... secure code review practices • Identify and remediate vulnerabilities related to the OWASP Top 10, APIs, authentication/authorization, secrets management, and software dependencies • Design and ...
... secure code review practices • Identify and remediate vulnerabilities related to the OWASP Top 10, APIs, authentication/authorization, secrets management, and software dependencies • Design and ...
Staff II - Application Security Engineer
Mountain View, CA · On-site +1
$69.25 - $92.50/hr
Secure Code Review & Vulnerability Research * Perform manual code review and application security testing across Java and C++ codebases; codify findings into reusable guidance engineers can act on ...
Staff II - Application Security Engineer
Mountain View, CA · On-site +1
$69.25 - $92.50/hr
Secure Code Review & Vulnerability Research * Perform manual code review and application security testing across Java and C++ codebases; codify findings into reusable guidance engineers can act on ...
Senior Product Security Engineer (Applications)
San Francisco, CA · Hybrid
$134K - $185K/yr
Conduct secure code reviews for critical modules in Python and C/C++, supporting secure coding practices across all engineering teams. * Evaluate cryptographic usage, authentication/authorization ...
Senior Product Security Engineer (Applications)
San Francisco, CA · Hybrid
$134K - $185K/yr
Conduct secure code reviews for critical modules in Python and C/C++, supporting secure coding practices across all engineering teams. * Evaluate cryptographic usage, authentication/authorization ...
Senior AppSec Engineer ID71672
Los Angeles, CA · On-site
$140 - $190/hr
Ability to confidently read, review, and secure enterprise source Java code. PERKS AND BENEFITS * Professional growth : Mentorship, TechTalks, and personalized growth roadmaps. * Competitive ...
Senior AppSec Engineer ID71672
Los Angeles, CA · On-site
$140 - $190/hr
Ability to confidently read, review, and secure enterprise source Java code. PERKS AND BENEFITS * Professional growth : Mentorship, TechTalks, and personalized growth roadmaps. * Competitive ...
Senior AppSec Engineer ID71672
San Francisco, CA · On-site
$130 - $200/hr
Ability to confidently read, review, and secure enterprise source Java code. PERKS AND BENEFITS * Professional growth : Mentorship, TechTalks, and personalized growth roadmaps. * Competitive ...
Senior AppSec Engineer ID71672
San Francisco, CA · On-site
$130 - $200/hr
Ability to confidently read, review, and secure enterprise source Java code. PERKS AND BENEFITS * Professional growth : Mentorship, TechTalks, and personalized growth roadmaps. * Competitive ...
Application Security Engineer (Senior) ID71668
San Francisco, CA · On-site
$69.25 - $92.50/hr
... review, and secure enterprise source code); - Deep, hands-on expertise deploying and tuning modern application security testing tools ( SAST , DAST , SCA ) and integrating them into complex CI/CD ...
Application Security Engineer (Senior) ID71668
San Francisco, CA · On-site
$69.25 - $92.50/hr
... review, and secure enterprise source code); - Deep, hands-on expertise deploying and tuning modern application security testing tools ( SAST , DAST , SCA ) and integrating them into complex CI/CD ...
Lead Software Engineer
San Francisco, CA · On-site
$152K - $215K/yr
Uphold SDLC rigor: secure coding, code reviews, automated testing, CI/CD, and production readiness. * Mentor junior engineers (technical and soft skills), delegate effectively, and unblock delivery ...
Lead Software Engineer
San Francisco, CA · On-site
$152K - $215K/yr
Uphold SDLC rigor: secure coding, code reviews, automated testing, CI/CD, and production readiness. * Mentor junior engineers (technical and soft skills), delegate effectively, and unblock delivery ...
Uphold SDLC rigor: secure coding, code reviews, automated testing, CI/CD, and production readiness. * Mentor junior engineers (technical and soft skills), delegate effectively, and unblock delivery ...
New
Uphold SDLC rigor: secure coding, code reviews, automated testing, CI/CD, and production readiness. * Mentor junior engineers (technical and soft skills), delegate effectively, and unblock delivery ...
New
Lead Software Engineer
San Francisco, CA · On-site
Uphold SDLC rigor: secure coding, code reviews, automated testing, CI/CD, and production readiness. * Mentor junior engineers (technical and soft skills), delegate effectively, and unblock delivery ...
Lead Software Engineer
San Francisco, CA · On-site
Uphold SDLC rigor: secure coding, code reviews, automated testing, CI/CD, and production readiness. * Mentor junior engineers (technical and soft skills), delegate effectively, and unblock delivery ...
