1

Secure Code Review Jobs in New York (NOW HIRING)

Application Security

Parsippany Troy Hills, NJ ยท On-site

$59 - $78.75/hr

Ability to sufficiently perform meaningful secure code review, validate SAST/SCA findings, and collaborate credibly with engineering teams on remediation * Experience working with change management ...

Sr. Security Engineer

New York, NY ยท On-site

$125K - $171K/yr

Lead application security reviews, threat modeling sessions, and secure code review for new features and significant product changes. * Operate and continuously improve SAST, DAST, and SCA tooling ...

Secure Code Review * CI/CD Security Integration / Responsibilities The role focuses on embedding security testing, vulnerability management, and business logic validation directly into CI/CD ...

New

This position is accountable for application-specific security controls, threat modeling, security architecture reviews, secure code practices, and security testing coordination. Responsible for ...

This position is accountable for application-specific security controls, threat modeling, security architecture reviews, secure code practices, and security testing coordination. Responsible for ...

Sr. Security Engineer

Manhattan, NY ยท On-site

$170 - $200/hr

Lead application security reviews, threat modeling sessions, and secure code review for new features and significant product changes. * Operate and continuously improve SAST, DAST, and SCA tooling ...

Staff Application Security Engineer

New York, NY ยท On-site +1

$168K - $240K/yr

Proven ability to perform design reviews, threat modeling, secure code reviews, and penetration testing with an attacker mindset * Strong background in application security best practices and ...

Proven ability to perform design reviews, threat modeling, secure code reviews, and penetration testing with an attacker mindset * Strong background in application security best practices and ...

next page

Showing results 1-20

Secure Code Review information

What is secure code review?

Secure code review is the process of systematically examining application source code to identify and remediate security vulnerabilities before software is released. This review can be performed manually or with automated tools, focusing on areas where coding errors could lead to security risks such as injection attacks, data leaks, or authentication flaws. The goal is to ensure that the code adheres to secure coding standards and best practices, ultimately reducing the risk of exploitation by malicious actors.

What are the key skills and qualifications needed to thrive as a secure code reviewer?

To thrive as a Secure Code Reviewer, you need a solid understanding of secure coding practices, programming languages (such as Java, Python, or C++), and common software vulnerabilities, often supported by relevant security certifications like CISSP or CSSLP. Familiarity with automated code analysis tools, static application security testing (SAST) platforms, and bug tracking systems is typically required. Strong analytical thinking, attention to detail, and clear communication skills set outstanding reviewers apart. These abilities are crucial for identifying, explaining, and mitigating security risks in code, ensuring robust application security.

What are some common challenges faced by professionals performing secure code reviews, and how can they be addressed?

Secure code reviewers often encounter challenges such as keeping up with evolving security threats, identifying subtle vulnerabilities in complex codebases, and maintaining effective communication with development teams. To address these, reviewers should stay updated on the latest security trends, use automated tools to assist in identifying potential issues, and foster collaborative relationships with developers to ensure that findings are understood and remediated effectively. Regular training, participating in security communities, and integrating secure code review into the software development lifecycle can also help overcome these challenges.

What is the difference between Secure Code Review vs Static Application Security Testing (SAST)?

AspectSecure Code ReviewStatic Application Security Testing (SAST)
CredentialsKnowledge of secure coding, programming languages, security standardsSecurity testing tools, programming knowledge, security certifications
Work EnvironmentManual review, developer collaboration, code analysisAutomated scanning, integration with CI/CD pipelines
Industry UsageDevelopment teams, security analysts, code auditsSecurity teams, QA, DevOps, automated security testing

Secure Code Review involves manual or semi-automated analysis of source code to identify security flaws, emphasizing developer collaboration. SAST uses automated tools to scan code for vulnerabilities during development, enabling faster detection. Both roles aim to improve code security but differ in approach: one is manual and detailed, the other automated and scalable.

What job categories do people searching Secure Code Review jobs in New York look for? The top searched job categories for Secure Code Review jobs in New York are:
Infographic showing various Secure Code Review job openings in New York as of August 2026, with employment types broken down into 67% Full Time, 11% Part Time, and 22% Contract. Highlights an 67% In-person, 11% Hybrid, and 22% Remote job distribution.

Application Offensive Security Lead (Associate Director)

Real Careers

Jersey City, NJ โ€ข Hybrid

$64.25 - $85.75/hr

Full-time

Medical, Life, Retirement, PTO

Re-posted 6 days ago


Job description

Application Offensive Security Lead (Associate Director)

Jersey City, NJ 07310

Must be a US Citizen or Green Card holder. - No Exceptions

  • The Associate Director of Application Offensive Security Lead is responsible for leading, providing technical direction and strategy on all the matters related to above mentioned functions Application Offensive Security testing, AppSec Threat modeling, Manual Secure code review, and Threat hunting, Cloud and Containers.
  • You will build, operate, and optimize the capabilities by combining the Application Offensive Security testing, Threat Modeling, Manual secure code review, and Advance Threat hunting techniques.
  • You will be responsible for performing the Threat modeling and assess the Threats at design stage and perform manual secure code reviews to assess the code level security risks which cannot be identified by automated scanners and perform advance threat exploit techniques to prove the vulnerabilities with evidence in pre-production environment.

