... Conduct secure code review trainings to developers - Understanding of OWASP, SANS, CWE standards, - Experience with enforcing application security in the SDLC of web applications - Develop ...
... Conduct secure code review trainings to developers - Understanding of OWASP, SANS, CWE standards, - Experience with enforcing application security in the SDLC of web applications - Develop ...
Pen Tester
San Francisco, CA · On-site
Conduct secure code review trainings to developers * Understanding of OWASP, SANS, CWE standards, * Experience with enforcing application security in the SDLC of web applications * Develop ...
Pen Tester
San Francisco, CA · On-site
Conduct secure code review trainings to developers * Understanding of OWASP, SANS, CWE standards, * Experience with enforcing application security in the SDLC of web applications * Develop ...
Lead AI AppSec Engineer
$63 - $84.25/hr
Conduct secure code reviews and support vulnerability remediation * Integrate and operate security tooling such as SAST, DAST, and SCA within CI/CD pipelines * Help define guardrails, monitoring, and ...
Quick apply
Lead AI AppSec Engineer
$63 - $84.25/hr
Conduct secure code reviews and support vulnerability remediation * Integrate and operate security tooling such as SAST, DAST, and SCA within CI/CD pipelines * Help define guardrails, monitoring, and ...
AI Software Engineer
San Francisco, CA · On-site
Review and refine AI-generated code to ensure compliance with secure coding standards (e.g., OWASP Top 10, secure SDLC practices). * Implement automated guardrails to detect insecure outputs, prompt ...
AI Software Engineer
San Francisco, CA · On-site
Review and refine AI-generated code to ensure compliance with secure coding standards (e.g., OWASP Top 10, secure SDLC practices). * Implement automated guardrails to detect insecure outputs, prompt ...
Review and refine AI-generated code to ensure compliance with secure coding standards (e.g., OWASP Top 10, secure SDLC practices). * Implement automated guardrails to detect insecure outputs, prompt ...
Review and refine AI-generated code to ensure compliance with secure coding standards (e.g., OWASP Top 10, secure SDLC practices). * Implement automated guardrails to detect insecure outputs, prompt ...
Review and refine AI-generated code to ensure compliance with secure coding standards (e.g., OWASP Top 10, secure SDLC practices). * Implement automated guardrails to detect insecure outputs, prompt ...
Review and refine AI-generated code to ensure compliance with secure coding standards (e.g., OWASP Top 10, secure SDLC practices). * Implement automated guardrails to detect insecure outputs, prompt ...
Application Security Engineer
San Francisco, CA · Hybrid
$145K - $180K/yr
Perform secure code reviews, validate false positive determinations, coach developers on effective remediation strategies, threat model our products and carry out essential parts of a secure SDLC.
Application Security Engineer
San Francisco, CA · Hybrid
$145K - $180K/yr
Perform secure code reviews, validate false positive determinations, coach developers on effective remediation strategies, threat model our products and carry out essential parts of a secure SDLC.
Sr. Application Security Engineer
San Francisco, CA · On-site
$69.25 - $92.50/hr
... Secure code review experience using automated toolsets Software Engineering career experience Following Certifications: CISSP, CEH, GWAPT, GPEN, OSCP Thorough understanding of software ...
Sr. Application Security Engineer
San Francisco, CA · On-site
$69.25 - $92.50/hr
... Secure code review experience using automated toolsets Software Engineering career experience Following Certifications: CISSP, CEH, GWAPT, GPEN, OSCP Thorough understanding of software ...
Staff+ Application Security Engineer
San Francisco, CA · On-site +1
$69.25 - $92.50/hr
Conduct secure design reviews and threat modeling. Identify and prioritize risks, attack surfaces, and vulnerabilities. * Develop tooling to scale security code reviews and respond to developer ...
Staff+ Application Security Engineer
San Francisco, CA · On-site +1
$69.25 - $92.50/hr
Conduct secure design reviews and threat modeling. Identify and prioritize risks, attack surfaces, and vulnerabilities. * Develop tooling to scale security code reviews and respond to developer ...
Sr. Application Security Engineer
San Francisco, CA · On-site
$69.25 - $92.50/hr
... • Secure code review experience using automated toolsets • Software Engineering career experience • Following Certifications: CISSP, CEH, GWAPT, GPEN, OSCP • Thorough understanding of ...
Sr. Application Security Engineer
San Francisco, CA · On-site
$69.25 - $92.50/hr
... • Secure code review experience using automated toolsets • Software Engineering career experience • Following Certifications: CISSP, CEH, GWAPT, GPEN, OSCP • Thorough understanding of ...
While your primary role is to build secure software in Python and modern web stacks, your expertise ... Perform security code reviews and penetration testing on our web applications and services.
While your primary role is to build secure software in Python and modern web stacks, your expertise ... Perform security code reviews and penetration testing on our web applications and services.
Senior Principal Software Developer - IC5
Santa Clara, CA · On-site
$147K - $203K/yr
Apply secure-by-default and responsible-AI practices across identity, access control, secrets handling, dependency hygiene, data protection, threat modeling, and secure code review. * Partner with ...
Senior Principal Software Developer - IC5
Santa Clara, CA · On-site
$147K - $203K/yr
Apply secure-by-default and responsible-AI practices across identity, access control, secrets handling, dependency hygiene, data protection, threat modeling, and secure code review. * Partner with ...
... secure code review practices • Identify and remediate vulnerabilities related to the OWASP Top 10, APIs, authentication/authorization, secrets management, and software dependencies • Design and ...
