1

Product Security Code Review Engineer Jobs in Michigan

Product Security Architect

Troy, MI · On-site

$61.50 - $79.50/hr

Work and collaborate with customer, product, engineering, and operations teams to ensure high ... Salary ranges are determined through interviews and a review of the education, experience ...

Product Security Architect

Troy, MI

$61.50 - $79.50/hr

Work and collaborate with customer, product, engineering, and operations teams to ensure high ... Salary ranges are determined through interviews and a review of the education, experience ...

... generated code, including testing, quality gates, security checks, and human review. • ... developer portals. • Strong ability to translate business and engineering problems into AI ...

next page

Showing results 1-20

Product Security Code Review Engineer information

What are the key skills and qualifications needed to thrive as a product security code review engineer?

To thrive as a Product Security Code Review Engineer, you need a deep understanding of secure coding practices, software development lifecycles, and vulnerability assessment, typically backed by a degree in computer science or a related field. Familiarity with static and dynamic analysis tools, code review platforms, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for explaining security findings and collaborating with development teams. These skills and qualities are vital to identify, communicate, and mitigate security risks in code, ensuring the overall resilience of software products.

What are some typical challenges faced by product security code review engineers when coordinating with development teams?

Product Security Code Review Engineers often encounter challenges in balancing security priorities with project timelines and developer workflows. Effective communication is essential, as engineers must clearly explain vulnerabilities and remediation steps to developers who may have varying levels of security expertise. Additionally, they need to ensure that security recommendations are practical and align with the product's architecture, all while fostering a collaborative environment rather than creating bottlenecks. Building strong relationships with development teams and understanding their processes helps streamline secure code adoption and continuous improvement.

What is the difference between Product Security Code Review Engineer vs Software Security Engineer?

AspectProduct Security Code Review EngineerSoftware Security Engineer
Primary FocusReviewing and analyzing source code for security vulnerabilities in productsDesigning and implementing security measures across software systems
Skills & CertificationsSecure coding, code review, security standards (e.g., OWASP), certifications like CSSLPSecurity architecture, threat modeling, secure coding, certifications like CISSP
Work EnvironmentCollaborates with development teams during product developmentWorks on system-wide security strategies and architecture
Industry UsageCommon in product-based companies, especially in tech and cybersecurityFound in organizations focusing on overall security infrastructure

While both roles focus on security, the Product Security Code Review Engineer primarily reviews source code for vulnerabilities in specific products, whereas the Software Security Engineer develops and implements security strategies across software systems. The roles often overlap but differ in scope and focus.

What is a product security code review engineer?

A Product Security Code Review Engineer is a cybersecurity professional responsible for analyzing and reviewing application source code to identify and mitigate security vulnerabilities. They work closely with development teams to ensure secure coding practices, review code for compliance with security standards, and recommend fixes for potential security issues. Their goal is to prevent security breaches by catching vulnerabilities early in the software development lifecycle.
What are popular job titles related to Product Security Code Review Engineer jobs in Michigan? For Product Security Code Review Engineer jobs in Michigan, the most frequently searched job titles are:
What job categories do people searching Product Security Code Review Engineer jobs in Michigan look for? The top searched job categories for Product Security Code Review Engineer jobs in Michigan are:
What cities in Michigan are hiring for Product Security Code Review Engineer jobs? Cities in Michigan with the most Product Security Code Review Engineer job openings:

Product Security Architect

Aptiv PLC

Troy, MI • On-site

$61.50 - $79.50/hr

Full-time

Medical, Dental, Life

Re-posted 26 days ago


Job description

ABOUT WIND RIVER
Wind River is a global leader in delivering software for mission-critical intelligent systems. For more than four decades, the company has been an innovator and pioneer, powering billions of systems that require the highest levels of security, safety, and reliability.
Wind River helps customers across automotive, aerospace, defense, industrial, medical, and telecommunications industries solve complex technology challenges on their journey toward the new intelligent machine economy. The company's software powers generation after generation of the safest, most secure systems in the world. Examples include playing a key role in NASA space missions such as Artemis I, the James Webb Space Telescope, and multiple Mars rovers. We've achieved recent 5G milestones including the world's first successful 5G data session with Verizon and building one of the largest Open RAN networks in the world with Vodafone.
The company has received industry recognition for its technology innovation and leadership, and for its workplace culture, including global Great Place to Work certification and being named a "Top Workplace" for ten consecutive years. If you want to be part of a unique culture where the lived experience is based on our cultural attributes of growth mindset, customer-focus, and diversity, equity, inclusion & belonging, come join us and help advance the future software defined world.
ABOUT THE OPPORTUNITY
YOUR ROLE
Wind River Systems is seeking an experienced Software Product Security Architect to join the R&D Security Office to scale trust in our product security to meet increasing business and security technology needs. This position will join a mature product security team and architect and mobilize product security trust initiatives, manage customer product security trust, and contribute to product security incident response (PSIRT) and vulnerability management.
HOW YOU WILL CONTRIBUTE
In your daily job you will:
  • Work and collaborate with customer, product, engineering, and operations teams to ensure high levels of product security trust with a scalable, compliance-driven mindset, across all products
  • Architect the product security trust roadmap and scale the compliance framework to meet emerging and future business priorities.
  • Empower product security compliance frameworks across engineering and aligned to the CTO Office, Product Management, IT, Legal, InfoSec, and SecOps.
  • Empower product security champions throughout product engineering.
  • Manage customer product security trust and compliance.
  • Training, mentoring, and supporting development teams to follow secure development values, principles, and practices.

Key skills and competencies for succeeding in this role are:
  • Direct experience with product security assurance techniques including Threat Modeling, Security Testing, Vulnerability Management, Software Composition, etc.
  • Experience in software engineering models and techniques.
  • Experience empowering security compliance broadly across an organization.
  • Broad-based experience with global security regulations, frameworks, and standards.
  • Exposure to customer compliance and remediations (Questionnaire's, Audits, Contracts, etc.)
  • Ability to analyze and think quickly and to resolve conflict.
  • Strong communication, interpersonal, and mentoring skills.
  • Ability to work effectively across the organization.
  • Ability to adapt to a changing environment.

QUALIFICATIONS:
  • Bachelor's degree in engineering, computer science, information technology or similar field with 14 years of experience in software development, security engineering, and/or compliance. Master's Degree is preferred and 12 years of related experience.
  • Preferred is a certified security professional (CSSLP, CISM, CISSP, CEH, or similar).
  • Direct experience mobilizing one or more security standards/certifications/models like OWASP SAMM, IEC 62443, ISO 21434, NIST 800-218, FIPS 140-3, DISA STIG, Common Criteria, CMMC, FedRamp, etc.
  • Practical experience with the NIST 800 series of security standards, including 800-53, 800-171, and others.
  • Experience mobilizing secure software development techniques across an organization such as training, workshops, or similar.
  • Demonstrated experience using agile techniques and frameworks to deliver secure software.
  • Excellent verbal and written, management level and customer communication skills.
  • Preferred experience with the European Union (EU) security regulatory environment including the Cyber Resilience Act (CRA).
  • Preferred experience with national security systems and standards (CNSS, etc.).
  • Preferred working knowledge of risk management frameworks and risk-based secure software development.
  • Preferred experience with AI and Machine learning and their governance and provenance in a secure software development environment.
  • Preferred working knowledge of related quality and safety assurance standards such as ASPICE, ISO 26262, or DO-178C.

BENEFITS
  • Hybrid work model for workplace flexibility
  • Comprehensive health, dental, and life insurance
  • Short and long-term disability coverage
  • RRSP matching for financial security
  • Flexible time-off policies for work-life balance
  • Employee assistance program for mental well-being
  • Learning benefits, including a LinkedIn Learning subscription and seminars

COMPENSATION
The annual base salary range for this role's listed grade level is currently $146,000 to 210,00 plus bonus, or $180,000 to $230,200 plus a bonus for MA, NYC, CO, WA and CA residents. Salary ranges are determined through interviews and a review of the education, experience, knowledge, skills, location, and abilities of the applicant, and equity with other team members.
SPECIAL CLEARANCE REQUIREMENTS
This position will perform work that the U.S. government has specified can only be performed by a U.S. citizen on U.S. soil, and therefore any offer will be contingent upon verification of both of these requirements.
Join us at Wind River, where we're not just shaping technology; we're shaping the future of a safer, more connected world. Your journey to make a meaningful impact begins here.
Wind River is an Equal Opportunity Employer with a commitment to diversity. We prohibit discrimination based on race, color, religion, gender, national origin, age, disability, veteran status, marital status, pregnancy, gender expression or identity, sexual orientation or any other legally protected status.
#LI-JP1
Privacy Notice - Active Candidates: https://www.aptiv.com/privacy-notice-active-candidates
Aptiv is an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, gender identity, sexual orientation, disability status, protected veteran status or any other characteristic protected by law.