1

Product Security Code Review Engineer Jobs in Boston, MA

Senior Product Security Engineer

Boston, MA · On-site

$124K - $170K/yr

We are seeking a Senior Product Security Engineer to join our Platform team. In this role, you will ... Identify security risks through architecture reviews, threat modeling, code review, and hands-on ...

Sr. Product Security Engineer II

Burlington, MA · Remote

$124K - $170K/yr

The Senior Product Security Engineer, based in Burlington Massachusetts, is a critical, high-level ... reviews, secure coding, peer review criteria, and security gates for releases. * Work with IEC ...

Sr. Product Security Engineer II

Burlington, MA · On-site

$124K - $170K/yr

The Senior Product Security Engineer, based in Burlington Massachusetts, is a critical, high-level ... reviews, secure coding, peer review criteria, and security gates for releases. * Work with IEC ...

... team of mariners, engineers, coders, and autonomy scientists. Sea Machiners get the unique ... Job Summary We are seeking a Product Security Engineer with strong networking expertise to secure ...

Sr. Product Security Engineer II

Burlington, MA · Remote

$124K - $170K/yr

The Senior Product Security Engineer, based in Burlington Massachusetts, is a critical, high-level ... reviews, secure coding, peer review criteria, and security gates for releases. * Work with IEC ...

... team of mariners, engineers, coders, and autonomy scientists. Sea Machiners get the unique ... Job Summary We are seeking a Product Security Engineer with strong networking expertise to secure ...

... and a low-code development platform. Our platform and PLM applications connect users in all ... Feedback from our community has established Aras as the top ranked PLM vendor in online review ...

Work closely with the software development team to ensure that secure coding practices are ... Proven experience as an Application Security Engineer or similar role. * Strong understanding of ...

Senior Cybersecurity Engineer

Boston, MA · Remote

$124K - $170K/yr

Provide product security support, including secure design review, threat modeling for sensitive ... Experience securing Kubernetes, containers, CI/CD pipelines, infrastructure-as-code, and modern ...

Senior Cybersecurity Engineer

Boston, MA · Remote

$165K - $185K/yr

Provide product security support, including secure design review, threat modeling for sensitive ... Experience securing Kubernetes, containers, CI/CD pipelines, infrastructure-as-code, and modern ...

Staff Application Security Engineer

Boston, MA · On-site

$63.75 - $85.25/hr

... production * Partner with engineering teams to prioritize and remediate critical threats, define API security standards, and conduct security code reviews. * Identify systemic security risks; lead ...

next page

Showing results 1-20

Product Security Code Review Engineer information

See Boston, MA salary details

$57.6K

$156.5K

$222.7K

How much do product security code review engineer jobs pay per year?

As of Jul 28, 2026, the average yearly pay for product security code review engineer in Boston, MA is $156,520.00, according to ZipRecruiter salary data. Most workers in this role earn between $95,600.00 and $222,700.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Product Security Code Review Engineer, and why are they important?

To thrive as a Product Security Code Review Engineer, you need a deep understanding of secure coding practices, software development lifecycles, and vulnerability assessment, typically backed by a degree in computer science or a related field. Familiarity with static and dynamic analysis tools, code review platforms, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for explaining security findings and collaborating with development teams. These skills and qualities are vital to identify, communicate, and mitigate security risks in code, ensuring the overall resilience of software products.

What are some typical challenges faced by Product Security Code Review Engineers when coordinating with development teams?

Product Security Code Review Engineers often encounter challenges in balancing security priorities with project timelines and developer workflows. Effective communication is essential, as engineers must clearly explain vulnerabilities and remediation steps to developers who may have varying levels of security expertise. Additionally, they need to ensure that security recommendations are practical and align with the product's architecture, all while fostering a collaborative environment rather than creating bottlenecks. Building strong relationships with development teams and understanding their processes helps streamline secure code adoption and continuous improvement.

What is the difference between Product Security Code Review Engineer vs Software Security Engineer?

AspectProduct Security Code Review EngineerSoftware Security Engineer
Primary FocusReviewing and analyzing source code for security vulnerabilities in productsDesigning and implementing security measures across software systems
Skills & CertificationsSecure coding, code review, security standards (e.g., OWASP), certifications like CSSLPSecurity architecture, threat modeling, secure coding, certifications like CISSP
Work EnvironmentCollaborates with development teams during product developmentWorks on system-wide security strategies and architecture
Industry UsageCommon in product-based companies, especially in tech and cybersecurityFound in organizations focusing on overall security infrastructure

While both roles focus on security, the Product Security Code Review Engineer primarily reviews source code for vulnerabilities in specific products, whereas the Software Security Engineer develops and implements security strategies across software systems. The roles often overlap but differ in scope and focus.

What is a Product Security Code Review Engineer?

