1

Product Security Code Review Engineer Jobs in Indiana

Enterprises, financial institutions, and developers use Circle to power trusted, internet-scale ... As VP, Global Head of Product Security & Risk, you will define and lead the enterprise framework ...

... and Product Security, and testing techniques. • Gather and analyze requirements, to drive ... code reviews for developed features • Define, review, and execute test cases Desired ...

Integrate security across the SSDLC, including code reviews, testing, and deployment. In this role ... Cross-Functional Collaboration Partner closely with product, engineering, cybersecurity, and risk ...

Embedded Software Engineer Location: Indianapolis, IN Schedule: Monday-Friday, Onsite | 9:00 AM-5 ... Participate in code reviews, testing, CI/CD, and firmware documentation. * Support product security ...

next page

Showing results 1-20

Product Security Code Review Engineer information

What is a product security code review engineer?

A Product Security Code Review Engineer is a cybersecurity professional responsible for analyzing and reviewing application source code to identify and mitigate security vulnerabilities. They work closely with development teams to ensure secure coding practices, review code for compliance with security standards, and recommend fixes for potential security issues. Their goal is to prevent security breaches by catching vulnerabilities early in the software development lifecycle.

What are the key skills and qualifications needed to thrive as a product security code review engineer?

To thrive as a Product Security Code Review Engineer, you need a deep understanding of secure coding practices, software development lifecycles, and vulnerability assessment, typically backed by a degree in computer science or a related field. Familiarity with static and dynamic analysis tools, code review platforms, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for explaining security findings and collaborating with development teams. These skills and qualities are vital to identify, communicate, and mitigate security risks in code, ensuring the overall resilience of software products.

What are some typical challenges faced by product security code review engineers when coordinating with development teams?

Product Security Code Review Engineers often encounter challenges in balancing security priorities with project timelines and developer workflows. Effective communication is essential, as engineers must clearly explain vulnerabilities and remediation steps to developers who may have varying levels of security expertise. Additionally, they need to ensure that security recommendations are practical and align with the product's architecture, all while fostering a collaborative environment rather than creating bottlenecks. Building strong relationships with development teams and understanding their processes helps streamline secure code adoption and continuous improvement.

What is the difference between Product Security Code Review Engineer vs Software Security Engineer?

AspectProduct Security Code Review EngineerSoftware Security Engineer
Primary FocusReviewing and analyzing source code for security vulnerabilities in productsDesigning and implementing security measures across software systems
Skills & CertificationsSecure coding, code review, security standards (e.g., OWASP), certifications like CSSLPSecurity architecture, threat modeling, secure coding, certifications like CISSP
Work EnvironmentCollaborates with development teams during product developmentWorks on system-wide security strategies and architecture
Industry UsageCommon in product-based companies, especially in tech and cybersecurityFound in organizations focusing on overall security infrastructure

While both roles focus on security, the Product Security Code Review Engineer primarily reviews source code for vulnerabilities in specific products, whereas the Software Security Engineer develops and implements security strategies across software systems. The roles often overlap but differ in scope and focus.

What job categories do people searching Product Security Code Review Engineer jobs in Indiana look for?

The top searched job categories for Product Security Code Review Engineer jobs in Indiana are:

What cities in Indiana are hiring for Product Security Code Review Engineer jobs?

Cities in Indiana with the most Product Security Code Review Engineer job openings:

Application Security Engineer

Warsaw, IN • On-site

$93.91 - $106.72/hr

Other

Medical, Dental, PTO

Posted 10 days ago


Job description

The Security team is responsible for protecting the company’s employees, users, and customers. Weare a team of security engineers and risk and compliance practitioners who build innovativesafeguards to ensure that our data is protected against threats and that we comply with legal, regulatory, and customer requirements. We collaborate closely with teams across theorganization to foster a culture of security throughout our product and operations. We’re lookingfor an Application Security Engineer to join our Security team in Warsaw. You’ll be afoundational member of the security presence in a key engineering hub, partnering directly withIT, infrastructure, and product teams to ensure we design and ship secure software. You will beinstrumental in scaling our security practices by conducting security design reviews, threatmodeling, and vulnerability assessments across our products and internal applications, eliminating entire classes of vulnerabilities, and championing a security-first mindset.