RESPONSIBILITIES:

  • Sets strategy, provide technical direction to the Application Offensive Security team to run capabilities like AppSec Red team assessment/offensive security testing, Application Threat modeling, Manual secure code review, Advance Threat hunting techniques and Container security.
  • Run day to day operations including Performing AppSec Threat modeling on the DTCC application design architectures, Manual secure code review of in-house developed and advance penetration testing techniques to identify the vulnerabilities which cannot be reported by automated SAST & DAST scanners.
  • Lead a robust team of AppSec Consultants and AppSec Specialists and coordinate with various partners and vendors as part of AppSec ecosystem.
  • Generate reports on assessment findings and summarizes to facilitate remediation, Document technical issues identified during security assessments applying standard CWE and CVSS classifications.
  • Defines and supervises application vulnerability and coverage KPIs/metrics to demonstrate assessment coverage and remediation efficiency.
  • Collaborate with Security Architects, Product Manager, Risk Managers, and other teams to deliver high quality products.
  • Interacts with senior management on matters where they may need to gain acceptance on an alternate approach.
  • Cultivate and manage relationships with key partners at varying organizational levels.
  • Assist with executive communication to senior leadership teams on status of Application Offensive Security programs.

Benefits:

Competitive compensation, including base pay and annual incentive.

Comprehensive health and life insurance and well-being benefits, based on location.

Pension / Retirement benefits

Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.

They offer a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee)


QUALIFICATIONS:

  • At least 10 years of multifaceted IT experience, preferably in information security and related experience
  • Bachelorsโ€™ Degree in related field and/or equivalent experience
  • Domain specialist in several security technologies (depth) with ability to lead across enterprise Application security functions (breadth)
  • Exposure to the Application Security Vulnerabilities (as listed in OWASP Top 10 and SANS Top 25), Security Testing methodologies and related tools such as Fortify, WebInspect, Burp Suite, Nexus and more.
  • Programming experience with at least one of these skills: Java/J2EE, JavaScript, Python, etc. and experience in performing manual secure code review of popular web application programming languages (Java, JavaScript, Angular, Python etc.)
  • Understanding of Authentication, Authorization mechanism programmatically across different web technologies and protocols (SSL/TLS, REST, OAuth, SAML etc.)
  • Experience working with DAST, SAST, and Penetration testing tools.
  • Experience with Application development build pipelines, automation, and CI/CD
  • A broad and deep understanding of cybersecurity threats, vulnerabilities, controls, and remediation strategies
  • Knowledge on large scale cloud-based services, Container security and very good understanding of security challenges involved in deploying Cloud and container applications.
  • Experience in facilitating technical conversations between engineering and operations teams.
  • Experience in leading global teams, remote employees and evaluating team member performance and offering career development mentorship.
  • Excellent verbal and written communication skills
  • Experience handling relationships with and addressing senior management.
  • Ability to work under stress, multitask and be flexible.
  • Strong planning and project management skills
  • Highly desired - one or more of the following active certifications CSSLP, CISSP, OSCP, GIAC GPEN


Required Knowledge, Skills, and Abilities: (Companies ATS Questions):

1. Do you have at least 10 years of multifaceted IT experience, preferably in information security and related experience

2. Do you have a Bachelorsโ€™ Degree in related field and/or equivalent experience

3. Are you a domain specialist in several security technologies (depth) with ability to lead across enterprise Application security functions (breadth)

4. Do you have exposure to the Application Security Vulnerabilities (as listed in OWASP Top 10 and SANS Top 25), Security Testing methodologies and related tools such as Fortify, WebInspect, Burp Suite, Nexus and more.

5. Do you have programming experience with at least one of these skills: Java/J2EE, JavaScript, Python, etc. and experience in performing manual secure code review of popular web application programming languages (Java, JavaScript, Angular, Python etc.)

6. Do you have you have a understanding of Authentication, Authorization mechanism programmatically across different web technologies and protocols (SSL/TLS, REST, OAuth, SAML etc.)

7. Do you have experience working with DAST, SAST, and Penetration testing tools.

8. Do you have experience with Application development build pipelines, automation, and CI/CD

9. Do you have a broad and deep understanding of cybersecurity threats, vulnerabilities, controls, and remediation strategies

10. Do you have knowledge on large scale cloud-based services, Container security and very good understanding of security challenges involved in deploying Cloud and container applications.

11. Do you have experience in leading global teams, remote employees and evaluating team member performance and offering career development mentorship.

12. Do you have strong planning and project management skills

13. Do you have - one or more of the following active certifications CSSLP, CISSP, OSCP, GIAC GPEN - Highly desired


14. Must be a US Citizen or Green Card holder. 



Application Offensive Security Lead (Associate Director)

Jersey City, NJ 07310

Must be a US Citizen or Green Card holder. - No Exceptions

  • The Associate Director of Application Offensive Security Lead is responsible for leading, providing technical direction and strategy on all the matters related to above mentioned functions Application Offensive Security testing, AppSec Threat modeling, Manual Secure code review, and Threat hunting, Cloud and Containers.
  • You will build, operate, and optimize the capabilities by combining the Application Offensive Security testing, Threat Modeling, Manual secure code review, and Advance Threat hunting techniques.
  • You will be responsible for performing the Threat modeling and assess the Threats at design stage and perform manual secure code reviews to assess the code level security risks which cannot be identified by automated scanners and perform advance threat exploit techniques to prove the vulnerabilities with evidence in pre-production environment.