A Product Security Code Review Engineer is a cybersecurity professional responsible for analyzing and reviewing application source code to identify and mitigate security vulnerabilities. They work closely with development teams to ensure secure coding practices, review code for compliance with security standards, and recommend fixes for potential security issues. Their goal is to prevent security breaches by catching vulnerabilities early in the software development lifecycle.
What are popular job titles related to Product Security Code Review Engineer jobs in Boston, MA? For Product Security Code Review Engineer jobs in Boston, MA, the most frequently searched job titles are:
What job categories do people searching Product Security Code Review Engineer jobs in Boston, MA look for? The top searched job categories for Product Security Code Review Engineer jobs in Boston, MA are:
Staff Security Engineer, Product Security And Architecture

Staff Security Engineer, Product Security And Architecture

Compass

Boston, MA

Other

Posted 5 days ago


Compass Real Estate rating

9.3

Company rating: 9.3 out of 10

Based on 7 frontline employees who took The Breakroom Quiz

5th of 200 rated real estate companies


Job description

About Compass International Holdings (CIH)

Compass International Holdings (CIH) is the largest residential real estate platform in the world, established by the January 2026 merger of Compass and Anywhere Real Estate. By bringing together the technology, brands, and agent networks that power residential real estate transactions across the United States and globally. CIH's mission is to help everyone find their place in the world - and to build the single software platform for all real estate activity, at a scale and complexity few technology companies ever operate at.

Security at Compass International Holdings

The Security organization protects one of the largest and most complex real estate technology estates in the industry. We are hands-on engineers who build security as a service: secure-by-design tooling, automated guardrails, and trusted partnership with Engineering, rather than gatekeeping. As a Staff Security Engineer, you are empowered to directly drive technical security results and shaping the roadmaps that our engineering teams adopt and build against.

What You Will Do

  • Automate & Scale Application Security: Build, enhance, and support automated application security testing frameworks and tooling to seamlessly integrate security into continuous integration and delivery (CI/CD) pipelines.
  • Drive Secure-by-Design Architectures: Partner closely with engineering teams to evaluate solution architectures and codebases, providing technical feedback that embeds secure-by-design principles from the start.
  • Serve as a Trusted Security Advisor: Act as a key resource and subject matter expert for product and engineering teams, offering security guidance and risk evaluations for new product features, development processes, tooling, and services.
  • Evangelize Product Security: Advocate for secure-by-design approaches across the organizations helping to mature the overall security culture.
  • Cultivate Collaboration: Build strong, collaborative relationships across the Product and Engineering organization to help product teams efficiently achieve their delivery goals without compromising on security.
  • Secure & Accelerate with AI: Drive the adoption of AI-powered security capabilities (e.g., code/IaC scanning copilots and automated triage) to foster operational efficiencies, while establishing a AI Security Posture Management (AI-SPM) frameworks and secure-by-design standards needed to safely integrate AI into CIH products and protect enterprise data assets from emerging threats (such as prompt injection, model/data exfiltration, and unsanctioned "shadow AI" usage).
  • Continuous Innovation: Stay ahead of industry trends, embracing and adopting new technologies to ensure security capabilities keep pace with evolving business and engineering objectives.

Who You Are

  • Strategic Collaborator: You thrive in Agile and DevOps environments, viewing security as an enabler of engineering velocity rather than a bottleneck.
  • Technical Leader & Advocate: You are passionate about mentoring others and can articulately champion security concepts to both deeply technical engineers and business stakeholders.
  • Analytical Problem Solver: You possess exceptional troubleshooting skills and the logical capacity to diagnose complex architectural and pipeline security challenges.
  • Self-Driven Achiever: You are highly self-motivated, with the organizational and time-management skills required to manage multiple complex initiatives simultaneously.

Minimum Qualifications

  • Bachelor's degree in Computer Science, a related technical field, or equivalent practical work experience.
  • Minimum of three (3) years of experience across the following areas:
    • Administering and configuring automated pipeline tools (CI/CD).
    • Administering and tuning application security testing tools (e.g., SAST, DAST, or SCA).
    • Automation scripting using Python or Bash.
    • Product development using Python, JavaScript, TypeScript, Golang, or Java.
    • Performing security code reviews for solutions built in Python, JavaScript, TypeScript, Golang, or Java.
    • Participating in security-focused reviews for both vendor and custom business solutions.
    • Hands-on experience with Infrastructure as Code (IaC) tools (e.g., Terraform) to provision secure, reproducible infrastructure.
    • Practical experience working with AWS services, aligning both product solution delivery and security objectives.
    • Hands-on experience using Artificial Intelligence (AI) to assist with product security processes to drive team and operational efficiencies.

Nice to Have 

  • Relevant industry certifications (e.g., CEH, CISSP, CSSLP, GIAC, or cloud security certifications) are a strong plus.
  • Direct experience working within high-performing DevOps and Agile cultures.
  • Experience with Layer 7 security controls (e.g., Web Application Firewalls (WAF), API Gateways, OAuth2/OIDC implementation, and rate limiting).
  • Experience driving secure-by-design practices across multi-cloud strategies (e.g., AWS, Azure, GCP).
  • Experience reviewing and assessing the use of AI technologies within both vendor-provided and custom-developed business solutions.
  • Experience operating in a publicly traded company, including familiarity with SOX-adjacent control environments and audit processes.
  • Experience securing environments through a merger, acquisition, or major infrastructure consolidation.

Compensation: The base pay range for this position is $210,000 - $234,100; however, base pay offered may vary depending on job-related knowledge, skills, and experience. Bonuses and restricted stock units may be provided as part of the compensation package, in addition to a full range of benefits. Base pay is based on market location. Minimum wage for the position will always be met


What Compass Real Estate employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom