1

Secure Code Review Jobs in California (NOW HIRING)

Uphold SDLC rigor: secure coding, code reviews, automated testing, CI/CD, and production readiness. * Mentor junior engineers (technical and soft skills), delegate effectively, and unblock delivery ...

New

Perform secure code reviews, validate false positive determinations, coach developers on effective remediation strategies, threat model our products and carry out essential parts of a secure SDLC.

Uphold SDLC rigor: secure coding, code reviews, automated testing, CI/CD, and production readiness. * Mentor junior engineers (technical and soft skills), delegate effectively, and unblock delivery ...

New

DAST * Secure Code Review * API Security * Application Security Architecture Cloud Security * AWS Security Architecture * Azure Security * Google Cloud Platform (GCP) Security * Cloud Security ...

Expertise in secure software development practices, including threat modeling, secure code review, and vulnerability assessment * Strong software engineering background with ability to review code ...

Showing results 21-40

Secure Code Review information

What is secure code review?

Secure code review is the process of systematically examining application source code to identify and remediate security vulnerabilities before software is released. This review can be performed manually or with automated tools, focusing on areas where coding errors could lead to security risks such as injection attacks, data leaks, or authentication flaws. The goal is to ensure that the code adheres to secure coding standards and best practices, ultimately reducing the risk of exploitation by malicious actors.

What are the key skills and qualifications needed to thrive as a secure code reviewer?

To thrive as a Secure Code Reviewer, you need a solid understanding of secure coding practices, programming languages (such as Java, Python, or C++), and common software vulnerabilities, often supported by relevant security certifications like CISSP or CSSLP. Familiarity with automated code analysis tools, static application security testing (SAST) platforms, and bug tracking systems is typically required. Strong analytical thinking, attention to detail, and clear communication skills set outstanding reviewers apart. These abilities are crucial for identifying, explaining, and mitigating security risks in code, ensuring robust application security.

What are some common challenges faced by professionals performing secure code reviews, and how can they be addressed?

Secure code reviewers often encounter challenges such as keeping up with evolving security threats, identifying subtle vulnerabilities in complex codebases, and maintaining effective communication with development teams. To address these, reviewers should stay updated on the latest security trends, use automated tools to assist in identifying potential issues, and foster collaborative relationships with developers to ensure that findings are understood and remediated effectively. Regular training, participating in security communities, and integrating secure code review into the software development lifecycle can also help overcome these challenges.

What is the difference between Secure Code Review vs Static Application Security Testing (SAST)?

AspectSecure Code ReviewStatic Application Security Testing (SAST)
CredentialsKnowledge of secure coding, programming languages, security standardsSecurity testing tools, programming knowledge, security certifications
Work EnvironmentManual review, developer collaboration, code analysisAutomated scanning, integration with CI/CD pipelines
Industry UsageDevelopment teams, security analysts, code auditsSecurity teams, QA, DevOps, automated security testing

Secure Code Review involves manual or semi-automated analysis of source code to identify security flaws, emphasizing developer collaboration. SAST uses automated tools to scan code for vulnerabilities during development, enabling faster detection. Both roles aim to improve code security but differ in approach: one is manual and detailed, the other automated and scalable.

What job categories do people searching Secure Code Review jobs in California look for? The top searched job categories for Secure Code Review jobs in California are:
Infographic showing various Secure Code Review job openings in California as of August 2026, with employment types broken down into 67% Full Time, and 33% Contract. Highlights an 100% In-person job distribution.

Member of Technical Staff, Security

Mandolin

San Francisco, CA • On-site

Full-time

Re-posted 19 days ago


Job description

Job Summary:
Mandolin is a company focused on revolutionizing healthcare by leveraging AI to expedite groundbreaking treatments. They are seeking a highly motivated Security Engineer to secure their applications and cloud infrastructure while ensuring compliance with various security programs.
Responsibilities:
• Integrate security into the Software Development Lifecycle (SDLC) and CI/CD pipelines
• Conduct application security reviews, threat modeling, vulnerability assessments, and support secure code review practices
• Identify and remediate vulnerabilities related to the OWASP Top 10, APIs, authentication/authorization, secrets management, and software dependencies
• Design and implement security controls across cloud and infrastructure environments including AWS, Azure, or GCP
• Secure cloud-native platforms, containers, Kubernetes environments, CI/CD systems, and Infrastructure-as-Code (IaC) deployments
• Monitor and improve logging, alerting, vulnerability management, endpoint protection, and incident response capabilities
• Collaborate with Platform Engineering and DevOps teams to improve infrastructure hardening and operational security practices
• Support security compliance initiatives including SOC 2, ISO 27001, HIPAA, PCI-DSS, GDPR, and NIST-based programs
• Assist with risk assessments, audit readiness, evidence collection, policy development, vendor security reviews, and remediation tracking
• Help drive security awareness, promote secure engineering best practices, and contribute to long-term security strategy and maturity initiatives
• Research emerging threats, vulnerabilities, and security technologies to continuously improve organizational security posture
Qualifications:
Required:
• 4+ years of experience in Security Engineering, Application Security, Cloud Security, DevSecOps, or related cybersecurity roles
• Strong understanding of application security, infrastructure/cloud security, and security compliance concepts
• Experience securing modern web applications, APIs, cloud environments, and distributed systems
• Hands-on experience with cloud platforms such as AWS, Azure, or GCP
• Familiarity with CI/CD pipelines, container security, Kubernetes, and Infrastructure-as-Code security practices
• Experience with security tools such as SAST, DAST, SIEM, vulnerability scanners, CSPM, EDR/XDR, and IAM solutions
• Scripting or automation experience using Python, Bash, PowerShell, or similar languages.
• Strong communication skills with the ability to collaborate across technical and non-technical teams
Preferred:
• Experience in SaaS, fintech, healthcare, or other regulated environments
• Familiarity with Zero Trust architectures and modern identity/security frameworks
• Experience supporting compliance audits and governance initiatives
• Relevant certifications such as CISSP, Security+, CCSP, AWS Security Specialty, GSEC, OSCP, or similar
Company:
Mandolin delivers precision automation tools for specialty drug processing workflows. Founded in 2024, the company is headquartered in San Francisco, USA, with a team of 11-50 employees. The company is currently Growth Stage.