1

Secure Code Review Jobs (NOW HIRING)

Define and maintain secure development lifecycle practices including secure code review standards, API security patterns, and authentication/authorization frameworks * Develop self-service security ...

Ability to perform secure code review on infrastructure scripts and code. Identify vulnerabilities and provide guidance to development team and provide development support in remediating findings.

... Conduct secure code review trainings to developers - Understanding of OWASP, SANS, CWE standards, - Experience with enforcing application security in the SDLC of web applications - Develop ...

... Conduct secure code review trainings to developers - Understanding of OWASP, SANS, CWE standards, - Experience with enforcing application security in the SDLC of web applications - Develop ...

... guidance on secure architecture and coding practices - Build automated, continuous security assessment capabilities that replace manual security reviews and scale across our business unit ...

Lead AI AppSec Engineer

New York, NY

$64.25 - $86/hr

Conduct secure code reviews and support vulnerability remediation * Integrate and operate security tooling such as SAST, DAST, and SCA within CI/CD pipelines * Help define guardrails, monitoring, and ...

Lead AI AppSec Engineer

Irvine, CA

$63 - $84.25/hr

Conduct secure code reviews and support vulnerability remediation * Integrate and operate security tooling such as SAST, DAST, and SCA within CI/CD pipelines * Help define guardrails, monitoring, and ...

This position is accountable for application-specific security controls, threat modeling, security architecture reviews, secure code practices, and security testing coordination. Responsible for ...

This position is accountable for application-specific security controls, threat modeling, security architecture reviews, secure code practices, and security testing coordination. Responsible for ...

Senior Security Engineer

San Francisco, CA · On-site

$134K - $185K/yr

Required : • Have 5+ years of hands-on application security engineering experience • Expertise in secure software development practices, including threat modeling, secure code review, and ...

They will set secure development standards, conduct secure code reviews, and integrate security into our CI/CD pipelines. Their expertise in vulnerability management will be essential for identifying ...

next page

Showing results 1-20

Secure Code Review information

See salary details

$29

$66

$96

How much do secure code review jobs pay per hour?

As of Jun 24, 2026, the average hourly pay for secure code review in the United States is $66.40, according to ZipRecruiter salary data. Most workers in this role earn between $56.49 and $75.48 per hour, depending on experience, location, and employer.

What is secure code review?

Secure code review is the process of systematically examining application source code to identify and remediate security vulnerabilities before software is released. This review can be performed manually or with automated tools, focusing on areas where coding errors could lead to security risks such as injection attacks, data leaks, or authentication flaws. The goal is to ensure that the code adheres to secure coding standards and best practices, ultimately reducing the risk of exploitation by malicious actors.

What are the key skills and qualifications needed to thrive as a Secure Code Reviewer, and why are they important?

To thrive as a Secure Code Reviewer, you need a solid understanding of secure coding practices, programming languages (such as Java, Python, or C++), and common software vulnerabilities, often supported by relevant security certifications like CISSP or CSSLP. Familiarity with automated code analysis tools, static application security testing (SAST) platforms, and bug tracking systems is typically required. Strong analytical thinking, attention to detail, and clear communication skills set outstanding reviewers apart. These abilities are crucial for identifying, explaining, and mitigating security risks in code, ensuring robust application security.

What are some common challenges faced by professionals performing secure code reviews, and how can they be addressed?

Secure code reviewers often encounter challenges such as keeping up with evolving security threats, identifying subtle vulnerabilities in complex codebases, and maintaining effective communication with development teams. To address these, reviewers should stay updated on the latest security trends, use automated tools to assist in identifying potential issues, and foster collaborative relationships with developers to ensure that findings are understood and remediated effectively. Regular training, participating in security communities, and integrating secure code review into the software development lifecycle can also help overcome these challenges.

What is the difference between Secure Code Review vs Static Application Security Testing (SAST)?

AspectSecure Code ReviewStatic Application Security Testing (SAST)
CredentialsKnowledge of secure coding, programming languages, security standardsSecurity testing tools, programming knowledge, security certifications
Work EnvironmentManual review, developer collaboration, code analysisAutomated scanning, integration with CI/CD pipelines
Industry UsageDevelopment teams, security analysts, code auditsSecurity teams, QA, DevOps, automated security testing

Secure Code Review involves manual or semi-automated analysis of source code to identify security flaws, emphasizing developer collaboration. SAST uses automated tools to scan code for vulnerabilities during development, enabling faster detection. Both roles aim to improve code security but differ in approach: one is manual and detailed, the other automated and scalable.

More about Secure Code Review jobs
What states have the most Secure Code Review jobs? States with the most job openings for Secure Code Review jobs include:
Senior Cybersecurity Engineer - Clearance Required with Security Clearance

Senior Cybersecurity Engineer - Clearance Required with Security Clearance

Cydecor

Norfolk, VA • On-site

$110K - $152K/yr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 7 days ago


Job description

Cydecor is a premier Federal Government solutions provider, delivering differentiated innovations in mission systems and business platforms. We leverage leading-edge secure systems and software development, backed by industry-leading subject matter expertise, and business intelligence to enable decision-support and remain ahead of ever-evolving national security challenges. Our success rests squarely on three bedrock principles: People, our center of gravity; Mission, what inspires us; and an unyielding commitment to Excellence, what separates us.

