti-tamper posture aligned with DoD policy (DoDI 5200.39) and applicable Program Protection Plan requirements. Define IP protection strategy spanning software binary protection, hardware design protection, firmware confidentiality, and cryptographically bound license enforcement.
  • Serve as OKSI's product security authority. Establish company-wide standards, lead design reviews, provide security sign-off at program milestones, and embed security requirements into the Systems Engineering process. Provide guidance and training to Engineering, IT, and Operations teams on secure design principles.
Requirements:

Requirements

  • 7+ years of product security, embedded security, or cybersecurity systems engineering in a defense, aerospace, or advanced technology environment.
  • Demonstrated expertise leading threat modeling, security risk assessments, and vulnerability analysis across hardware, firmware, and software domains — including production of threat matrices, attack surface analyses, and traceable mitigation plans.
  • Hands-on experience defining and implementing security policies and standards (not just executing implementation tasks). You own the policy and architecture.
  • Working knowledge of secure boot architectures, anti-tamper techniques, and embedded platform security (e.g., UEFI Secure Boot, ARM TrustZone, fuse-based root-of-trust).
  • Practical experience with embedded Linux hardening: kernel configuration, module signing, RBAC/least-privilege access models, debug interface lockdown, and production credential management.
  • Experience with key management infrastructure and signing pipelines (HSMs, KMS, or equivalent) for firmware, software releases, and factory provisioning workflows.
  • Familiarity with DoD program protection and anti-tamper policy frameworks (DoDI 5200.39) and experience producing or reviewing Program Protection Plans (PPPs).
  • Strong written and verbal communication skills for policy documentation, risk reporting, and cross-functional leadership.

Preferred

  • Active DoD Secret or Top Secret clearance.
  • Experience establishing a secure product development lifecycle (SPDLC) or embedding security checkpoints into an engineering development process.
  • Familiarity with secure CI/CD pipeline design, software supply chain security, and artifact integrity controls.
  • Background in ITAR/EAR technology protection controls and export-controlled program environments.
  • Familiarity with CMMC, RMF, IEC 62443, or NIST SP 800-193/800-147 frameworks.
  • Experience with EO/IR, UAS, autonomous systems, or other embedded defense technology programs.
  • Relevant certifications: CISSP, CSSLP, CEH, or equivalent.
  • DoD SkillBridge participants with relevant MOS/AFSC experience (e.g., 17A, 25D, 1B4, or program protection/acquisition roles) are strongly encouraged to apply.

Compensation and Benefits

  • Salary range: $154,000 - $210,000 annually
  • Medical, dental, and vision coverage fully paid by the employer for employees
  • Three weeks of vacation to start
  • Automatic company contribution to 401K – 5% of earned wages (no matching required)
  • Educational assistance and professional development opportunities
  • In-office (Jacksonville, AK or Los Angeles, CA) or remote work (United States) available (position dependent)

Additional Requirements:

  • You must have, or be eligible to obtain, a U.S. Department of Defense Secret security clearance. You will be subject to government security investigations and must be able to access classified information. The inability to obtain a security clearance will result in you being ineligible for the position.

ITAR Requirements

  • To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C.
  • 1157, or (iv) Asylee under 8 U.S.C.
  • 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here.

We are an equal employment opportunity and affirmative action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, protected veteran status, or any other status protected by law. We provide reasonable accommodations for qualified individuals with disabilities in the application and hiring process.

This employer participates in E-Verify.