Perform in-depth security-focused code reviews across various codebases and languages * Identify ... Work closely with developers to educate and guide them in secure coding practices. * Recommend ...
Perform in-depth security-focused code reviews across various codebases and languages * Identify ... Work closely with developers to educate and guide them in secure coding practices. * Recommend ...
Perform in-depth security-focused code reviews across various codebases and languages * Identify ... Work closely with developers to educate and guide them in secure coding practices. * Recommend ...
Perform in-depth security-focused code reviews across various codebases and languages * Identify ... Work closely with developers to educate and guide them in secure coding practices. * Recommend ...
Application Security Code Review - SAC (Security Code Review)
Florham Park, NJ · On-site
$61.50 - $82.25/hr
Application Security Code Review - SAC A strong understanding of secure development life cycle, application security frameworks and various regulatory requirements. * Preferred background in software ...
Application Security Code Review - SAC (Security Code Review)
Florham Park, NJ · On-site
$61.50 - $82.25/hr
Application Security Code Review - SAC A strong understanding of secure development life cycle, application security frameworks and various regulatory requirements. * Preferred background in software ...
Senior Security Code Reviewer
Camp Springs, MD · On-site
$120K - $164.50K/yr
This Key Personnel role will lead application security testing, secure code review, DevSecOps pipeline integration, secure development guidance, risk assessments, and cloud/network security ...
Senior Security Code Reviewer
Camp Springs, MD · On-site
$120K - $164.50K/yr
This Key Personnel role will lead application security testing, secure code review, DevSecOps pipeline integration, secure development guidance, risk assessments, and cloud/network security ...
Senior Security Code Reviewer
$120K - $164.50K/yr
This Key Personnel role will lead application security testing, secure code review, DevSecOps pipeline integration, secure development guidance, risk assessments, and cloud/network security ...
New
Senior Security Code Reviewer
$120K - $164.50K/yr
This Key Personnel role will lead application security testing, secure code review, DevSecOps pipeline integration, secure development guidance, risk assessments, and cloud/network security ...
New
Senior Security Code Reviewer
Camp Springs, MD · On-site
$120K - $164.50K/yr
This Key Personnel role will lead application security testing, secure code review, DevSecOps pipeline integration, secure development guidance, risk assessments, and cloud/network security ...
New
Quick apply
Senior Security Code Reviewer
Camp Springs, MD · On-site
$120K - $164.50K/yr
This Key Personnel role will lead application security testing, secure code review, DevSecOps pipeline integration, secure development guidance, risk assessments, and cloud/network security ...
New
Information Technology - Cyber Consultant
Orlando, FL · Remote
$65 - $70/hr
Primary Duties: - Deliver secure code review assessment on programming languages such as Java, C#, JavaScript & SQL - Analyze and identify security vulnerabilities in source code using both automated ...
Quick apply
Information Technology - Cyber Consultant
Orlando, FL · Remote
$65 - $70/hr
Primary Duties: - Deliver secure code review assessment on programming languages such as Java, C#, JavaScript & SQL - Analyze and identify security vulnerabilities in source code using both automated ...
Application Offensive Security Lead (Associate Director)
Jersey City, NJ · Hybrid
$64.25 - $85.75/hr
You will be responsible for performing the Threat modeling and assess the Threats at design stage and perform manual secure code reviews to assess the code level security risks which cannot be ...
Application Offensive Security Lead (Associate Director)
Jersey City, NJ · Hybrid
$64.25 - $85.75/hr
You will be responsible for performing the Threat modeling and assess the Threats at design stage and perform manual secure code reviews to assess the code level security risks which cannot be ...
Experienced Lead of Product Secure Development Lifecycle and Regulatory Compliance
San Diego, CA · On-site
... design reviews, secure code review, vulnerability assessment, and security testing activities. • Provide expertise in one or more security domains, including hardware, trusted execution ...
Experienced Lead of Product Secure Development Lifecycle and Regulatory Compliance
San Diego, CA · On-site
... design reviews, secure code review, vulnerability assessment, and security testing activities. • Provide expertise in one or more security domains, including hardware, trusted execution ...
Senior Application Security Engineer
Chicago, IL · On-site
$60.50 - $80.75/hr
Align secure coding governance with established Bank technology standards, including SDLC, secure development expectations, and code review procedures. Ensure teams understand and implement secure-by ...
Quick apply
Senior Application Security Engineer
Chicago, IL · On-site
$60.50 - $80.75/hr
Align secure coding governance with established Bank technology standards, including SDLC, secure development expectations, and code review procedures. Ensure teams understand and implement secure-by ...