Application Security Engineer
San Francisco, CA · On-site
$145K - $180K/yr
Perform secure code reviews, validate false positive determinations, coach developers on effective remediation strategies, threat model our products and carry out essential parts of a secure SDLC.
Application Security Engineer
San Francisco, CA · On-site
$145K - $180K/yr
Perform secure code reviews, validate false positive determinations, coach developers on effective remediation strategies, threat model our products and carry out essential parts of a secure SDLC.
Uphold SDLC rigor: secure coding, code reviews, automated testing, CI/CD, and production readiness. * Mentor junior engineers (technical and soft skills), delegate effectively, and unblock delivery ...
New
Uphold SDLC rigor: secure coding, code reviews, automated testing, CI/CD, and production readiness. * Mentor junior engineers (technical and soft skills), delegate effectively, and unblock delivery ...
New
Lead Software Engineer
San Francisco, CA · On-site
Uphold SDLC rigor: secure coding, code reviews, automated testing, CI/CD, and production readiness. * Mentor junior engineers (technical and soft skills), delegate effectively, and unblock delivery ...
Lead Software Engineer
San Francisco, CA · On-site
Uphold SDLC rigor: secure coding, code reviews, automated testing, CI/CD, and production readiness. * Mentor junior engineers (technical and soft skills), delegate effectively, and unblock delivery ...
Lead Software Engineer
San Francisco, CA · On-site
Uphold SDLC rigor: secure coding, code reviews, automated testing, CI/CD, and production readiness. * Mentor junior engineers (technical and soft skills), delegate effectively, and unblock delivery ...
Lead Software Engineer
San Francisco, CA · On-site
Uphold SDLC rigor: secure coding, code reviews, automated testing, CI/CD, and production readiness. * Mentor junior engineers (technical and soft skills), delegate effectively, and unblock delivery ...
Lead Software Engineer
San Francisco, CA · On-site
Uphold SDLC rigor: secure coding, code reviews, automated testing, CI/CD, and production readiness. * Mentor junior engineers (technical and soft skills), delegate effectively, and unblock delivery ...
Lead Software Engineer
San Francisco, CA · On-site
Uphold SDLC rigor: secure coding, code reviews, automated testing, CI/CD, and production readiness. * Mentor junior engineers (technical and soft skills), delegate effectively, and unblock delivery ...
Lead Software Engineer
San Francisco, CA · On-site
$152K - $215K/yr
Uphold SDLC rigor: secure coding, code reviews, automated testing, CI/CD, and production readiness. * Mentor junior engineers (technical and soft skills), delegate effectively, and unblock delivery ...
Lead Software Engineer
San Francisco, CA · On-site
$152K - $215K/yr
Uphold SDLC rigor: secure coding, code reviews, automated testing, CI/CD, and production readiness. * Mentor junior engineers (technical and soft skills), delegate effectively, and unblock delivery ...
Help engineering teams interpret and apply secure coding standards, OWASP guidance, internal Secure SDLC requirements, and product security best practices. * Assist in reviewing AI-related security ...
Help engineering teams interpret and apply secure coding standards, OWASP guidance, internal Secure SDLC requirements, and product security best practices. * Assist in reviewing AI-related security ...
Information Security Engineer 4
Fremont, CA · On-site
$92 - $211/hr
Help engineering teams interpret and apply secure coding standards, OWASP guidance, internal Secure SDLC requirements, and product security best practices. * Assist in reviewing AI-related security ...
Information Security Engineer 4
Fremont, CA · On-site
$92 - $211/hr
Help engineering teams interpret and apply secure coding standards, OWASP guidance, internal Secure SDLC requirements, and product security best practices. * Assist in reviewing AI-related security ...
Lead Security Architect
Santa Clara, CA · On-site
$75 - $95/hr
DAST * Secure Code Review * API Security * Application Security Architecture Cloud Security * AWS Security Architecture * Azure Security * Google Cloud Platform (GCP) Security * Cloud Security ...
Quick apply
Lead Security Architect
Santa Clara, CA · On-site
$75 - $95/hr
DAST * Secure Code Review * API Security * Application Security Architecture Cloud Security * AWS Security Architecture * Azure Security * Google Cloud Platform (GCP) Security * Cloud Security ...
Platform Engineer, Security
San Francisco, CA · On-site
$200 - $330/hr
Expertise in secure software development practices, including threat modeling, secure code review, and vulnerability assessment * Strong software engineering background with ability to review code ...
