1

Product Security Code Review Engineer Jobs (NOW HIRING)

The Senior Product Security Engineer is a highly skilled practitioner who drives hands-on security ... Lead manual and automated code review efforts to discover vulnerabilities, weaknesses, and anti ...

Senior Product Security Engineer

$117K - $160K/yr

... and review security-critical code across key parts of the product, including authentication and ... for the engineers • Drive mitigation during security-related incidents, working cross ...

... Code Review, Threat Assessment etc.) Security Testing standards and checklist , 12+ Years of ... products Experience with enterprise SSO and familiarity with OAuth, SAML, etc. is preferred.

Mobility Application Security

Rancho Cordova, CA · On-site

$62.75 - $83.75/hr

... Code Review, Threat Assessment etc.) • Security Testing standards and checklist , 12+ Years of ... products • Experience with enterprise SSO and familiarity with OAuth, SAML, etc. is preferred.

Senior Product Security Engineer

$117K - $160K/yr

Lead security architecture reviews, secure code reviews, threat modeling, and application ... Serve as advisor to product and engineering on security risk, architectural trade-offs, and risk ...

Build a developer driven security program where there is tight integration with engineering ... Plan and perform product security assessments including architecture review threat modeling, code ...

Build a developer driven security program where there is tight integration with engineering ... Plan and perform product security assessments including architecture review threat modeling, code ...

New

Showing results 21-40

Product Security Code Review Engineer information

See salary details

$53K

$144.1K

$205K

How much do product security code review engineer jobs pay per year?

As of Aug 6, 2026, the average yearly pay for product security code review engineer in the United States is $144,072.00, according to ZipRecruiter salary data. Most workers in this role earn between $88,000.00 and $205,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a product security code review engineer?

To thrive as a Product Security Code Review Engineer, you need a deep understanding of secure coding practices, software development lifecycles, and vulnerability assessment, typically backed by a degree in computer science or a related field. Familiarity with static and dynamic analysis tools, code review platforms, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for explaining security findings and collaborating with development teams. These skills and qualities are vital to identify, communicate, and mitigate security risks in code, ensuring the overall resilience of software products.

What are some typical challenges faced by product security code review engineers when coordinating with development teams?

Product Security Code Review Engineers often encounter challenges in balancing security priorities with project timelines and developer workflows. Effective communication is essential, as engineers must clearly explain vulnerabilities and remediation steps to developers who may have varying levels of security expertise. Additionally, they need to ensure that security recommendations are practical and align with the product's architecture, all while fostering a collaborative environment rather than creating bottlenecks. Building strong relationships with development teams and understanding their processes helps streamline secure code adoption and continuous improvement.

What is the difference between Product Security Code Review Engineer vs Software Security Engineer?

AspectProduct Security Code Review EngineerSoftware Security Engineer
Primary FocusReviewing and analyzing source code for security vulnerabilities in productsDesigning and implementing security measures across software systems
Skills & CertificationsSecure coding, code review, security standards (e.g., OWASP), certifications like CSSLPSecurity architecture, threat modeling, secure coding, certifications like CISSP
Work EnvironmentCollaborates with development teams during product developmentWorks on system-wide security strategies and architecture
Industry UsageCommon in product-based companies, especially in tech and cybersecurityFound in organizations focusing on overall security infrastructure

While both roles focus on security, the Product Security Code Review Engineer primarily reviews source code for vulnerabilities in specific products, whereas the Software Security Engineer develops and implements security strategies across software systems. The roles often overlap but differ in scope and focus.

What is a product security code review engineer?

A Product Security Code Review Engineer is a cybersecurity professional responsible for analyzing and reviewing application source code to identify and mitigate security vulnerabilities. They work closely with development teams to ensure secure coding practices, review code for compliance with security standards, and recommend fixes for potential security issues. Their goal is to prevent security breaches by catching vulnerabilities early in the software development lifecycle.
More about Product Security Code Review Engineer jobs
What cities are hiring for Product Security Code Review Engineer jobs? Cities with the most Product Security Code Review Engineer job openings:
What states have the most Product Security Code Review Engineer jobs? States with the most job openings for Product Security Code Review Engineer jobs include:
What job categories do people searching Product Security Code Review Engineer jobs look for? The top searched job categories for Product Security Code Review Engineer jobs are:
Infographic showing various Product Security Code Review Engineer job openings in the United States as of August 2026, with employment types broken down into 79% Full Time, 17% Part Time, 3% Contract, and 1% Nights. Highlights an 90% Physical, 2% Hybrid, and 8% Remote job distribution, with an average salary of $144,072 per year, or $69.3 per hour.

