1

Secure Code Review Jobs in New York (NOW HIRING)

Responsibilities : • Cultivates security culture across product, technology, and business teams by embedding threat modeling, security architecture reviews, and secure code practices, ensuring ...

Lead secure design reviews, threat modeling, code review, and penetration testing for high-risk products such as crypto custody, trading systems, and payments * Build and ship code: design and build ...

Lead secure design reviews, threat modeling, code review, and penetration testing for high-risk products such as crypto custody, trading systems, and payments * Build and ship code: design and build ...

Sr. Application Security Engineer

Montvale, NJ · On-site

$61.50 - $82/hr

... Secure code review experience using automated toolsets Software Engineering career experience Following Certifications: CISSP, CEH, GWAPT, GPEN, OSCP Thorough understanding of software ...

Sr. Application Security Engineer

Montvale, NJ · On-site

$61.50 - $82/hr

... • Secure code review experience using automated toolsets • Software Engineering career experience • Following Certifications: CISSP, CEH, GWAPT, GPEN, OSCP • Thorough understanding of ...

Showing results 21-40

Secure Code Review information

What is secure code review?

Secure code review is the process of systematically examining application source code to identify and remediate security vulnerabilities before software is released. This review can be performed manually or with automated tools, focusing on areas where coding errors could lead to security risks such as injection attacks, data leaks, or authentication flaws. The goal is to ensure that the code adheres to secure coding standards and best practices, ultimately reducing the risk of exploitation by malicious actors.

What are the key skills and qualifications needed to thrive as a secure code reviewer?

To thrive as a Secure Code Reviewer, you need a solid understanding of secure coding practices, programming languages (such as Java, Python, or C++), and common software vulnerabilities, often supported by relevant security certifications like CISSP or CSSLP. Familiarity with automated code analysis tools, static application security testing (SAST) platforms, and bug tracking systems is typically required. Strong analytical thinking, attention to detail, and clear communication skills set outstanding reviewers apart. These abilities are crucial for identifying, explaining, and mitigating security risks in code, ensuring robust application security.

What are some common challenges faced by professionals performing secure code reviews, and how can they be addressed?

Secure code reviewers often encounter challenges such as keeping up with evolving security threats, identifying subtle vulnerabilities in complex codebases, and maintaining effective communication with development teams. To address these, reviewers should stay updated on the latest security trends, use automated tools to assist in identifying potential issues, and foster collaborative relationships with developers to ensure that findings are understood and remediated effectively. Regular training, participating in security communities, and integrating secure code review into the software development lifecycle can also help overcome these challenges.

What is the difference between Secure Code Review vs Static Application Security Testing (SAST)?

AspectSecure Code ReviewStatic Application Security Testing (SAST)
CredentialsKnowledge of secure coding, programming languages, security standardsSecurity testing tools, programming knowledge, security certifications
Work EnvironmentManual review, developer collaboration, code analysisAutomated scanning, integration with CI/CD pipelines
Industry UsageDevelopment teams, security analysts, code auditsSecurity teams, QA, DevOps, automated security testing

Secure Code Review involves manual or semi-automated analysis of source code to identify security flaws, emphasizing developer collaboration. SAST uses automated tools to scan code for vulnerabilities during development, enabling faster detection. Both roles aim to improve code security but differ in approach: one is manual and detailed, the other automated and scalable.

What job categories do people searching Secure Code Review jobs in New York look for? The top searched job categories for Secure Code Review jobs in New York are:
Infographic showing various Secure Code Review job openings in New York as of August 2026, with employment types broken down into 67% Full Time, 11% Part Time, and 22% Contract. Highlights an 67% In-person, 11% Hybrid, and 22% Remote job distribution.

