This position is accountable for application-specific security controls, threat modeling, security architecture reviews, secure code practices, and security testing coordination. Responsible for ...
This position is accountable for application-specific security controls, threat modeling, security architecture reviews, secure code practices, and security testing coordination. Responsible for ...
Application Security Engineer (Tech Lead) ID71666
Downey, CA · On-site +1
$61 - $81.75/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Downey, CA · On-site +1
$61 - $81.75/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Code Review Software/Application Penetration Testing Architecture Security Analysis and Threat Modeling Secure Software Design, Architecture, and Engineering Software/Application Reverse Engineering ...
Code Review Software/Application Penetration Testing Architecture Security Analysis and Threat Modeling Secure Software Design, Architecture, and Engineering Software/Application Reverse Engineering ...
Application Security Engineer (Tech Lead) ID71666
Richmond, VA · On-site +1
$58.25 - $77.75/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Richmond, VA · On-site +1
$58.25 - $77.75/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Dallas, TX · On-site +1
$58 - $77.75/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Dallas, TX · On-site +1
$58 - $77.75/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Austin, TX · On-site
$58.25 - $77.75/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Austin, TX · On-site
$58.25 - $77.75/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Analyst
Miami, FL · On-site
Experience with penetration testing, threat modeling, or secure code review * Background in bug bounty programs or red teaming * Familiarity with AI or machine learning evaluation workflows Why Join ...
Application Security Analyst
Miami, FL · On-site
Experience with penetration testing, threat modeling, or secure code review * Background in bug bounty programs or red teaming * Familiarity with AI or machine learning evaluation workflows Why Join ...
Application Security Engineer (Tech Lead) ID71666
San Francisco, CA · On-site +1
$69.25 - $92.50/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
San Francisco, CA · On-site +1
$69.25 - $92.50/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Richmond, VA · On-site +1
$58.25 - $77.75/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Richmond, VA · On-site +1
$58.25 - $77.75/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Baltimore, MD · On-site +1
$58.50 - $78/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Baltimore, MD · On-site +1
$58.50 - $78/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Blacksburg, VA · On-site +1
$51.50 - $68.75/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Blacksburg, VA · On-site +1
$51.50 - $68.75/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Dallas, TX · On-site +1
$58 - $77.75/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Dallas, TX · On-site +1
$58 - $77.75/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Texas City, TX · On-site +1
$50.25 - $67.25/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Texas City, TX · On-site +1
$50.25 - $67.25/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Baltimore, MD · On-site +1
$58.50 - $78/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Baltimore, MD · On-site +1
$58.50 - $78/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Tampa, FL · On-site
$55.50 - $74.25/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Tampa, FL · On-site
$55.50 - $74.25/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Tampa, FL · On-site +1
$55.50 - $74.25/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Tampa, FL · On-site +1
$55.50 - $74.25/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
... secure code review, and security testing Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Our ...
... secure code review, and security testing Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Our ...
Application Security Engineer (Tech Lead) ID71666
West Palm Beach, FL · On-site +1
$56.75 - $76/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
West Palm Beach, FL · On-site +1
$56.75 - $76/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
West Palm Beach, FL · On-site +1
$56.75 - $76/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
West Palm Beach, FL · On-site +1
$56.75 - $76/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Los Angeles, CA · On-site +1
$63.25 - $84.50/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Application Security Engineer (Tech Lead) ID71666
Los Angeles, CA · On-site +1
$63.25 - $84.50/hr
You will facilitate clean shift hand-offs with peer leads across timezones, own regional technical escalations, perform secure code reviews, and drive 24-hour delivery velocity in a highly regulated ...
Secure Code Review information
See salary details
$29.81 - $35.86
1% of jobs
$35.86 - $41.91
1% of jobs
$41.91 - $47.97
2% of jobs
$47.97 - $54.02
13% of jobs
$56.22 is the 25th percentile. Wages below this are outliers.
$54.02 - $60.07
23% of jobs
The median wage is $64.40 / hr.
