Senior Security Code Reviewer
$120K - $164K/yr
... Review application architecture, source code, dependencies, infrastructure-as code, and deployment practices. • Support secure coding standards, developer security training, and technical ...
$120K - $164K/yr
... Review application architecture, source code, dependencies, infrastructure-as code, and deployment practices. • Support secure coding standards, developer security training, and technical ...
$120K - $164K/yr
... Review application architecture, source code, dependencies, infrastructure-as code, and deployment practices. • Support secure coding standards, developer security training, and technical ...
Camp Springs, MD · On-site
$120K - $164K/yr
Review application architecture, source code, dependencies, infrastructure-as-code, and deployment practices. * Support secure coding standards, developer security training, and technical remediation ...
Camp Springs, MD · On-site
$120K - $164K/yr
Review application architecture, source code, dependencies, infrastructure-as-code, and deployment practices. * Support secure coding standards, developer security training, and technical remediation ...
$120K - $164K/yr
Review application architecture, source code, dependencies, infrastructure-as-code, and deployment practices. * Support secure coding standards, developer security training, and technical remediation ...
$120K - $164K/yr
Review application architecture, source code, dependencies, infrastructure-as-code, and deployment practices. * Support secure coding standards, developer security training, and technical remediation ...
$120K - $164K/yr
Review application architecture, source code, dependencies, infrastructure-as-code, and deployment practices. * Support secure coding standards, developer security training, and technical remediation ...
Quick apply
$120K - $164K/yr
Review application architecture, source code, dependencies, infrastructure-as-code, and deployment practices. * Support secure coding standards, developer security training, and technical remediation ...
... Engineer to join their Product Security team. This role focuses on ensuring the security and ... Required : • Conduct in-depth code reviews to identify and remediate security vulnerabilities ...
... Engineer to join their Product Security team. This role focuses on ensuring the security and ... Required : • Conduct in-depth code reviews to identify and remediate security vulnerabilities ...
Arlington, VA · On-site
$131K - $180K/yr
The Product Security Team within CPSS supports a large number of applications built using AWS ... Code Review, primarily in Java, Python and Javascript - Development of security automation tools ...
Arlington, VA · On-site
$131K - $180K/yr
The Product Security Team within CPSS supports a large number of applications built using AWS ... Code Review, primarily in Java, Python and Javascript - Development of security automation tools ...
... code reviews and implementing security best practices. Responsibilities : • Leverage broad ... Engineer with a focus on product security. • Proficiency in NodeJS, TypeScript, Python, and/or ...
... code reviews and implementing security best practices. Responsibilities : • Leverage broad ... Engineer with a focus on product security. • Proficiency in NodeJS, TypeScript, Python, and/or ...
Product Security Engineering * Design and implement secure software and hardware system ... Support secure development initiatives including code review, dependency management, secrets ...
Product Security Engineering * Design and implement secure software and hardware system ... Support secure development initiatives including code review, dependency management, secrets ...
Product Security Engineering * Design and implement secure software and hardware system ... Support secure development initiatives including code review, dependency management, secrets ...
Product Security Engineering * Design and implement secure software and hardware system ... Support secure development initiatives including code review, dependency management, secrets ...
You will conduct in-depth code reviews, implement security best practices, and influence the ... Proven experience as a Security Engineer with a focus on product security. * Proficiency in NodeJS ...
You will conduct in-depth code reviews, implement security best practices, and influence the ... Proven experience as a Security Engineer with a focus on product security. * Proficiency in NodeJS ...
Washington, DC · On-site
$66.50 - $89/hr
... code and design reviews of all internal and external software products. Work with application developers ensure adoption of security principals and best practices. 6. Provides direction and support ...
Washington, DC · On-site
$66.50 - $89/hr
... code and design reviews of all internal and external software products. Work with application developers ensure adoption of security principals and best practices. 6. Provides direction and support ...
