1

Product Security Code Review Engineer Jobs (NOW HIRING)

Application Security Engineer

Washington, DC · On-site

$66.50 - $89/hr

... code and design reviews of all internal and external software products. Work with application developers ensure adoption of security principals and best practices. 6. Provides direction and support ...

Senior Security Engineer

San Francisco, CA · On-site

$134K - $185K/yr

... product engineering teams to integrate security throughout the software development lifecycle, from ... code reviews and architecture assessments for new features, with special focus on AI model ...

Own and review security-critical code across key parts of the product, including authentication and ... Mentor engineers and raise the security bar across teams through code reviews, design reviews, and ...

Senior Application Security Engineer

Broomfield, CO · On-site

$59.25 - $79/hr

Programming Languages (Ruby, Go, Rust, JavaScript), Cloud Armor WAF, Static Application Security ... code reviews of new features and bug fixes • Complete security assessments of new products ...

Staff Application Security Engineer

$60.25 - $80.25/hr

You will write code, review code, build tooling, and lead the technically hardest work across ... Product Security * Engineer enterprise SSO (SAML 2.0 and OpenID Connect) into customer-facing ...

Application Security Engineer

Washington, DC · On-site

$66.50 - $89/hr

... code and design reviews of all internal and external software products. Work with application developers ensure adoption of security principals and best practices. 6. Provides direction and support ...

We are looking for a mission-driven Product Security Engineer to embed security into the entire ... for design, code review, CI/CD, and release. Each feature will include measurable security ...

We're hiring a Product Security Lead to drive how we build security into the platform. The work ... code review, threat modeling, detection engineering, and security tooling. * Excellent written ...

New

They are seeking a mission-driven Product Security Engineer to embed security into the lifecycle of ... design, code review, CI/CD, and release processes. • Develop secure firmware and update ...

Sr/Staff Security Engineer

$117K - $160K/yr

Partner with product and engineering teams to perform security design reviews and threat modeling ... Own and evolve Cherry's product security program - including secure coding standards, vulnerability ...

... Security as Code solutions. • Provide training, guidance, and assistance to development teams ... Required : • Proven experience performing threat modeling and architecture reviews for complex ...

Product Security Engineer

San Francisco, CA · On-site +1

$187K - $260K/yr

Join Airtable as a Product Security Engineer and play a pivotal role in shaping the security of our ... You are proficient in writing and reviewing code and treat security as an engineering problem to be ...

Product Security Engineer

Seattle, WA · Remote

$187K - $260K/yr

Join Airtable as a Product Security Engineer and play a pivotal role in shaping the security of our ... You are proficient in writing and reviewing code and treat security as an engineering problem to be ...

Product Security Engineer

New York, NY · On-site

$175K - $210K/yr

As a Product Security Engineer you will play a key role in shaping how security works across our ... Review code and infrastructure to find and fix security risks. Help teams use secure patterns that ...

next page

Showing results 1-20

Product Security Code Review Engineer information

See salary details

$53K

$144.1K

$205K

How much do product security code review engineer jobs pay per year?

As of Jun 27, 2026, the average yearly pay for product security code review engineer in the United States is $144,072.00, according to ZipRecruiter salary data. Most workers in this role earn between $88,000.00 and $205,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Product Security Code Review Engineer, and why are they important?

To thrive as a Product Security Code Review Engineer, you need a deep understanding of secure coding practices, software development lifecycles, and vulnerability assessment, typically backed by a degree in computer science or a related field. Familiarity with static and dynamic analysis tools, code review platforms, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for explaining security findings and collaborating with development teams. These skills and qualities are vital to identify, communicate, and mitigate security risks in code, ensuring the overall resilience of software products.

What are some typical challenges faced by Product Security Code Review Engineers when coordinating with development teams?

Product Security Code Review Engineers often encounter challenges in balancing security priorities with project timelines and developer workflows. Effective communication is essential, as engineers must clearly explain vulnerabilities and remediation steps to developers who may have varying levels of security expertise. Additionally, they need to ensure that security recommendations are practical and align with the product's architecture, all while fostering a collaborative environment rather than creating bottlenecks. Building strong relationships with development teams and understanding their processes helps streamline secure code adoption and continuous improvement.

What is the difference between Product Security Code Review Engineer vs Software Security Engineer?

AspectProduct Security Code Review EngineerSoftware Security Engineer
Primary FocusReviewing and analyzing source code for security vulnerabilities in productsDesigning and implementing security measures across software systems
Skills & CertificationsSecure coding, code review, security standards (e.g., OWASP), certifications like CSSLPSecurity architecture, threat modeling, secure coding, certifications like CISSP
Work EnvironmentCollaborates with development teams during product developmentWorks on system-wide security strategies and architecture
Industry UsageCommon in product-based companies, especially in tech and cybersecurityFound in organizations focusing on overall security infrastructure

While both roles focus on security, the Product Security Code Review Engineer primarily reviews source code for vulnerabilities in specific products, whereas the Software Security Engineer develops and implements security strategies across software systems. The roles often overlap but differ in scope and focus.