Security Engineer, Correlation and Response, AWS Security Hub

Amazon

Boston, MA • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 9 days ago


Amazon rating

7.4

Company rating: 7.4 out of 10

Based on 7,062 frontline employees who took The Breakroom Quiz

6th of 39 rated national retailers


Job description

Are you excited about advancing the state of threat detection, correlation and response at scale to mitigate risk from an ever-evolving threat landscape for a diverse range of customers?
The AWS Security Hub team is looking for a highly motivated Security Engineer to join our team. In this role, you will research emerging threats to develop new criticality and posture management ideas and build high-confidence markers and rules that correlate criticality across a diverse set of conditions from large-scale data sources. You will work closely with engineering and product teams to shape the analysis, context and inference that drive visibility into the most critical threats and vulnerabilities for AWS customers operating on AWS and other cloud providers. You will also develop innovative methods utilizing the latest techniques to analyze detections at scale. Your expertise will help defend the data of Amazon's millions of customers against the most critical threats.
Key job responsibilities
Basic qualifications
- Experience evaluating threats and vulnerabilities, assigning criticality based on impact, and developing response automation
- Experience scripting with Python, Perl, Bash or PowerShell
- Experience with software development for the cloud using java and AWS Developer Tools
- Knowledge of web protocols, common attacks, and Linux/Unix tools and architecture
- Knowledge of cloud computing concepts and design considerations for AWS, Azure and GCP
- 2+ years of non academic experience in any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
Preferred qualifications
- Experience with Machine Learning and Large Language Model fundamentals, including architecture, training/inference lifecycles, and optimization of model execution, or experience leading and influencing your team or organization
- Experience using AI to automate security assessment work flows, implement LLMs and perform agentic threat detection and remediation
- Experience with AI-driven development and verification
A day in the life
Most days you'll be heads-down building and tuning evaluations, digging into resource analysis and log data to figure out what data markers looks like and how to reliably assess impact. You'll spend time reading up on the latest threats and turning that research into something actionable. You'll also work on advancing how we assess threats, whether that's prototyping new approaches using machine learning or generative AI, improving enrichment pipelines, or finding ways to scale what we do. It's a mix of deep technical work and close collaboration with security teams across the organization.
About the team
At AWS Security Hub, security is central to maintaining customer trust and protecting customer cloud environments. Our organization is responsible for creating and maintaining a high bar for security analysis across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of customer environments.
BASIC QUALIFICATIONS
- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
- 2+ years of scripting, programming, and security code review in a common programming language (non-internship) experience
- 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience
- Bachelor's degree in computer science or equivalent
- Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or experience in IT Security
- Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or 2+ years of IT Security experience
- Knowledge of networking protocols such as HTTP, DNS and TCP/IP
- Knowledge of industry-based security vulnerabilities and remediation techniques
- Experience in scripting, programming, and security code reviewing in a common programming language (non-internship)
- Experience in troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship experience)
PREFERRED QUALIFICATIONS
- 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- 2+ years of scripting, programming, or security code review in a common language, such as Python, Java or C++ experience
- Knowledge of command line tools to troubleshoot protocols, analyze log outputs, or automate basic tasks
- Knowledge of networking protocols such as HTTP(S), DNS, and TCP/IP
- Knowledge of networking protocols, to include HTTP(S), DNS, and TCP/IP
- Experience with AWS products and services
- Experience with programming languages such as Python, Java, C++
- Experience in scripting, programming, or security code reviewing in a common language, such as Python, Java, or C++
- Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner.
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, MA, Boston - 159,300.00 - 202,400.00 USD annually
USA, WA, Seattle - 159,300.00 - 202,400.00 USD annually

What Amazon employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Amazon logo

About Amazon

Sourced by ZipRecruiter

Amazon.com, Inc., commonly known as Amazon, is an American multinational technology company. It was founded by Jeff Bezos in 1994 and initially started as an online marketplace for books. Since then, Amazon has expanded its operations and become one of the largest e-commerce companies in the world. Amazon's primary business is its online retail platform, where customers can purchase a vast array of products, including electronics, clothing, books, home goods, and much more. The company offers a convenient and user-friendly shopping experience, with features such as fast shipping, customer reviews, and personalized recommendations. In addition to its e-commerce platform, Amazon has diversified its business into various other areas. One of its notable ventures is Amazon Web Services (AWS), a comprehensive cloud computing platform that provides services such as storage, compute power, and database management to individuals and businesses. AWS has become a leader in the cloud computing industry, powering many websites and applications worldwide. Amazon has also developed its own consumer electronics, including the popular Amazon Kindle e-reader, Fire tablets, Fire TV streaming devices, and the Alexa-powered Echo smart speakers. The Alexa voice assistant, integrated into these devices, allows users to interact with their devices using voice commands, perform tasks, and access information. Furthermore, Amazon has expanded into media and entertainment. It operates Prime Video, a streaming service that offers a wide range of movies, TV shows, and original content. Amazon Music provides a platform for streaming and purchasing digital music, while Audible offers audiobooks and other audio content. The company's commitment to customer satisfaction and convenience is demonstrated by its membership program, Amazon Prime. Prime members receive various benefits, including free two-day shipping, access to streaming services, exclusive deals, and more.

Industry

It services, book publishers, retail, real estate and computer and electronic product manufacturing

Company size

10,000+ Employees

Headquarters location

Seattle, WA, US