$60.07 - $66.13
15% of jobs
$66.13 - $72.18
16% of jobs
$74.34 is the 75th percentile. Wages above this are outliers.
$72.18 - $78.23
15% of jobs
$78.23 - $84.29
7% of jobs
$84.29 - $90.34
4% of jobs
$90.34 - $96.39
4% of jobs
$29
$66
$96
How much do secure code review jobs pay per hour?
What is secure code review?
What are the key skills and qualifications needed to thrive as a Secure Code Reviewer, and why are they important?
What are some common challenges faced by professionals performing secure code reviews, and how can they be addressed?
What is the difference between Secure Code Review vs Static Application Security Testing (SAST)?
| Aspect | Secure Code Review | Static Application Security Testing (SAST) |
|---|---|---|
| Credentials | Knowledge of secure coding, programming languages, security standards | Security testing tools, programming knowledge, security certifications |
| Work Environment | Manual review, developer collaboration, code analysis | Automated scanning, integration with CI/CD pipelines |
| Industry Usage | Development teams, security analysts, code audits | Security teams, QA, DevOps, automated security testing |
Secure Code Review involves manual or semi-automated analysis of source code to identify security flaws, emphasizing developer collaboration. SAST uses automated tools to scan code for vulnerabilities during development, enabling faster detection. Both roles aim to improve code security but differ in approach: one is manual and detailed, the other automated and scalable.
Full-time
Medical, Dental, Vision, Life
Posted 17 days ago
Job description
Position Title
Product Security PrincipalLocation
New York, NY 10018Job Summary
Serves as the embedded security subject matter expert and thought lead for assigned product lines within the product operating model framework. Partners with the Technology Line of Business Lead, Business Architect, and Business Unit Risk Manager (BURM) to cultivate a security-first culture, ensuring products are secure from design through deployment. This position is accountable for application-specific security controls, threat modeling, security architecture reviews, secure code practices, and security testing coordination. Responsible for identifying and managing security risks, translating regulatory and policy requirements into actionable control designs, and serving as the clear point of escalation for IT Risk and Cyber domains within the product. Acts with urgency to monitor Key Risk Indicators, manage emerging security issues, and drive real risk reduction outcomes across the product's technology supply chain.Job Responsibilities:
JOB RESPONSIBILITIES
- Cultivates security culture across product, technology, and business teams by embedding threat modeling, security architecture reviews, and secure code practices, ensuring products adopt security controls and are secure from design through deployment.
- Owns application-specific security requirements, threat modeling, security architecture design, authentication/authorization design, and data classification/handling standards in partnership with Tech Leads and Business Architects.
- Leads security testing, vulnerability assessments, penetration testing coordination, and security validation activities, tracking security defect remediation and ensuring compliance with secure coding standards.
- Prepares and delivers Technology Review Board security artifacts including Initial Design Review security assessments, Production Release Review security validation, and security incident response plans.
- Proactively monitors Key Risk Indicators, manages emerging security issues with urgency, identifies root causes and themes, and provides timely recommendations for resolution to the BURM and leadership.
- Partners with Third Party Oversight teams to ensure effective technology risk management of vendors, with focus on Cloud computing, SaaS tools, and emerging technologies engaged by technology partners.
- Collaborates on business-as-usual audit and regulatory engagements, translating firmwide policy and regulatory requirements into control designs for Software Engineers and SRE teams.
- Serves as the product's security thought leader, sharing best practices between product and cybersecurity teams, and acting as the clear point of escalation and subject matter expert for IT Risk and Cyber domains.
ADDITIONAL ACCOUNTABILITIES
- Performs special projects, and additional duties and responsibilities as required.
- Where applicable and when performing the responsibilities of the job, employees are accountable to maintain regulatory compliance and adhere to internal policies, standards, and controls.