What is a Product Security Code Review Engineer?

A Product Security Code Review Engineer is a cybersecurity professional responsible for analyzing and reviewing application source code to identify and mitigate security vulnerabilities. They work closely with development teams to ensure secure coding practices, review code for compliance with security standards, and recommend fixes for potential security issues. Their goal is to prevent security breaches by catching vulnerabilities early in the software development lifecycle.
More about Product Security Code Review Engineer jobs
What cities are hiring for Product Security Code Review Engineer jobs? Cities with the most Product Security Code Review Engineer job openings:
What states have the most Product Security Code Review Engineer jobs? States with the most job openings for Product Security Code Review Engineer jobs include:
What job categories do people searching Product Security Code Review Engineer jobs look for? The top searched job categories for Product Security Code Review Engineer jobs are:
Application Security Engineer

Application Security Engineer

Eliassen Group

Washington, DC • On-site

$66.50 - $89/hr

Full-time

Posted 14 days ago


Job description

Company Description
Demonstrate your expertise and challenge your skills in this exciting IT Security Engineering opportunity! We are seeking an experienced IT Security Engineer for a lead role within our Security Team in our Washington DC IT Department. In this role, you will provide IT security support for applications and software systems in all platforms as well as providing security support to all systems in production, staging and development environments. This Security Engineer role will work closely with Washington DC IT departments and ensures the security and protection of organizational information assets including data, applications, systems, databases, networks, and other resources. We offer a competitive salary and comprehensive benefits, making this a great opportunity for an experienced IT Security Engineer, like you, to take their IT career to the next level!
Job Description
1. Security Engineer works on defining security frameworks for existing and new systems.
2. Represents the IT security team for enterprise projects during development phases like architecture/design review, providing IT security consulting and recommendations, to ensure the implementation of a secure application design.
3. Responsible for supporting the implementation and enforcement of secure application design principles
4. Responsible for explaining and demonstrating vulnerabilities to application/system owners, and provide recommendations for mitigation.
5. Responsible for defining and designing security code analysis tools and framework, Performing code and design reviews of all internal and external software products. Work with application developers ensure adoption of security principals and best practices.
6. Provides direction and support in security management and security architecture standards and documentations.
7. Provides fault resolution and escalation advice.
8. Responsible for defining processes to manage and enforce application security.
9. Conducts active penetration tests; discover vulnerabilities in information systems.
10. Participate in IT security compliance and audit efforts (eg PCI DSS )
Qualifications
• College degree (relevant field) or equivalent experience; 3-5 years of work experience.
• 2+ years of experience in web application development in .NET, Java EE, and SQL
• 1+ years of experience in web or mobile application security preferred
• HTTP protocol knowledge required
• Knowledge of authentication mechanisms like SAML, OAuth etc. along with web service security protocols for SOAP such as WS-Security are nice to have
• Knowledge of information security principles, web applications and a level of familiarity with malicious code and common techniques used by hackers
• Experience with application security code review practices / static analysis and methods, such as OWASP Top Ten
• Detailed knowledge and understanding of the Payment Card Industry (PCI) data security standards (PCI DSS) as well as experience in the implementation of controls to mitigate PCI issues
• Experience with Application Security Firewalls, F5' ASM / Citrix's Teros etc are desirable
• Experience in creating, maintaining, and executing Incident Response Plans
• Strong interpersonal and communications skills along with strong customer service skills
• Strong programming background with: JavaScript, JSP, PHP, ASP.Net strongly preferred
• Knowledge of Security Flaws and its Resolution as listed in sites like OWASP, SANS etc.
• Knowledge and understanding of network and web related protocols (e.g., TCP/IP, UDP, IPSEC, DNS, LTM, GTM) preferred
• Experience in technical security countermeasures, risk management, contingency planning, and data communications networking preferred
Additional Information
All your information will be kept confidential according to EEO guidelines.
http://www.eliassen.com/consulting-services-consultant/agile-consulting-services

Eliassen Group logo

About Eliassen Group

Sourced by ZipRecruiter

Eliassen Group provides strategic consulting and talent solutions to drive our clients' innovation and business results. Our purpose is to positively impact the lives of our employees, clients, consultants, and the communities in which we operate. Leveraging over 30 years of success, our expertise in talent solutions, life sciences consulting, Agile consulting, cloud services, risk management, business optimization, and managed services enables us to partner with our clients to execute their business strategy and scale effectively. Headquartered in Reading, MA, and with offices from coast to coast, Eliassen Group offers local community presence and deep networks, as well as national reach.

Industry

It services

Company size

5,001 - 10,000 Employees

Headquarters location

Reading, MA, US

Year founded

1989