1

Secure Code Review Jobs in California (NOW HIRING)

Perform secure code reviews, validate false positive determinations, coach developers on effective remediation strategies, threat model our products and carry out essential parts of a secure SDLC.

Secure Code Review: Conduct secure code reviews and security assessments on products and services built with Next.js, Node.js, and our serverless backend. You'll uncover code-level vulnerabilities ...

Senior Security Engineer

Livermore, CA · On-site

$134K - $184K/yr

Lead application security reviews across the SDLC - threat modeling, secure design review, and secure code review for web, API, and cloud services. Triage and drive remediation of vulnerabilities ...

... Conduct secure code review trainings to developers - Understanding of OWASP, SANS, CWE standards, - Experience with enforcing application security in the SDLC of web applications - Develop ...

Senior Security Engineer

Livermore, CA · On-site +1

$134K - $184K/yr

Lead application security reviews across the SDLC - threat modeling, secure design review, and secure code review for web, API, and cloud services. Triage and drive remediation of vulnerabilities ...

... Conduct secure code review trainings to developers - Understanding of OWASP, SANS, CWE standards, - Experience with enforcing application security in the SDLC of web applications - Develop ...

Review and refine AI-generated code to ensure compliance with secure coding standards (e.g., OWASP Top 10, secure SDLC practices). * Implement automated guardrails to detect insecure outputs, prompt ...

Review and refine AI-generated code to ensure compliance with secure coding standards (e.g., OWASP Top 10, secure SDLC practices). * Implement automated guardrails to detect insecure outputs, prompt ...

Review and refine AI-generated code to ensure compliance with secure coding standards (e.g., OWASP Top 10, secure SDLC practices). * Implement automated guardrails to detect insecure outputs, prompt ...

Perform secure code reviews, validate false positive determinations, coach developers on effective remediation strategies, threat model our products and carry out essential parts of a secure SDLC.

next page

Showing results 1-20

Secure Code Review information

What is secure code review?

Secure code review is the process of systematically examining application source code to identify and remediate security vulnerabilities before software is released. This review can be performed manually or with automated tools, focusing on areas where coding errors could lead to security risks such as injection attacks, data leaks, or authentication flaws. The goal is to ensure that the code adheres to secure coding standards and best practices, ultimately reducing the risk of exploitation by malicious actors.

What are the key skills and qualifications needed to thrive as a secure code reviewer?

To thrive as a Secure Code Reviewer, you need a solid understanding of secure coding practices, programming languages (such as Java, Python, or C++), and common software vulnerabilities, often supported by relevant security certifications like CISSP or CSSLP. Familiarity with automated code analysis tools, static application security testing (SAST) platforms, and bug tracking systems is typically required. Strong analytical thinking, attention to detail, and clear communication skills set outstanding reviewers apart. These abilities are crucial for identifying, explaining, and mitigating security risks in code, ensuring robust application security.

What are some common challenges faced by professionals performing secure code reviews, and how can they be addressed?

Secure code reviewers often encounter challenges such as keeping up with evolving security threats, identifying subtle vulnerabilities in complex codebases, and maintaining effective communication with development teams. To address these, reviewers should stay updated on the latest security trends, use automated tools to assist in identifying potential issues, and foster collaborative relationships with developers to ensure that findings are understood and remediated effectively. Regular training, participating in security communities, and integrating secure code review into the software development lifecycle can also help overcome these challenges.

What is the difference between Secure Code Review vs Static Application Security Testing (SAST)?

AspectSecure Code ReviewStatic Application Security Testing (SAST)
CredentialsKnowledge of secure coding, programming languages, security standardsSecurity testing tools, programming knowledge, security certifications
Work EnvironmentManual review, developer collaboration, code analysisAutomated scanning, integration with CI/CD pipelines
Industry UsageDevelopment teams, security analysts, code auditsSecurity teams, QA, DevOps, automated security testing

Secure Code Review involves manual or semi-automated analysis of source code to identify security flaws, emphasizing developer collaboration. SAST uses automated tools to scan code for vulnerabilities during development, enabling faster detection. Both roles aim to improve code security but differ in approach: one is manual and detailed, the other automated and scalable.

What job categories do people searching Secure Code Review jobs in California look for?

The top searched job categories for Secure Code Review jobs in California are:

Infographic showing various Secure Code Review job openings in California as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 15% Part Time, 1% Temporary, and 2% Contract. Highlights an 88% Physical, 3% Hybrid, and 9% Remote job distribution.

Application Security Engineer

Jobtailor

San Francisco, CA • On-site

$140 - $180/hr

Other

This job post has expired today. Applications are no longer accepted.


Job description

  • Partner with the engineering team to provide hands-on technical guidance to software developers throughout the vulnerability remediation lifecycle. Perform secure code reviews, validate false positive determinations, coach developers on effective remediation strategies, threat model our products and carry out essential parts of a secure SDLC.
  • Drive vulnerability identification using SAST, DAST, SCA and in-house AI tooling and manage external penetration testing.
  • Support engineering team on vulnerability management, including risk assessment, remediation, improving identification of vulnerabilities and translate security and privacy requirements into technical requirements.
  • Build security awareness through training on secure coding practices, security standards and latest security threats.
Requirements
  • Security Communication – Ability to reason about risk in complex environments and communicate that risk to technical and non-technical audiences. Experience leading training, speaking internally/externally about security projects valued.
  • Programming Skills – Experience writing and maintaining code in at least one modern programming language and with at least one scripting language (Heartflow uses C++/Python). Comfortable with testing frameworks and CI/CD pipelines.
  • AI Development Tools – Experience using AI code tools such as Claude Code and Github Copilot for development and security testing.
  • Education & Experience – BS in Computer Science (or related degree) or relevant certifications and equivalent experience. 5+ years of total experience with at least 1 year working in Application Security or performing security tasks in a development role.
  • Securing SDLC – Have contributed to secure SDLC activities, including threat modeling, code review, security testing and vulnerability management.
  • Knowledge of Modern AI Security Threats – Experience working with or ability to discuss current AI threats for both machine learning and generative AI.
Core Competencies

Emphasize expertise in secure software development lifecycle (SDLC) practices, including secure code reviews, vulnerability management, and risk assessment. Highlight experience in programming, particularly in C++ and Python, along with familiarity with AI development tools and modern security threats.

Highest-signal resume keywords
  • Secure Software Development Lifecycle (SDLC)
  • Vulnerability Management
  • Risk Assessment
  • Secure Code Reviews
  • AI Development Tools
ATS Optimization Keywords Hard Skills
  • C++
  • Python
  • SAST
  • DAST
  • SCA
Soft Skills
  • Security Communication
  • Training
  • Coaching
  • Risk Reasoning
  • Stakeholder Engagement
Certifications & Qualifications
  • BS in Computer Science
  • Relevant Certifications
Industry Keywords
  • Application Security
  • Vulnerability Remediation
  • Threat Modeling
  • Security Standards
  • AI Security Threats
Tools & Technologies
  • AI Code Tools
  • Github Copilot
  • CI/CD Pipelines
  • Testing Frameworks
  • In-House AI Tooling
#J-18808-Ljbffr