Job Description: We're looking for a Senior Cybersecurity Engineer to lead the security side of software delivery on a large Navy readiness reporting program. You'll work shoulder-to-shoulder with the development teams - embedding security into how code is designed, built, tested, and deployed, not bolting it on at the end. This is a hands-on technical leadership role, not a paperwork role.

You'll set the DevSecOps standards and tooling, drive secure design and code reviews, coach engineers on secure practices, and lead a small cybersecurity team. You'll also stay close enough to the RMF posture to make sure the program stays accredited as systems evolve. Responsibilities include: Primary Responsibilities * Lead DevSecOps practice across multiple development teams.

Set the standards, the toolchain, and the bar. * Integrate SAST, DAST, software composition analysis, container and image scanning, and IaC scanning into CI/CD pipelines. Tune the tools so they catch what matters and don't drown the teams in noise.

* Drive secure design reviews, threat modeling, and code-level remediation guidance. Push back on design decisions that create unnecessary risk - and explain why. * Own the cybersecurity engineering posture: vulnerability response, patching cadence, hardening baselines, and the program's ongoing RMF/ATO health as the software evolves.

* Lead and mentor a small cybersecurity team. Coach developers on secure coding. Represent cybersecurity in technical decisions with the customer, software leads, and program leadership.

Additional duties and Responsibilities of the Cybersecurity Lead Engineer include, but are not limited to the following: * Stay current. DoD cyber guidance, tooling, and best practices keep moving - bring useful changes back to the team and the program. * Communicate cybersecurity posture and risk clearly - in writing and out loud - to people who don't live in the details day to day.

* Build the team's standards and reusable patterns. Don't make the next person solve the same problem from scratch. * Take ownership.

When something is broken or missing, fix it or get it fixed. Here's what you need: * 10+ years in cybersecurity engineering, with 5+ years specialized in network and application security. * Demonstrated DevSecOps experience: integrating security testing into CI/CD pipelines using tools like SonarQube, Fortify, Checkmarx, or Snyk in Azure DevOps or comparable platforms.

* Hands-on with secure SDLC, threat modeling, secure code review, container security, IaC scanning, and SBOM practices. * 5+ years implementing RMF for DoD systems, including continuous monitoring and ATO sustainment as the software changes around you. * IAM Level II Information Assurance Certification (per DoDI 8570.01-M and SECNAV M-5239.2), or equivalent under DoDM 8140.03 at Intermediate or Advanced proficiency.

* Active CISSP or Qualified Navy Validator required. Bonus Points If You Have: * Qualified Navy Validator designation; CSSLP, CCSP, GWAPT, or similar; prior work on DoD or Navy software programs; experience hardening cloud workloads. Security Clearance: * DoD Secret Clearance Education: * Master's degree in computer science, cybersecurity, engineering, or a related technical field.

Bachelor's with significant additional relevant experience considered. Work Schedule: * M-F, 8 hours Compensation and Benefits: Cydecor offers a comprehensive compensation package including Health and Dental Insurance, Vision and Life Insurance, Short-Term & Long-Term Disability, 401(K) + company match, Paid Time Off (PTO), Paid Company Holidays, Tuition and Professional Development Assistance and more. What We Believe We have an unwavering commitment to diversity with the aim that every one of our people has a full sense of belonging within our organization.

As a business imperative, every person at Cydecor has the responsibility to create and sustain an inclusive environment. Key Words: Cybersecurity Engineer, Senior Cybersecurity Engineer, Lead Cybersecurity Engineer, DevSecOps Engineer, DevSecOps Lead, Application Security, Software Security, Security Engineer, Cybersecurity Architect, Secure Software Development, Secure SDLC, DevSecOps, CI/CD, Azure DevOps, Security Automation, Secure Coding, Threat Modeling, Secure Code Review, SAST, DAST, Software Composition Analysis (SCA), Container Security, Infrastructure as Code (IaC), SBOM, Vulnerability Management, Security Hardening, RMF, Risk Management Framework, ATO, Continuous Monitoring, eMASS, NIST 800-53, Security Compliance, Information Assurance, ISSE, Cloud Security, AWS, Azure, Kubernetes, Docker, SonarQube, Fortify, Checkmarx, Snyk, CISSP, CSSLP, CCSP, Qualified Navy Validator, IAM Level II, DoD 8570, DoDM 8140, U.S. Navy, Department of Defense, DoD, Federal Government, GovCon, Mission Systems, Cleared Jobs, Secret Clearance Equal Employment Opportunity Statement Cydecor is an Equal Employment Opportunity/Affirmative Action Employer (EEO/AA).

All employment and hiring decisions are based on qualifications, merit, and business needs without regard to race, religion, color, sexual orientation, nationality, gender, ethnic origin, disability, age, sex, gender identity & expression, veteran status, marital status, or any other characteristic protected by applicable law. If you are a qualified individual with a disability and/or a disabled veteran, you may request a reasonable accommodation if you are unable or limited in your ability to access job openings or apply for a job on this site because of your disability. You can request assistance by contacting or calling 703-884-2105.