1

Product Security Code Review Engineer Jobs in Washington

Staff Application Security Engineer

Washington, DC ยท On-site

$66.50 - $89/hr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Review application designs and code changes for security issues before they become production risk ... Partner with engineering teams to create paved roads: secure templates, checklists, automation ...

Staff Application Security Engineer

Washington, DC ยท On-site

$66.50 - $89/hr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Review application designs and code changes for security issues before they become production risk ... Partner with engineering teams to create paved roads: secure templates, checklists, automation ...

Senior Security Engineer NYC MIA

Sterling, VA ยท On-site

$180 - $210/hr

  • Retirement

  • PTO

Application and Product Security * Perform secure code reviews and provide handsโ€‘on application security support to engineering teams. * Review authentication flows, payment logic, and API security ...

AppSec Security Engineer

Arlington, VA ยท On-site

$67.50 - $90.25/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Infrastructure as Code: Develop secure IaC patterns using Terraform, Helm, and Kustomize. * Build ... Strong Threat modeling and security review experience with Product and Engineering teams

Senior Engineer, Application Security

Tysons, VA ยท On-site

$59.50 - $79.25/hr

Perform and lead deep secure design reviews, code reviews, threat modeling, and penetration testing ... Own product security for an assigned product area or portfolio - serve as the accountable security ...

You will embed security across the SDLC--from design and code review through CI/CD and cloud deployment--working alongside engineering, DevSecOps, and IT teams in a regulated, cloud-native ...

Showing results 21-40

Product Security Code Review Engineer information

What is a product security code review engineer?

A Product Security Code Review Engineer is a cybersecurity professional responsible for analyzing and reviewing application source code to identify and mitigate security vulnerabilities. They work closely with development teams to ensure secure coding practices, review code for compliance with security standards, and recommend fixes for potential security issues. Their goal is to prevent security breaches by catching vulnerabilities early in the software development lifecycle.

What are the key skills and qualifications needed to thrive as a product security code review engineer?

To thrive as a Product Security Code Review Engineer, you need a deep understanding of secure coding practices, software development lifecycles, and vulnerability assessment, typically backed by a degree in computer science or a related field. Familiarity with static and dynamic analysis tools, code review platforms, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for explaining security findings and collaborating with development teams. These skills and qualities are vital to identify, communicate, and mitigate security risks in code, ensuring the overall resilience of software products.

What are some typical challenges faced by product security code review engineers when coordinating with development teams?

Product Security Code Review Engineers often encounter challenges in balancing security priorities with project timelines and developer workflows. Effective communication is essential, as engineers must clearly explain vulnerabilities and remediation steps to developers who may have varying levels of security expertise. Additionally, they need to ensure that security recommendations are practical and align with the product's architecture, all while fostering a collaborative environment rather than creating bottlenecks. Building strong relationships with development teams and understanding their processes helps streamline secure code adoption and continuous improvement.

What is the difference between Product Security Code Review Engineer vs Software Security Engineer?

AspectProduct Security Code Review EngineerSoftware Security Engineer
Primary FocusReviewing and analyzing source code for security vulnerabilities in productsDesigning and implementing security measures across software systems
Skills & CertificationsSecure coding, code review, security standards (e.g., OWASP), certifications like CSSLPSecurity architecture, threat modeling, secure coding, certifications like CISSP
Work EnvironmentCollaborates with development teams during product developmentWorks on system-wide security strategies and architecture
Industry UsageCommon in product-based companies, especially in tech and cybersecurityFound in organizations focusing on overall security infrastructure

While both roles focus on security, the Product Security Code Review Engineer primarily reviews source code for vulnerabilities in specific products, whereas the Software Security Engineer develops and implements security strategies across software systems. The roles often overlap but differ in scope and focus.

What are popular job titles related to Product Security Code Review Engineer jobs in Washington?

For Product Security Code Review Engineer jobs in Washington, the most frequently searched job titles are:

What job categories do people searching Product Security Code Review Engineer jobs in Washington look for?

The top searched job categories for Product Security Code Review Engineer jobs in Washington are:

Infographic showing various Product Security Code Review Engineer job openings in Washington as of June 2026, with employment types broken down into 1% As Needed, 87% Full Time, 10% Part Time, and 2% Contract. Highlights an 90% Physical, 2% Hybrid, and 8% Remote job distribution.

Sr. Software Security Engineer

Alphalogic, Inc.