JOB REQUIREMENTS
- Education level preferred: High School / High School Equivalency (GED, HiSET, TASC) / Foreign Equivalent
- Minimum experience required: 8+ Years in information security, cybersecurity, or technology risk management with strong security and technical skills in a regulated organization
- Experience operating in a 3 Lines of Defense (3LoD) model with demonstrated ability to translate policy and regulatory requirements into control designs for engineers and architects
- Proven ability to communicate effectively and authoritatively with technical and non-technical stakeholders, explaining complex security concepts in simple terms
Preferred Qualifications:
- Education level preferred: Undergraduate Degree (4 years or equivalent)
- Technical understanding of Public Cloud computing (Azure/AWS), including cloud hardening, data protection controls, resiliency, and access management. Experience with APIs/microservices, IAM, Secrets Management, DevSecOps, and SSDLC preferred.
- Financial services and banking experience preferred; experience in industries with similar risk tolerance acceptable. CISSP, CISM, or equivalent security certifications strongly preferred.
Job Competencies:
- Expert knowledge of application security principles, threat modeling methodologies, and secure software development lifecycle (SSDLC) practices.
- Deep understanding of cloud security architecture, identity and access management, secrets management, and data protection controls.
- Strong understanding of vulnerability assessment, penetration testing, secure code review, and security testing methodologies.
- Ability to think in terms of risks and outcomes, translating them into actions required to achieve business and technology goals.
- Knowledge of regulatory compliance frameworks, 3 Lines of Defense model, and control design principles for financial institutions.
- Delivery excellence mixed with strategic vision; ability to balance tactical security needs with long-term security architecture goals.
- Excellent written and verbal communication skills with ability to explain complex technical security concepts in simple terms.
- Demonstrated success influencing peers inside and outside your department without direct authority.
- Self-motivated learner with proven experience upskilling on modern technologies and security practices.
- Experience with DevSecOps tooling, CI/CD security integration, code scanning, and container security at build and runtime.
- Knowledge of endpoint security, email security, and workforce technology protection strategies.
- Understanding of third-party risk management, vendor security assessments, and SaaS security considerations.
- Ability to monitor Key Risk Indicators and act with urgency managing emerging security issues.
- Ability to mentor and guide development teams on secure coding practices and security best practices.
- Flexibility to adapt to evolving threat landscape and emerging security technologies.
- Ability to work collaboratively with product, technology, and business colleagues at all levels.
- Understanding of product operating framework and cross-functional collaboration with Business Architects, Tech Leads, and SRE teams.
- Deep understanding of security incident response, root cause analysis, and corrective action implementation.
- Experience presenting security assessments and recommendations to Technology Review Boards and executive leadership.
- Critical thinking mindset with ability to identify hidden security issues and unfamiliar technology risks.
- Recognized as a security thought leader with ability to share best practices across product and cybersecurity teams.
- Demonstrates a strong ability to build and maintain effective relationships with stakeholders by communicating clearly, engaging in proactive collaboration, and leveraging cross functional insights. Aligns relationship building efforts with enterprise goals to accelerate performance and drive strategic results.
- Builds trusted client relationships, whether internal or external, by identifying needs and delivering tailored solutions to enhance the overall client experience.
- Fosters or supports a positive work culture and productive work environment, displaying importance of effective relationships with customers and stakeholders.
- Minimal travel required
- Physical demands (ADA): No unusual physical exertion is involved.
Flagstar is an Equal Opportunity Employer
We are committed to providing clear and accurate compensation information in accordance with applicable laws. Actual starting base pay will be determined based on location, experience, and other non-discriminatory factors permitted by law. Total compensation may also include variable incentives, bonuses, commissions, or other awards as outlined in the offer of employment. Flagstar provides teammates access to a variety of benefits including medical, dental, vision, life, and disability insurance, as well as a comprehensive leave program. Please click the following link for detailed information:Benefits | Flagstar Bank
Pay Range
$159,075.00 - $242,112.00About Flagstar Bank
Sourced by ZipRecruiter
Industry
Commercial banking
Company size
5,001 - 10,000 Employees
Headquarters location
Hicksville, NY, US