1

Product Security Code Review Engineer Jobs in Illinois

Security Engineer About Us: On a mission to deliver affordable, delightful healthcare for all ... Lead application security initiatives including architecture reviews, threat modeling, code reviews ...

AI Solutions Engineer (AVP)

Chicago, IL · On-site

$160K - $180K/yr

Incorporate security considerations into application design and development processes * Evaluate ... Code Review & Production Readiness * Review and refine application code, including AI-assisted ...

Support production deployment of ML models, LLM applications, RAG pipelines, and agentic AI systems ... Implement engineering standards for testing, code quality, security, maintainability, scalability ...

Senior Software Engineer

Chicago, IL · On-site

$102K - $179K/yr

Support production deployment of ML models, LLM applications, RAG pipelines, and agentic AI systems ... Implement engineering standards for testing, code quality, security, maintainability, scalability ...

Senior AI Security Engineer

Chicago, IL · On-site

$118K - $161K/yr

... conducting product security reviews and threat modeling using frameworks such as MITRE ATT&CK ... Azure Security Engineer Associate (AZ-500) WHY WE COULD BE A GREAT FIT Impactful Mission * Build ...

Showing results 41-60

Product Security Code Review Engineer information

What are the key skills and qualifications needed to thrive as a product security code review engineer?

To thrive as a Product Security Code Review Engineer, you need a deep understanding of secure coding practices, software development lifecycles, and vulnerability assessment, typically backed by a degree in computer science or a related field. Familiarity with static and dynamic analysis tools, code review platforms, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for explaining security findings and collaborating with development teams. These skills and qualities are vital to identify, communicate, and mitigate security risks in code, ensuring the overall resilience of software products.

What are some typical challenges faced by product security code review engineers when coordinating with development teams?

Product Security Code Review Engineers often encounter challenges in balancing security priorities with project timelines and developer workflows. Effective communication is essential, as engineers must clearly explain vulnerabilities and remediation steps to developers who may have varying levels of security expertise. Additionally, they need to ensure that security recommendations are practical and align with the product's architecture, all while fostering a collaborative environment rather than creating bottlenecks. Building strong relationships with development teams and understanding their processes helps streamline secure code adoption and continuous improvement.

What is the difference between Product Security Code Review Engineer vs Software Security Engineer?

AspectProduct Security Code Review EngineerSoftware Security Engineer
Primary FocusReviewing and analyzing source code for security vulnerabilities in productsDesigning and implementing security measures across software systems
Skills & CertificationsSecure coding, code review, security standards (e.g., OWASP), certifications like CSSLPSecurity architecture, threat modeling, secure coding, certifications like CISSP
Work EnvironmentCollaborates with development teams during product developmentWorks on system-wide security strategies and architecture
Industry UsageCommon in product-based companies, especially in tech and cybersecurityFound in organizations focusing on overall security infrastructure

While both roles focus on security, the Product Security Code Review Engineer primarily reviews source code for vulnerabilities in specific products, whereas the Software Security Engineer develops and implements security strategies across software systems. The roles often overlap but differ in scope and focus.

What is a product security code review engineer?

A Product Security Code Review Engineer is a cybersecurity professional responsible for analyzing and reviewing application source code to identify and mitigate security vulnerabilities. They work closely with development teams to ensure secure coding practices, review code for compliance with security standards, and recommend fixes for potential security issues. Their goal is to prevent security breaches by catching vulnerabilities early in the software development lifecycle.
What are popular job titles related to Product Security Code Review Engineer jobs in Illinois? For Product Security Code Review Engineer jobs in Illinois, the most frequently searched job titles are:
What job categories do people searching Product Security Code Review Engineer jobs in Illinois look for? The top searched job categories for Product Security Code Review Engineer jobs in Illinois are:
What cities in Illinois are hiring for Product Security Code Review Engineer jobs? Cities in Illinois with the most Product Security Code Review Engineer job openings:

Senior Director, Security Engineering

Ripple

Chicago, IL • On-site

Full-time

Posted 3 days ago

New


Job description

THE WORK:

As the Senior Director of Security Engineering, you will be responsible for building and leading a dedicated, humble, and paranoid team of Security Engineers to secure Ripple's products, infrastructure, and corporate IT systems. You will play a substantial role in defining the security strategy and encouraging a culture of security across the entire company. Your leadership will be crucial in protecting our business and our customers by embedding security into every layer of our technology stack.

This is a hands-on role and requires a deep understanding of technology. AI is fundamentally reshaping how we build software and how our tools and systems operate, and this role sits at the center of that challenge. You will ensure our use of AI tooling and agentic workflows is secure, controlled, and auditable.

WHAT YOU'LL DO:

  • Set the strategic vision and roadmap for the Security Engineering team, focusing on product security, infrastructure security, and IT security, with a particular focus on AI security, including agentic guardrails and AI-assisted development risk.
  • Serve as a security domain expert, providing guidance and communicating security risks and concepts to senior leadership, engineering teams, and other partners.
  • Define guardrails around AI agents and tools operating within Ripple's environment, including scope boundaries, blast radius limits, and rollback mechanisms.
  • Implement and enforce agentic SDLC guardrails, testing gates, and human oversight of AI-assisted development workflows.
  • Lead, mentor, and strengthen a team of security engineers, cultivating an atmosphere that values technical excellence, continual learning, and innovation.
  • Drive the implementation of security guidelines across the engineering organization, ensuring security is integrated into day-to-day development processes.
  • Lead security architecture reviews for new products, infrastructure changes, and major engineering initiatives, serving as a formal checkpoint before systems go to production.
  • Own the vulnerability management program, including coordinating penetration testing, prioritizing remediation, and partnering with engineering teams to close risk at pace.
  • Collaborate with engineering, product, and IT leadership to ensure alignment on security priorities and to champion security outcomes on behalf of our customers.

WHAT YOU'LL BRING:

  • 15+ years of experience in security engineering, with at least 5+ years in a leadership or management role, preferably in the crypto, blockchain, or FinTech space.
  • Hands-on expertise in AI security: a clear understanding of the risk surface introduced by LLMs, AI agents, and AI-assisted development workflows, and how to build guardrails around them.
  • Expert-level knowledge of security architecture, including cloud environments (AWS, GCP, Azure), modern application stacks, and network security.
  • Strong understanding of cryptographic principles, secure coding practices, and common web and blockchain vulnerabilities (e.g., OWASP Top 10).
  • Experience with authentication and authorization standards (OAuth, SAML, OIDC) and their security implications.
  • Demonstrated expertise in IT security, including endpoint protection, network security, identity and access management (IAM), and corporate security policy enforcement.
  • Hands-on experience with threat modeling methodologies and risk identification techniques.
  • Ability to communicate complex technical concepts and security risks to both technical and non-technical audiences.
  • A track record of fostering a positive security culture within an organization and proven experience leading and building a high-performing security team.
  • Excellent problem-solving skills and the ability to effectively and creatively manage complex security challenges.