Platform Engineer, Security
San Francisco, CA · On-site
$200 - $330/hr
Expertise in secure software development practices, including threat modeling, secure code review, and vulnerability assessment * Strong software engineering background with ability to review code ...
Set the standard for secure code review, manual and AI-assisted penetration testing, and vulnerability analysis; drive root-cause remediation strategies that eliminate whole vulnerability classes ...
Set the standard for secure code review, manual and AI-assisted penetration testing, and vulnerability analysis; drive root-cause remediation strategies that eliminate whole vulnerability classes ...
Secure Code Review information
What is secure code review?
What are the key skills and qualifications needed to thrive as a secure code reviewer?
What are some common challenges faced by professionals performing secure code reviews, and how can they be addressed?
What is the difference between Secure Code Review vs Static Application Security Testing (SAST)?
| Aspect | Secure Code Review | Static Application Security Testing (SAST) |
|---|---|---|
| Credentials | Knowledge of secure coding, programming languages, security standards | Security testing tools, programming knowledge, security certifications |
| Work Environment | Manual review, developer collaboration, code analysis | Automated scanning, integration with CI/CD pipelines |
| Industry Usage | Development teams, security analysts, code audits | Security teams, QA, DevOps, automated security testing |
Secure Code Review involves manual or semi-automated analysis of source code to identify security flaws, emphasizing developer collaboration. SAST uses automated tools to scan code for vulnerabilities during development, enabling faster detection. Both roles aim to improve code security but differ in approach: one is manual and detailed, the other automated and scalable.

Full-time
Re-posted 19 days ago
Job description
Mandolin is a company focused on revolutionizing healthcare by leveraging AI to expedite groundbreaking treatments. They are seeking a highly motivated Security Engineer to secure their applications and cloud infrastructure while ensuring compliance with various security programs.
Responsibilities:
• Integrate security into the Software Development Lifecycle (SDLC) and CI/CD pipelines
• Conduct application security reviews, threat modeling, vulnerability assessments, and support secure code review practices
• Identify and remediate vulnerabilities related to the OWASP Top 10, APIs, authentication/authorization, secrets management, and software dependencies
• Design and implement security controls across cloud and infrastructure environments including AWS, Azure, or GCP
• Secure cloud-native platforms, containers, Kubernetes environments, CI/CD systems, and Infrastructure-as-Code (IaC) deployments
• Monitor and improve logging, alerting, vulnerability management, endpoint protection, and incident response capabilities
• Collaborate with Platform Engineering and DevOps teams to improve infrastructure hardening and operational security practices
• Support security compliance initiatives including SOC 2, ISO 27001, HIPAA, PCI-DSS, GDPR, and NIST-based programs
• Assist with risk assessments, audit readiness, evidence collection, policy development, vendor security reviews, and remediation tracking
• Help drive security awareness, promote secure engineering best practices, and contribute to long-term security strategy and maturity initiatives
• Research emerging threats, vulnerabilities, and security technologies to continuously improve organizational security posture
Qualifications:
Required:
• 4+ years of experience in Security Engineering, Application Security, Cloud Security, DevSecOps, or related cybersecurity roles
• Strong understanding of application security, infrastructure/cloud security, and security compliance concepts
• Experience securing modern web applications, APIs, cloud environments, and distributed systems
• Hands-on experience with cloud platforms such as AWS, Azure, or GCP
• Familiarity with CI/CD pipelines, container security, Kubernetes, and Infrastructure-as-Code security practices
• Experience with security tools such as SAST, DAST, SIEM, vulnerability scanners, CSPM, EDR/XDR, and IAM solutions
• Scripting or automation experience using Python, Bash, PowerShell, or similar languages.
• Strong communication skills with the ability to collaborate across technical and non-technical teams
Preferred:
• Experience in SaaS, fintech, healthcare, or other regulated environments
• Familiarity with Zero Trust architectures and modern identity/security frameworks
• Experience supporting compliance audits and governance initiatives
• Relevant certifications such as CISSP, Security+, CCSP, AWS Security Specialty, GSEC, OSCP, or similar
Company:
Mandolin delivers precision automation tools for specialty drug processing workflows. Founded in 2024, the company is headquartered in San Francisco, USA, with a team of 11-50 employees. The company is currently Growth Stage.
About Mandolin Software
Sourced by ZipRecruiter
Company size
51 - 200 Employees
Headquarters location
Indianapolis, IN, US
Year founded
2020