Senior Consultant (Source Code Review)
Austin, TX · Remote
$80 - $100/hr
Senior Consultant - Source Code Review (IP Litigation) responsible for deep-dive firmware, driver ... Work independently in secure "clean room" environments, adhering to all confidentiality and ...
Quick apply
Senior Consultant (Source Code Review)
Austin, TX · Remote
$80 - $100/hr
Senior Consultant - Source Code Review (IP Litigation) responsible for deep-dive firmware, driver ... Work independently in secure "clean room" environments, adhering to all confidentiality and ...
Experienced Lead of Product Secure Development Lifecycle and Regulatory Compliance
San Diego, CA · On-site
Drive secure design reviews, secure code review, vulnerability assessment, and security testing activities. * Provide expertise in one or more security domains, including hardware, trusted execution ...
Experienced Lead of Product Secure Development Lifecycle and Regulatory Compliance
San Diego, CA · On-site
Drive secure design reviews, secure code review, vulnerability assessment, and security testing activities. * Provide expertise in one or more security domains, including hardware, trusted execution ...
Perform and oversee secure code reviews, static (SAST) and dynamic (DAST) analysis, and manual assessments to identify vulnerabilities. * Develop and maintain software security standards, secure ...
Perform and oversee secure code reviews, static (SAST) and dynamic (DAST) analysis, and manual assessments to identify vulnerabilities. * Develop and maintain software security standards, secure ...
Perform and oversee secure code reviews, static (SAST) and dynamic (DAST) analysis, and manual assessments to identify vulnerabilities. * Develop and maintain software security standards, secure ...
Perform and oversee secure code reviews, static (SAST) and dynamic (DAST) analysis, and manual assessments to identify vulnerabilities. * Develop and maintain software security standards, secure ...
Define and maintain secure development lifecycle practices including secure code review standards, API security patterns, and authentication/authorization frameworks * Develop self-service security ...
Define and maintain secure development lifecycle practices including secure code review standards, API security patterns, and authentication/authorization frameworks * Develop self-service security ...
Define and maintain secure development lifecycle practices including secure code review standards, API security patterns, and authentication/authorization frameworks * Develop self-service security ...
Define and maintain secure development lifecycle practices including secure code review standards, API security patterns, and authentication/authorization frameworks * Develop self-service security ...
Ability to perform secure code review on infrastructure scripts and code. Identify vulnerabilities and provide guidance to development team and provide development support in remediating findings.
Quick apply
Ability to perform secure code review on infrastructure scripts and code. Identify vulnerabilities and provide guidance to development team and provide development support in remediating findings.
Pen Tester
San Francisco, CA · On-site
... Conduct secure code review trainings to developers - Understanding of OWASP, SANS, CWE standards, - Experience with enforcing application security in the SDLC of web applications - Develop ...
Pen Tester
San Francisco, CA · On-site
... Conduct secure code review trainings to developers - Understanding of OWASP, SANS, CWE standards, - Experience with enforcing application security in the SDLC of web applications - Develop ...
Pen Tester
San Francisco, CA · On-site
Conduct secure code review trainings to developers * Understanding of OWASP, SANS, CWE standards, * Experience with enforcing application security in the SDLC of web applications * Develop ...
Pen Tester
San Francisco, CA · On-site
Conduct secure code review trainings to developers * Understanding of OWASP, SANS, CWE standards, * Experience with enforcing application security in the SDLC of web applications * Develop ...
Lead AI AppSec Engineer
$64.25 - $86/hr
Conduct secure code reviews and support vulnerability remediation * Integrate and operate security tooling such as SAST, DAST, and SCA within CI/CD pipelines * Help define guardrails, monitoring, and ...
Quick apply
Lead AI AppSec Engineer
$64.25 - $86/hr
Conduct secure code reviews and support vulnerability remediation * Integrate and operate security tooling such as SAST, DAST, and SCA within CI/CD pipelines * Help define guardrails, monitoring, and ...
Secure Code Review information
See salary details
$29.81 - $35.86
1% of jobs
$35.86 - $41.91
1% of jobs
$41.91 - $47.97
2% of jobs
$47.97 - $54.02
13% of jobs
$56.22 is the 25th percentile. Wages below this are outliers.
$54.02 - $60.07
23% of jobs
The median wage is $64.40 / hr.
$60.07 - $66.13
15% of jobs
$66.13 - $72.18
16% of jobs
$74.34 is the 75th percentile. Wages above this are outliers.