Reston, VA โ€ข On-site

Full-time

Re-posted 15 days ago


Job description

Company Description
Alphalogic is a global technology solutions company headquartered in the Washington, DC metropolitan area. Alphalogic offers a wide range of technology and consulting services; predictive analytics, data warehousing & BI, cloud consulting, web & mobile application development.
Cutting-edge Technologies
Our company's core competencies are cloud and mobile computing; healthcare solutions and services; data warehousing-analytics- business intelligence; and enterprise collaboration-content management. Alphalogic teams are continually deploying emerging technologies to meet our clients' current challenges.
Industry Best Practices
Alphalogic specializes in the effective use of industry-standard frameworks such Agile, for helping our clients achieve quick wins and reduce cycle times.
Job Description
The Senior Software Security Engineer will work within the software engineering organization to translate and define security requirements, use and mature practices for building secure applications; and suggest and support remediation activities for identified vulnerabilities. This position requires interest and expertise in defining and executing on a software engineering security practice; strong proven software development skills; expertise with major software infrastructures (J2EE, .NET, Oracle) and architectures (Web, SOA); an ability to build rapport and credibility with management and software development teams; and the ability to document and communicate the results of code reviews and penetration tests. Successful candidates must be action-oriented self-starters, capable of solving complex technical problems both independently and in a team environment. Candidates must also be able to communicate clearly and effectively to both technical and executive level audiences, both verbally and in written form.
  • Defines and mentors software engineering teams on processes that build security in, such as security related programming standards, use of APIs that support secure coding, code review, use of automated scanning tools, and penetration testing.
  • Works with software engineering teams and Enterprise Architecture (EA) to build out formal product security plans that put in place controls to build security in during the software development life cycle.
  • Stays current with emerging software security technologies, trends, and attack vectors, with a primary focus on internal reference architectures and security standards.
  • Performs/participates in architectural reviews that are meant to identify and remedy architectural security flaws.
  • Responsible for the use of security-related code analysis tools and takes the lead on tuning, enhancements, upgrades, and tool integration.
  • Develops threat models in conjunction with architects and software engineering staff.
  • Oversees the development of misuse/abuse cases in conjunction with requirements analysts.
  • Works with the Information Security Office on incident response and operational/strategic initiatives.

Qualifications
Qualifications
Education/Experience
Bachelor's Degree in a related field plus additional related college courses or professional training. Four to seven years of progressively responsible directly-related experience.
Related Skills & Other Requirements:
  • Strong and evolving competence in several programming languages and technologies, mastery of one or more tools sets, technologies, and implementation environments.
  • Advanced knowledge of programming languages, relational database management systems, networking technology, multiple desk operating systems and multiple server operating systems.
  • Must have strong knowledge in one or more of the following: HTML, JavaScript, DOM, AJAX, CSS/CSS2, XML, XHTML, DHTML, etc.
  • Must have adequate knowledge of J2EE and/or .NET technologies.
  • Experience writing automated unit tests.
  • Experience in performing code reviews.
  • Knowledge of TCP/IP, HTTP/S and other protocols.
  • Knowledge of cross-site scripting (XSS), session hijacking, SQL injection, CSRF (Cross-Site Request Forgery), OWASP Top 10, and other attack vectors a plus.
  • Knowledge of OWASP Web Security Certification Criteria, OWASP testing guidelines and PCI Data Security Standards is a plus.
  • Experience with one or more of the following tools is a plus: nmap, Nessus, Metasploit, TCPDump, Burp Suite, ZAProxy.
  • Experience with IBM AppScan Source Edition, IBM AppScan Standard, and/or HP Fortify is a plus.
  • Experience with the following source code repositories is a plus: SVN, GIT, IBM ClearCase
  • Any knowledge of one or more of the following is a plus -- Python, Ruby, PHP or other scripting languages.
  • Reverse engineering experience is a plus.
  • Protocol analysis and forensic analysis experience is a plus.
  • Experience installing, configuring and maintaining continuous integration (CI) environment(s) using tools such as Cruise Control, Cruise Control.NET, Hudson, Jenkins, Bamboo, Gauntlet, in a test driven development (TDD) process is a plus.
  • Experience with one or more of the following static analysis tools is a plus: FindBugs, FxCop, and PMD.
  • Additional certifications such as CISSP, CSSLP, CEH, ENCE, CCE, GCFA, GCIA, GCIH, CHFI and/or QSA are highly desired.

Additional Information
No C2C or Agency candidates. Local candidates are strongly encouraged to apply.