$66.50 - $89/hr
... code and design reviews of all internal and external software products. Work with application developers ensure adoption of security principals and best practices. 6. Provides direction and support ...
$66.50 - $89/hr
... code and design reviews of all internal and external software products. Work with application developers ensure adoption of security principals and best practices. 6. Provides direction and support ...
Washington, DC · On-site
$175K - $210K/yr
As a Product Security Engineer you will play a key role in shaping how security works across our ... Review code and infrastructure to find and fix security risks. Help teams use secure patterns that ...
Quick apply
Washington, DC · On-site
$175K - $210K/yr
As a Product Security Engineer you will play a key role in shaping how security works across our ... Review code and infrastructure to find and fix security risks. Help teams use secure patterns that ...
... security code review in a common programming language (non-internship) experience - Knowledge of ... with AWS products and services - Experience performing security activities across one or more ...
... security code review in a common programming language (non-internship) experience - Knowledge of ... with AWS products and services - Experience performing security activities across one or more ...
Fort Washington, MD · Remote
$117K - $160K/yr
Hands-on certifications such as OSCP, GWAPT, GPEN, CISSP, or equivalent -- and/or public code ... reviewing applications, analyzing resumes, or assessing responses. These tools assist our ...
Quick apply
Fort Washington, MD · Remote
$117K - $160K/yr
Hands-on certifications such as OSCP, GWAPT, GPEN, CISSP, or equivalent -- and/or public code ... reviewing applications, analyzing resumes, or assessing responses. These tools assist our ...
... engineers, and technical leads. * Participate in architecture review boards, design forums, and ... as-code. * Knowledge of OWASP Top 10, OWASP API Security Top 10, OWASP ASVS, and Zero Trust ...
... engineers, and technical leads. * Participate in architecture review boards, design forums, and ... as-code. * Knowledge of OWASP Top 10, OWASP API Security Top 10, OWASP ASVS, and Zero Trust ...
Gaithersburg, MD · On-site +1
$103K - $165K/yr
... R&D Product Development Job Sub Function: R&D Software/Systems Engineering Job Category ... Performing software code reviews and design reviews with a cyber-lens. * Performing periodic risk ...
Gaithersburg, MD · On-site +1
$103K - $165K/yr
... R&D Product Development Job Sub Function: R&D Software/Systems Engineering Job Category ... Performing software code reviews and design reviews with a cyber-lens. * Performing periodic risk ...
$76K - $122K/yr
... reviews. Thenice to haves: * 8+ years in security engineering, detection engineering, or product ... Hands-on experience with threat detection logic, MITRE ATT&CK mapping, and detection-as-code ...
$76K - $122K/yr
... reviews. Thenice to haves: * 8+ years in security engineering, detection engineering, or product ... Hands-on experience with threat detection logic, MITRE ATT&CK mapping, and detection-as-code ...
Rockville, MD · On-site +1
$103K - $165K/yr
... R&D Product Development Job Sub Function: R&D Software/Systems Engineering Job Category ... Performing software code reviews and design reviews with a cyber-lens. * Performing periodic risk ...
Rockville, MD · On-site +1
$103K - $165K/yr
... R&D Product Development Job Sub Function: R&D Software/Systems Engineering Job Category ... Performing software code reviews and design reviews with a cyber-lens. * Performing periodic risk ...
Adelphi, MD · On-site +1
$103K - $165K/yr
... R&D Product Development Job Sub Function: R&D Software/Systems Engineering Job Category ... Performing software code reviews and design reviews with a cyber-lens. * Performing periodic risk ...