$72.18 - $78.23
15% of jobs
$78.23 - $84.29
7% of jobs
$84.29 - $90.34
4% of jobs
$90.34 - $96.39
4% of jobs
$29
$66
$96
How much do secure code review jobs pay per hour?
What are the key skills and qualifications needed to thrive as a Secure Code Reviewer, and why are they important?
What are some common challenges faced by professionals performing secure code reviews, and how can they be addressed?
What is secure code review?
What is the difference between Secure Code Review vs Static Application Security Testing (SAST)?
| Aspect | Secure Code Review | Static Application Security Testing (SAST) |
|---|---|---|
| Credentials | Knowledge of secure coding, programming languages, security standards | Security testing tools, programming knowledge, security certifications |
| Work Environment | Manual review, developer collaboration, code analysis | Automated scanning, integration with CI/CD pipelines |
| Industry Usage | Development teams, security analysts, code audits | Security teams, QA, DevOps, automated security testing |
Secure Code Review involves manual or semi-automated analysis of source code to identify security flaws, emphasizing developer collaboration. SAST uses automated tools to scan code for vulnerabilities during development, enabling faster detection. Both roles aim to improve code security but differ in approach: one is manual and detailed, the other automated and scalable.

Full-time
Posted 5 days ago
ThreatLocker rating
7.0
Based on 6 frontline employees who took The Breakroom Quiz
139th of 184 rated software companies
Job description
ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application Allowlisting, Ringfencing™, Storage Control, Elevation Control, Endpoint Network Control, Configuration Management, and Operational Alert solutions are leading the cybersecurity market toward a more secure approach of blocking the exploits of application vulnerabilities.
POSITION OVERVIEW
We are looking for a Security-Focused Software Developer to join our onsite team, specializing exclusively in manual and automated code review for security vulnerabilities. In this role, you will not be writing production code but will be deeply involved in reviewing application code to identify security issues, enforce secure coding practices, and ensure compliance with industry security standards.
The role will be based in Orlando, FL and is an in-office position.
KEY RESPONSIBILITIES
- Perform in-depth security-focused code reviews across various codebases and languages
- Identify common and advanced security vulnerabilities (e.g., injection, XSS, insecure deserialization, insecure APIs).
- Work closely with developers to educate and guide them in secure coding practices.
- Recommend fixes and mitigation strategies, ensuring adherence to security standards (e.g., OWASP Top 10, CWE, NIST).
- Collaborate with security engineers, architects, and DevSecOps teams to enhance code security posture.
- Maintain documentation of findings and track remediation status.
- Utilize static and dynamic analysis tools to supplement manual reviews.
- Participate in security audits, threat modeling, and secure code training sessions.
REQUIRED QUALIFICATIONS
- Bachelor's degree in Computer Science, Cybersecurity, or a related field (or equivalent experience).
- 5+ years of experience in software development with at least 2 years in secure code review or application security.
- Strong understanding of secure software development lifecycle (SSDLC).
- Experience identifying and remediating vulnerabilities in code written in one or more languages (e.g., C/C++, C#, Swift, Java, JavaScript, Python).
- Familiarity with security tools such as SonarQube, Fortify, Checkmarx, Veracode, or similar.
- Knowledge of OWASP Top 10, CWE/SANS 25, and CVSS scoring.
- Strong analytical, communication, and documentation skills.
PREFERRED QUALIFICATIONS IN
- Security certifications such as OSCP, CSSLP, CEH, or GWAPT.
- Experience in regulated environments (e.g., finance, healthcare, defense).
- Familiarity with threat modeling, penetration testing, or red/blue team operations.
WORKING CONDITIONS
The duties described below are representative of those encountered while performing the essential functions of this position. If necessary, reasonable accommodation may be requested and will be evaluated for its relationship to the essential functions that must be performed.
- Job will generally be performed in an office environment but may require travel to visit company offices and/or property locations.
- While performing duties of this job, would occasionally require to stand, walk, sit, reach with hands and arms, climb or balance, stoop or kneel, talk and hear, and use fingers and hands to feel objects and tools.
- Must occasionally lift and/or move up to 25 pounds.
- Specific vision abilities required include close vision, distance vision, depth perceptions, and the ability to adjust focus.
A background check and drug/substance screening are required after a conditional offer. Employment will proceed only upon receiving clear results from both.
ThreatLocker also conducts randomized drug and substance testing approximately every 60 days, in line with the same screening standards.
About ThreatLocker
Sourced by ZipRecruiter
Industry
Network security
Company size
201 - 500 Employees
Headquarters location
Maitland, FL, US
Year founded
2015