1

Product Security Code Review Engineer Jobs (NOW HIRING)

Security Architect

San Jose, CA · On-site

$76.25 - $98.50/hr

This includes threat modeling, security testing, penetration testing, security code reviews, and ... Work across SW/HW engineering, production, and operations teams and ODM/OEM to identify component ...

OR · On-site

$114K - $156K/yr

The Senior Product Security Engineer is a highly skilled practitioner who drives hands-on security ... Lead manual and automated code review efforts to discover vulnerabilities, weaknesses, and anti ...

... coding practices and knowledge of cryptographic tools and libraries. The candidate can review ... Security Engineering (10%) * Support product teams with guidance and recommendations for ...

The Role We're seeking a Senior Product Security Engineer who is passionate about building and ... Experience leveraging AI and automation to scale security programs (e.g., LLM-assisted code review ...

New

... code review in a common language, such as Python, Java or C++ experience - Experience with AWS products and services - Experience in scripting, programming, or security code reviewing in a common ...

Senior Product Security Engineer Remote • Full-Time • Engineering About Cherry Founded in 2019 ... coding standards, vulnerability management, and security testing processes. * Lead security reviews ...

About the Role We are looking for a Product Security Architect to serve as the subject matter ... Code Review: Apply a strong programming background (Python/Go/JavaScript) to perform hands-on code ...

next page

Showing results 1-20

Product Security Code Review Engineer information

See salary details

$53K

$144.1K

$205K

How much do product security code review engineer jobs pay per year?

As of Jun 5, 2026, the average yearly pay for product security code review engineer in the United States is $144,072.00, according to ZipRecruiter salary data. Most workers in this role earn between $88,000.00 and $205,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Product Security Code Review Engineer, and why are they important?

To thrive as a Product Security Code Review Engineer, you need a deep understanding of secure coding practices, software development lifecycles, and vulnerability assessment, typically backed by a degree in computer science or a related field. Familiarity with static and dynamic analysis tools, code review platforms, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for explaining security findings and collaborating with development teams. These skills and qualities are vital to identify, communicate, and mitigate security risks in code, ensuring the overall resilience of software products.

What are some typical challenges faced by Product Security Code Review Engineers when coordinating with development teams?

Product Security Code Review Engineers often encounter challenges in balancing security priorities with project timelines and developer workflows. Effective communication is essential, as engineers must clearly explain vulnerabilities and remediation steps to developers who may have varying levels of security expertise. Additionally, they need to ensure that security recommendations are practical and align with the product's architecture, all while fostering a collaborative environment rather than creating bottlenecks. Building strong relationships with development teams and understanding their processes helps streamline secure code adoption and continuous improvement.

What is a Product Security Code Review Engineer?

A Product Security Code Review Engineer is a cybersecurity professional responsible for analyzing and reviewing application source code to identify and mitigate security vulnerabilities. They work closely with development teams to ensure secure coding practices, review code for compliance with security standards, and recommend fixes for potential security issues. Their goal is to prevent security breaches by catching vulnerabilities early in the software development lifecycle.

What is the difference between Product Security Code Review Engineer vs Software Security Engineer?

AspectProduct Security Code Review EngineerSoftware Security Engineer
Primary FocusReviewing and analyzing source code for security vulnerabilities in productsDesigning and implementing security measures across software systems
Skills & CertificationsSecure coding, code review, security standards (e.g., OWASP), certifications like CSSLPSecurity architecture, threat modeling, secure coding, certifications like CISSP
Work EnvironmentCollaborates with development teams during product developmentWorks on system-wide security strategies and architecture
Industry UsageCommon in product-based companies, especially in tech and cybersecurityFound in organizations focusing on overall security infrastructure

While both roles focus on security, the Product Security Code Review Engineer primarily reviews source code for vulnerabilities in specific products, whereas the Software Security Engineer develops and implements security strategies across software systems. The roles often overlap but differ in scope and focus.

More about Product Security Code Review Engineer jobs
What cities are hiring for Product Security Code Review Engineer jobs? Cities with the most Product Security Code Review Engineer job openings:
What states have the most Product Security Code Review Engineer jobs? States with the most job openings for Product Security Code Review Engineer jobs include:
What job categories do people searching Product Security Code Review Engineer jobs look for? The top searched job categories for Product Security Code Review Engineer jobs are:
Security Architect

$76.25 - $98.50/hr

Contractor

Posted 9 days ago


Job description

Title: Security Architect
Location: San Jose, CA
Duration: 6-9 Months Contract to Hire
Responsibilities:
  • Define security requirements and checklist for IoT platforms.
  • Champion the Client's product security SDLC. This includes threat modeling, security testing, penetration testing, security code reviews, and secure design/architecture reviews, and identifying and fixing vulnerabilities in software and applications.
  • Perform vulnerability research, assessment and management, serve as technical security/risk advisor on all new technology/developed by the Client.
  • Provide architectural guidance and leadership on best practices regarding security in software development, IoT platform, mobile application, user interface design frameworks, high performance messaging solutions, server-side development, integrations and tools and technologies.
  • Work across SW/HW engineering, production, and operations teams and ODM/OEM to identify component and system level security risks, determine technical security controls to mitigate risks, prioritize and schedule controls with product development timelines.
  • Work with corporate security governance team to comply with internal SLA and policies.
  • Mentor junior Security Engineers.
  • Maintain knowledge of current and emerging technologies / products / trends related to security architectural solutions.

  • Requirements
    Qualifications:
  • 12+ years of experience in security research, product security, and/or software engineering.
  • Demonstrated expertise in cryptographic algorithms and protocols.
  • Demonstrated expertise in network protocols.
  • Demonstrated expertise in end-to-end software architecture.
  • Proficiency in programming languages - Java, C/C++.
  • Proficiency in Secure Boot and Trusted Execution Environment (TEE).
  • Ability to present complex security topics to wide range of internal and internal audiences (engineers to executives).
  • Strong project planning and execution skills.
  • Excellent written & oral communication skills and coordination with peers, end-users, and management.
  • Good analytical and debugging skills; creative ability, good organizational skills.

  • Preferred:
  • CISSP or equivalent certification.
  • Proficiency in audio and video streaming protocols.

  • TWO95 International logo

    About TWO95 International

    Sourced by ZipRecruiter

    At TWO95 International, we believe it is imperative that a hiring company is assured of procuring the right candidate to fill a job requirement. We have an extensive local and International network, and a fully digitalized sourcing approach that allows us to find a candidate best suited for the job. Furthermore, we strive to secure well matched opportunities that align with the personal and career aspirations of our candidates.

    Industry

    Recruiting and staffing services

    Company size

    11 - 50 Employees

    Headquarters location

    Cherry Hill, NJ, US

    Year founded

    2009

    Social media