Adelphi, MD · On-site +1
$103K - $165K/yr
... R&D Product Development Job Sub Function: R&D Software/Systems Engineering Job Category ... Performing software code reviews and design reviews with a cyber-lens. * Performing periodic risk ...
| Aspect | Product Security Code Review Engineer | Software Security Engineer |
|---|---|---|
| Primary Focus | Reviewing and analyzing source code for security vulnerabilities in products | Designing and implementing security measures across software systems |
| Skills & Certifications | Secure coding, code review, security standards (e.g., OWASP), certifications like CSSLP | Security architecture, threat modeling, secure coding, certifications like CISSP |
| Work Environment | Collaborates with development teams during product development | Works on system-wide security strategies and architecture |
| Industry Usage | Common in product-based companies, especially in tech and cybersecurity | Found in organizations focusing on overall security infrastructure |
While both roles focus on security, the Product Security Code Review Engineer primarily reviews source code for vulnerabilities in specific products, whereas the Software Security Engineer develops and implements security strategies across software systems. The roles often overlap but differ in scope and focus.

$120K - $164K/yr
Other
Posted 11 days ago
Job Description
Ashburn is seeking a Senior Security Code Reviewer to support a federal cybersecurity
architecture opportunity. This Key Personnel role will lead application security testing,
secure code review, DevSecOps pipeline integration, secure development guidance, risk
assessments, and cloud/network security evaluation for a proposal opportunity.
Primary Responsibilities
• Conduct security code reviews and risk assessments for applications and
enterprise systems.
• Use application security testing tools to identify vulnerabilities and provide
remediation guidance.
• Integrate security testing into DevSecOps and CI/CD pipelines.
• Review application architecture, source code, dependencies, infrastructure-as
code, and deployment practices.
• Support secure coding standards, developer security training, and technical
remediation guidance.
• Evaluate and improve cloud, network, and enterprise system security.
• Provide technical writing, reporting, and mentoring to engineering and development
teams.
• Support federal cybersecurity compliance objectives and secure development
lifecycle requirements.
Qualifications
Required Qualifications
• Candidates must be willing and able to work as Ashburn W-2 employees. 1099 and
corp-to-corp arrangements are not permitted for these roles.
• DHS EOD / suitability is required.
• 10+ years of experience automating application security scanning processes, Zero
Trust integration, and data sanitization for Government or similarly complex
enterprise systems.
• Experience deploying and using Application Security Testing platforms such as
Checkmarx.
• Experience automating or supporting Zero Trust Network Access (ZTNA) and Secure
Web Gateway (SWG) solutions.
• Advanced security engineering experience across on-premises and cloud
environments.
• Experience implementing AWS security best practices, including VPC Flow Logs,
Security Lake, and audit monitoring.
• Experience building EKS clusters using Terraform and Kubernetes.
• Experience creating custom hardened AMI builds.
• Experience integrating network security tools such as Palo Alto, AlgoSec, Gigamon,
and Corelight.
• Experience reviewing, evaluating, and improving security of complex systems and
networks.
• Experience with vulnerability management, SIEM integrations, certificate
management, single sign-on implementations, and federal regulatory compliance.
• Demonstrated ability to lead security code reviews and conduct risk assessments.
• Experience developing OS hardening strategies, evaluating firewall policies, and
implementing enterprise infrastructure monitoring solutions.
• Strong technical writing, training, and mentoring skills.
• Ability to mentor development teams in secure coding practices and align technical
solutions to Government cybersecurity objectives.
Preferred / Strongly Desired Qualifications
• Experience with Burp Suite, Checkmarx One, PortSwigger, SonarQube, Fortify, SAST,
DAST, SCA, API security testing, or IaC scanning.
• Experience integrating application security testing into CI/CD pipelines.
• Experience with secure coding practices in Java, Python, JavaScript, C#, Ruby, SQL,
React, Node.js, PowerShell, Go, or similar languages.
• Experience applying OWASP, NIST, DHS, DevSecOps, and secure software lifecycle
practices.
• Secure software certification preferred, such as CSSLP, GIAC secure software
credential, EC-Council secure programmer certification, or comparable experience.
• Prior DHS, DOD / DOW or federal application security experience.
Sourced by ZipRecruiter
Computer networking
51 - 200 Employees
Fairfax, VA, US
2002