1

Product Security Code Review Engineer Jobs in Michigan

Application Security Analyst

Auburn Hills, MI ยท On-site

$55.50 - $74.25/hr

Hands-on experience with secure code review in common languages (Java, C#, Python preferred ... Programming/scripting: Java, JavaScript, SQL, HTML * Scripting languages (Python, Bash preferred)

Application Security Analyst

Auburn Hills, MI

$55.50 - $74.25/hr

Hands-on experience with secure code review in common languages (Java, C#, Python preferred ... Programming/scripting: Java, JavaScript, SQL, HTML * Scripting languages (Python, Bash preferred)

Mentor engineers through code review, pairing, and design discussion * Identify high-leverage opportunities in product, operations, and data-and drive them * Help shape engineering practices ...

... products 3. Develop clean and maintainable code to ensure cross-browser compatibility. 4. Design ... library & code review/security scanning toolsets like SonarQube and JFrog. 9. Demonstrate ...

New

As a Full Stack Software Engineer, you will collaborate closely with Product, Architecture & QA ... library & code review/security scanning toolsets like SonarQube and JFrog. 9. Demonstrate ...

Showing results 21-40

Product Security Code Review Engineer information

What are the key skills and qualifications needed to thrive as a product security code review engineer?

To thrive as a Product Security Code Review Engineer, you need a deep understanding of secure coding practices, software development lifecycles, and vulnerability assessment, typically backed by a degree in computer science or a related field. Familiarity with static and dynamic analysis tools, code review platforms, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for explaining security findings and collaborating with development teams. These skills and qualities are vital to identify, communicate, and mitigate security risks in code, ensuring the overall resilience of software products.

What are some typical challenges faced by product security code review engineers when coordinating with development teams?

Product Security Code Review Engineers often encounter challenges in balancing security priorities with project timelines and developer workflows. Effective communication is essential, as engineers must clearly explain vulnerabilities and remediation steps to developers who may have varying levels of security expertise. Additionally, they need to ensure that security recommendations are practical and align with the product's architecture, all while fostering a collaborative environment rather than creating bottlenecks. Building strong relationships with development teams and understanding their processes helps streamline secure code adoption and continuous improvement.

What is the difference between Product Security Code Review Engineer vs Software Security Engineer?

AspectProduct Security Code Review EngineerSoftware Security Engineer
Primary FocusReviewing and analyzing source code for security vulnerabilities in productsDesigning and implementing security measures across software systems
Skills & CertificationsSecure coding, code review, security standards (e.g., OWASP), certifications like CSSLPSecurity architecture, threat modeling, secure coding, certifications like CISSP
Work EnvironmentCollaborates with development teams during product developmentWorks on system-wide security strategies and architecture
Industry UsageCommon in product-based companies, especially in tech and cybersecurityFound in organizations focusing on overall security infrastructure

While both roles focus on security, the Product Security Code Review Engineer primarily reviews source code for vulnerabilities in specific products, whereas the Software Security Engineer develops and implements security strategies across software systems. The roles often overlap but differ in scope and focus.

What is a product security code review engineer?

A Product Security Code Review Engineer is a cybersecurity professional responsible for analyzing and reviewing application source code to identify and mitigate security vulnerabilities. They work closely with development teams to ensure secure coding practices, review code for compliance with security standards, and recommend fixes for potential security issues. Their goal is to prevent security breaches by catching vulnerabilities early in the software development lifecycle.
What are popular job titles related to Product Security Code Review Engineer jobs in Michigan? For Product Security Code Review Engineer jobs in Michigan, the most frequently searched job titles are:
What job categories do people searching Product Security Code Review Engineer jobs in Michigan look for? The top searched job categories for Product Security Code Review Engineer jobs in Michigan are:
What cities in Michigan are hiring for Product Security Code Review Engineer jobs? Cities in Michigan with the most Product Security Code Review Engineer job openings:

Staff Security Engineer, Enterprise Security Architecture

Aurora Innovation

Detroit, MI โ€ข On-site

Other

Re-posted 13 days ago


Job description

Aurora hires talented people with diverse backgrounds who are ready to help build a transportation ecosystem that will make our roads safer, get crucial goods where they need to go, and make mobility more efficient and accessible for all. We're searching for a Staff Security Engineer, Enterprise Security Architecture.

This position is open to the following office locations: Mountain View, San Francisco, Seattle, Pittsburgh, Dallas, Detroit, and Phoenix.