... secure code review practices • Identify and remediate vulnerabilities related to the OWASP Top 10, APIs, authentication/authorization, secrets management, and software dependencies • Design and ...
Senior Product Security Engineer (Generalist)
San Francisco, CA · Hybrid
$134K - $185K/yr
Conduct secure code reviews for critical modules in Python and C/C++, supporting secure coding practices across all engineering teams. * Evaluate cryptographic usage, authentication/authorization ...
Senior Product Security Engineer (Generalist)
San Francisco, CA · Hybrid
$134K - $185K/yr
Conduct secure code reviews for critical modules in Python and C/C++, supporting secure coding practices across all engineering teams. * Evaluate cryptographic usage, authentication/authorization ...
Software Engineer, Security
South San Francisco, CA · On-site
$120/hr
Perform secure code reviews, threat modeling, and security design reviews for new features and services. * Use AI to automate tooling like SAST, DAST, SCA, secret scanning, and container scanning ...
Software Engineer, Security
South San Francisco, CA · On-site
$120/hr
Perform secure code reviews, threat modeling, and security design reviews for new features and services. * Use AI to automate tooling like SAST, DAST, SCA, secret scanning, and container scanning ...
Product Security Engineer
Sunnyvale, CA · On-site
Prescribe and evaluate secure coding standards as a component of SPDF and SDLC. * Support product cybersecurity testing and remediation as a component of SPDF and SDLC. * Through review of Software ...
Product Security Engineer
Sunnyvale, CA · On-site
Prescribe and evaluate secure coding standards as a component of SPDF and SDLC. * Support product cybersecurity testing and remediation as a component of SPDF and SDLC. * Through review of Software ...
Application Security Engineer
San Francisco, CA · On-site
$145K - $180K/yr
Perform secure code reviews, validate false positive determinations, coach developers on effective remediation strategies, threat model our products and carry out essential parts of a secure SDLC.
Application Security Engineer
San Francisco, CA · On-site
$145K - $180K/yr
Perform secure code reviews, validate false positive determinations, coach developers on effective remediation strategies, threat model our products and carry out essential parts of a secure SDLC.
Senior Security Engineer
San Francisco, CA · On-site
$200K - $330K/yr
Expertise in secure software development practices, including threat modeling, secure code review, and vulnerability assessment * Strong software engineering background with ability to review code ...
Senior Security Engineer
San Francisco, CA · On-site
$200K - $330K/yr
Expertise in secure software development practices, including threat modeling, secure code review, and vulnerability assessment * Strong software engineering background with ability to review code ...
Platform Engineer, Security
San Francisco, CA · On-site
$200K - $330K/yr
Expertise in secure software development practices, including threat modeling, secure code review, and vulnerability assessment * Strong software engineering background with ability to review code ...
Platform Engineer, Security
San Francisco, CA · On-site
$200K - $330K/yr
Expertise in secure software development practices, including threat modeling, secure code review, and vulnerability assessment * Strong software engineering background with ability to review code ...
... code and reviewing designs, the job is as diverse as it is critical. This position requires someone with strong technical abilities and a passionate desire to secure systems by showing how they can ...
... code and reviewing designs, the job is as diverse as it is critical. This position requires someone with strong technical abilities and a passionate desire to secure systems by showing how they can ...
Secure Code Review information
What is secure code review?
What are the key skills and qualifications needed to thrive as a Secure Code Reviewer, and why are they important?
What are some common challenges faced by professionals performing secure code reviews, and how can they be addressed?
What is the difference between Secure Code Review vs Static Application Security Testing (SAST)?
| Aspect | Secure Code Review | Static Application Security Testing (SAST) |
|---|---|---|
| Credentials | Knowledge of secure coding, programming languages, security standards | Security testing tools, programming knowledge, security certifications |
| Work Environment | Manual review, developer collaboration, code analysis | Automated scanning, integration with CI/CD pipelines |
| Industry Usage | Development teams, security analysts, code audits | Security teams, QA, DevOps, automated security testing |
Secure Code Review involves manual or semi-automated analysis of source code to identify security flaws, emphasizing developer collaboration. SAST uses automated tools to scan code for vulnerabilities during development, enabling faster detection. Both roles aim to improve code security but differ in approach: one is manual and detailed, the other automated and scalable.
- Piece Rate Game Developer
- Remote No Experience Full Stack Software Developer
- Js Fort Group
- Junior Telematics Engineer
- Medical Software Developer
- Part Time Developer
- Contract Remote Asp Net Software Developer
- Software Engineer Co Op
- Internship Software Engineer Fall Co Op
- Temporary Internship Full Stack Software Developer

Contractor
Posted 21 days ago
Job description
- Conduct black box, white box vulnerability and penetration testing
- Setup threat modesla and protocol fuzzers
- Experience in architecture & design reviews with developers at all levels
- Develop, implement & support security tools and services
- Good at assessment of security policies, best practices and recommendations
- Experience with vulnerability tracking methods and tools
- Conduct secure code review trainings to developers
- Understanding of OWASP, SANS, CWE standards,
- Experience with enforcing application security in the SDLC of web applications
- Develop Application Security practice
- Experience in Ethical hacking domain
- Hands-on experience on Java, Python, C/C++, Ruby, Perl, Node.js, DoJo and Angular.js
- Experience with tools like - CheckMarx, Coverity, IBM AppScan Enterprise, Nessus, Qualys, GFI, Client Fortify, Veracode, Burp Suite, MS Threat Modeler etc.
- Good understand of malwares
All your information will be kept confidential according to EEO guidelines.