Product Security Principal

Flagstar Bank

Manhattan, NY • On-site

Full-time

Re-posted 3 days ago


Job description

Job Summary:
Flagstar Bank is seeking a Product Security Principal who will act as the embedded security subject matter expert for assigned product lines. This role is responsible for cultivating a security-first culture, managing security risks, and ensuring secure practices are followed throughout the product lifecycle.
Responsibilities:
• Cultivates security culture across product, technology, and business teams by embedding threat modeling, security architecture reviews, and secure code practices, ensuring products adopt security controls and are secure from design through deployment.
• Owns application-specific security requirements, threat modeling, security architecture design, authentication/authorization design, and data classification/handling standards in partnership with Tech Leads and Business Architects.
• Leads security testing, vulnerability assessments, penetration testing coordination, and security validation activities, tracking security defect remediation and ensuring compliance with secure coding standards.
• Prepares and delivers Technology Review Board security artifacts including Initial Design Review security assessments, Production Release Review security validation, and security incident response plans.
• Proactively monitors Key Risk Indicators, manages emerging security issues with urgency, identifies root causes and themes, and provides timely recommendations for resolution to the BURM and leadership.
• Partners with Third Party Oversight teams to ensure effective technology risk management of vendors, with focus on Cloud computing, SaaS tools, and emerging technologies engaged by technology partners.
• Collaborates on business-as-usual audit and regulatory engagements, translating firmwide policy and regulatory requirements into control designs for Software Engineers and SRE teams.
• Serves as the product’s security thought leader, sharing best practices between product and cybersecurity teams, and acting as the clear point of escalation and subject matter expert for IT Risk and Cyber domains.
• Performs special projects, and additional duties and responsibilities as required.
Qualifications:
Required:
• Education level preferred: High School / High School Equivalency (GED, HiSET, TASC) / Foreign Equivalent
• Minimum experience required: 8+ Years in information security, cybersecurity, or technology risk management with strong security and technical skills in a regulated organization
• Experience operating in a 3 Lines of Defense (3LoD) model with demonstrated ability to translate policy and regulatory requirements into control designs for engineers and architects
• Proven ability to communicate effectively and authoritatively with technical and non-technical stakeholders, explaining complex security concepts in simple terms
• Expert knowledge of application security principles, threat modeling methodologies, and secure software development lifecycle (SSDLC) practices.
• Deep understanding of cloud security architecture, identity and access management, secrets management, and data protection controls.
• Strong understanding of vulnerability assessment, penetration testing, secure code review, and security testing methodologies.
• Ability to think in terms of risks and outcomes, translating them into actions required to achieve business and technology goals.
• Knowledge of regulatory compliance frameworks, 3 Lines of Defense model, and control design principles for financial institutions.
• Delivery excellence mixed with strategic vision; ability to balance tactical security needs with long-term security architecture goals.
• Excellent written and verbal communication skills with ability to explain complex technical security concepts in simple terms.
• Demonstrated success influencing peers inside and outside your department without direct authority.
• Self-motivated learner with proven experience upskilling on modern technologies and security practices.
• Experience with DevSecOps tooling, CI/CD security integration, code scanning, and container security at build and runtime.
• Knowledge of endpoint security, email security, and workforce technology protection strategies.
• Understanding of third-party risk management, vendor security assessments, and SaaS security considerations.
• Ability to monitor Key Risk Indicators and act with urgency managing emerging security issues.
• Ability to mentor and guide development teams on secure coding practices and security best practices.
• Flexibility to adapt to evolving threat landscape and emerging security technologies.
• Ability to work collaboratively with product, technology, and business colleagues at all levels.
• Understanding of product operating framework and cross-functional collaboration with Business Architects, Tech Leads, and SRE teams.
• Deep understanding of security incident response, root cause analysis, and corrective action implementation.
• Experience presenting security assessments and recommendations to Technology Review Boards and executive leadership.
• Critical thinking mindset with ability to identify hidden security issues and unfamiliar technology risks.
• Recognized as a security thought leader with ability to share best practices across product and cybersecurity teams.
• Demonstrates a strong ability to build and maintain effective relationships with stakeholders by communicating clearly, engaging in proactive collaboration, and leveraging cross functional insights. Aligns relationship building efforts with enterprise goals to accelerate performance and drive strategic results.
• Builds trusted client relationships, whether internal or external, by identifying needs and delivering tailored solutions to enhance the overall client experience.
• Fosters or supports a positive work culture and productive work environment, displaying importance of effective relationships with customers and stakeholders.
• Minimal travel required
• Physical demands (ADA): No unusual physical exertion is involved.
Preferred:
• Education level preferred: Undergraduate Degree (4 years or equivalent)
• Technical understanding of Public Cloud computing (Azure/AWS), including cloud hardening, data protection controls, resiliency, and access management. Experience with APIs/microservices, IAM, Secrets Management, DevSecOps, and SSDLC preferred.
• Financial services and banking experience preferred; experience in industries with similar risk tolerance acceptable. CISSP, CISM, or equivalent security certifications strongly preferred.
Company:
Thank you for visiting Flagstar Bank, N.A. on LinkedIn, and we look forward to being part of your financial journey. Founded in 1987, the company is headquartered in Troy, USA, with a team of 5001-10000 employees. The company is currently Late Stage.