In this role, you will

  • Define and champion Aurora's enterprise security architecture strategy, roadmap, and target-state operating model across enterprise and backend operational security domains.
  • Develop enterprise security reference architectures, design patterns, and technical standards for endpoint security, network security, infrastructure security, enterprise vulnerability management, data protection, resilience, enterprise platforms, and security tooling.
  • Translate security strategy, governance requirements, and business priorities into scalable technical architecture and implementation guidance.
  • Partner with GRC to operationalize security policies, standards, and control objectives into practical enterprise security architectures.
  • Support and influence Aurora's broader Enterprise Architecture Committee by representing enterprise security priorities, technical standards, and strategic design principles.
  • Participate in architecture review boards, design committees, and strategic planning forums to ensure enterprise security alignment across major initiatives.
  • Architect secure solutions for workforce platforms, enterprise systems, internal infrastructure, and backend operational ecosystems using Zero Trust principles and modern security frameworks.
  • Guide enterprise security design for endpoint security, network security, PKI, enterprise vulnerability management, BCP/DR, data security, enterprise infrastructure, and security tooling modernization.
  • Provide architectural oversight for major enterprise security initiatives, ensuring scalability, interoperability, governance alignment, and reduced fragmentation.
  • Partner with Security Engineering, GRC, Cloud Security, IT, Product Security, and IAM teams to align technical security capabilities while maintaining clear domain boundaries.
  • Identify architectural gaps, capability overlaps, and opportunities to streamline enterprise security investments.
  • Help shape long-term strategy for enterprise security capabilities, including emerging needs related to AI security, automation, infrastructure modernization, and operational resilience.
  • Support security tooling strategy by evaluating architectural fit, integration models, and long-term scalability of enterprise security platforms.
  • Establish and maintain enterprise security design documentation, architecture diagrams, reference standards, and technical governance artifacts.
  • Guide enterprise security maturity by aligning architecture to frameworks such as Zero Trust, NIST CSF, ISO 27001, SOX, SOC 2, and broader operational resilience objectives.
  • Serve as a strategic advisor to Enterprise Security leadership on architecture, maturity, organizational scaling, and strategic technical investments.
  • Support Enterprise Security leadership with strategic technical narratives that improve executive and business understanding of enterprise security investments.

Required Qualifications

  • 10+ years of professional experience in Information Security, Enterprise Architecture, Security Engineering, or related technical leadership capacities.
  • 5+ years specifically focused on designing enterprise-scale security architectures across diverse domains, including endpoint, network, infrastructure, vulnerability management, resilience, and enterprise platforms.
  • Demonstrated success in developing enterprise security architecture strategies, reference architectures, and scalable technical standards.
  • Extensive technical depth in Zero Trust principles, enterprise security frameworks, and modern backend or enterprise security architecture design patterns.
  • Comprehensive knowledge of core enterprise security domains, including endpoint security, network security, PKI, enterprise vulnerability management, resilience, data protection, and governance integration.
  • Proven ability to translate governance, compliance, and strategic business requirements into actionable technical architecture and implementation guidance.
  • Experience representing security interests within architecture review boards, governance committees, or enterprise-wide design councils.
  • Advanced familiarity with enterprise infrastructure, SaaS ecosystems, internal platforms, and the strategic integration of security tooling.
  • Adept at evaluating technical tradeoffs, identifying scalability constraints, and assessing the long-term implications of enterprise security architecture decisions.
  • Exceptional documentation skills, including the creation of detailed architecture diagrams, technical standards, and strategic narratives for executive leadership.
  • Proven capacity to influence technical and business stakeholders across multifaceted cross-functional teams.
  • Strong strategic mindset, complex problem-solving abilities, and a track record of organizational leadership.

Desirable Qualificationsย 

  • Direct experience in the automotive industry.
  • Knowledge of enterprise architecture committee structures and multifaceted cross-functional governance models.
  • Expert-level knowledge on AI security, security automation, or enterprise-scale modernization initiatives.
  • Relevant security and architecture certifications (such as CISSP, SABSA, TOGAF, or equivalent) are a plus but not required.

The base salary range for this position is $171,000-$273,000 per year.ย  Aurora's pay ranges are determined by role, level, and location. Within the range, the successful candidate's starting base pay will be determined based on factors including job-related skills, experience, qualifications, relevant education or training, and market conditions. These ranges may be modified in the future. The successful candidate will also be eligible for an annual bonus, equity compensation, and benefits.

ย #LI-KW1