This role is based in our Warsaw office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do, andyour recruiter can share more about the in-office requirements.We offer a Contract of Employment (UoP) for our employees in Poland.

What you’ll achieve
  • Conduct security architecture reviews and threat modeling for new features and servicesacross our product and internal applications, identifying risks early and influencing securedesign decisions.
  • Perform vulnerability assessments of software and systems, using a range of assessmentmethodologies to surface and prioritize security weaknesses across our product surface.
  • Triage, investigate, and drive remediation of vulnerabilities from our bug bounty programand automated security tooling, ensuring issues are tracked and resolved within definedSLAs.
  • Influence engineering initiatives by conducting design and roadmap reviews, effectivelycommunicating security constraints, and assisting teams in making informed trade-offs.
  • Investigate product security incidents as a subject matter expert, using logs andmonitoring tools to assess scope, impact, and root cause.
  • Develop and deliver training to educate engineers on secure coding best practices, threatmodeling techniques, and emerging threats.
  • Stay informed of industry trends, emerging threats, and best practices to ensure thatthe company's security posture remains robust and ahead of the threat landscape.
  • Collaborate with teammates and stakeholders to develop both short-term and long-termstrategies for risk management and security program maturity.
  • Join a collaborative Security team composed of specialists in product, application,software engineering, infrastructure and detection and response, all working together tohelp engineering teams design and ship secure software.
About you
  • Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making.
  • 5+ years of experience in application security, product security, or software engineeringwith a security focus, with significant experience in security design reviews, threatmodeling, and vulnerability assessments.
  • Strong software engineering background with experience in languages like Python,JavaScript/TypeScript or Scala.
  • Deep working knowledge of the OWASP Top 10 and common web applicationvulnerabilities such as XSS, CSRF, SSRF, and SQL injection.
  • Experience with security tools for static/dynamic analysis (SAST/DAST), softwarecomposition analysis (SCA), and vulnerability management.
  • Proven experience performing security design reviews and threat modeling for complex,distributed applications, with the ability to identify systemic risk and drive remediation atscale.
  • Excellent communication skills for collaborating effectively with both technical andnon-technical partners, translating security risk into business impact.
  • A pragmatic and collaborative mindset, with a passion for building defenses into thesoftware development lifecycle and enabling other engineers to do their best, most securework.
What we’ll offer
  • Generous, transparent and fair compensation system (base salary and RSUs)
  • Contract of Employment (and the option of 50% tax deductible costs for author’s rightsusage in respect of applicable roles)
  • Health insurance with dental and travel coverage (Lux Med)
  • Breakfast and lunch catering on the days that you work from the office
  • Vacation allowance
  • Career growth budget
  • Home office setup budget
  • Gym/Fitness card
  • Fertility healthcare and family-forming support with Carrot
  • Mental Health Support in Modern Health
  • Group life insurance
  • MacBooks with all necessary accessories

For this role, the estimated base salary range is between 31,900 - 36,250 PLN gross per month (subject to all taxes and necessary deductions). The actual base salary will vary based onvarious factors, including market and individual qualifications objectively assessed during theinterview process. The listed range above is a guideline, and the base salary range for this rolemay be modified.
In addition to base salary, your compensation package may include additional componentssuchas equity and sales incentive pay (for most sales roles), and benefits. If you're interviewing forthis role, speak with your recruiter to learn more about the total compensation and benefits forthis role.

At the company, we're committed to building teams that include a variety of backgrounds,perspectives, and skills, as this is critical to helping us achieve our mission. If you're interested in this role and don't meet every listed requirement, we still encourage you to apply.

#J-18808-Ljbffr