RESPONSIBILITIES:

  • Sets strategy, provide technical direction to the Application Offensive Security team to run capabilities like AppSec Red team assessment/offensive security testing, Application Threat modeling, Manual secure code review, Advance Threat hunting techniques and Container security.
  • Run day to day operations including Performing AppSec Threat modeling on the DTCC application design architectures, Manual secure code review of in-house developed and advance penetration testing techniques to identify the vulnerabilities which cannot be reported by automated SAST & DAST scanners.
  • Lead a robust team of AppSec Consultants and AppSec Specialists and coordinate with various partners and vendors as part of AppSec ecosystem.
  • Generate reports on assessment findings and summarizes to facilitate remediation, Document technical issues identified during security assessments applying standard CWE and CVSS classifications.
  • Defines and supervises application vulnerability and coverage KPIs/metrics to demonstrate assessment coverage and remediation efficiency.
  • Collaborate with Security Architects, Product Manager, Risk Managers, and other teams to deliver high quality products.
  • Interacts with senior management on matters where they may need to gain acceptance on an alternate approach.
  • Cultivate and manage relationships with key partners at varying organizational levels.
  • Assist with executive communication to senior leadership teams on status of Application Offensive Security programs.

Benefits:

Competitive compensation, including base pay and annual incentive.

Comprehensive health and life insurance and well-being benefits, based on location.

Pension / Retirement benefits

Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.

They offer a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee)


QUALIFICATIONS:

  • At least 10 years of multifaceted IT experience, preferably in information security and related experience
  • Bachelorsโ€™ Degree in related field and/or equivalent experience
  • Domain specialist in several security technologies (depth) with ability to lead across enterprise Application security functions (breadth)
  • Exposure to the Application Security Vulnerabilities (as listed in OWASP Top 10 and SANS Top 25), Security Testing methodologies and related tools such as Fortify, WebInspect, Burp Suite, Nexus and more.
  • Programming experience with at least one of these skills: Java/J2EE, JavaScript, Python, etc. and experience in performing manual secure code review of popular web application programming languages (Java, JavaScript, Angular, Python etc.)
  • Understanding of Authentication, Authorization mechanism programmatically across different web technologies and protocols (SSL/TLS, REST, OAuth, SAML etc.)
  • Experience working with DAST, SAST, and Penetration testing tools.
  • Experience with Application development build pipelines, automation, and CI/CD
  • A broad and deep understanding of cybersecurity threats, vulnerabilities, controls, and remediation strategies
  • Knowledge on large scale cloud-based services, Container security and very good understanding of security challenges involved in deploying Cloud and container applications.
  • Experience in facilitating technical conversations between engineering and operations teams.
  • Experience in leading global teams, remote employees and evaluating team member performance and offering career development mentorship.
  • Excellent verbal and written communication skills
  • Experience handling relationships with and addressing senior management.
  • Ability to work under stress, multitask and be flexible.
  • Strong planning and project management skills
  • Highly desired - one or more of the following active certifications CSSLP, CISSP, OSCP, GIAC GPEN


Required Knowledge, Skills, and Abilities: (Companies ATS Questions):

1. Do you have at least 10 years of multifaceted IT experience, preferably in information security and related experience

2. Do you have a Bachelorsโ€™ Degree in related field and/or equivalent experience

3. Are you a domain specialist in several security technologies (depth) with ability to lead across enterprise Application security functions (breadth)

4. Do you have exposure to the Application Security Vulnerabilities (as listed in OWASP Top 10 and SANS Top 25), Security Testing methodologies and related tools such as Fortify, WebInspect, Burp Suite, Nexus and more.

5. Do you have programming experience with at least one of these skills: Java/J2EE, JavaScript, Python, etc. and experience in performing manual secure code review of popular web application programming languages (Java, JavaScript, Angular, Python etc.)

6. Do you have you have a understanding of Authentication, Authorization mechanism programmatically across different web technologies and protocols (SSL/TLS, REST, OAuth, SAML etc.)

7. Do you have experience working with DAST, SAST, and Penetration testing tools.

8. Do you have experience with Application development build pipelines, automation, and CI/CD

9. Do you have a broad and deep understanding of cybersecurity threats, vulnerabilities, controls, and remediation strategies

10. Do you have knowledge on large scale cloud-based services, Container security and very good understanding of security challenges involved in deploying Cloud and container applications.

11. Do you have experience in leading global teams, remote employees and evaluating team member performance and offering career development mentorship.

12. Do you have strong planning and project management skills

13. Do you have - one or more of the following active certifications CSSLP, CISSP, OSCP, GIAC GPEN - Highly desired


14. Must be a US Citizen or Green