1

Secure Code Review Jobs (NOW HIRING)

... Conduct secure code review trainings to developers - Understanding of OWASP, SANS, CWE standards, - Experience with enforcing application security in the SDLC of web applications - Develop ...

... Conduct secure code review trainings to developers - Understanding of OWASP, SANS, CWE standards, - Experience with enforcing application security in the SDLC of web applications - Develop ...

This position is accountable for application-specific security controls, threat modeling, security architecture reviews, secure code practices, and security testing coordination. Responsible for ...

Application Security

Parsippany Troy Hills, NJ · On-site

$59 - $78.75/hr

Ability to sufficiently perform meaningful secure code review, validate SAST/SCA findings, and collaborate credibly with engineering teams on remediation * Experience working with change management ...

Senior Security Engineer

San Francisco, CA · On-site

$134K - $185K/yr

Required : • Have 5+ years of hands-on application security engineering experience • Expertise in secure software development practices, including threat modeling, secure code review, and ...

Sr. Security Engineer

New York, NY · On-site

$125K - $171K/yr

Lead application security reviews, threat modeling sessions, and secure code review for new features and significant product changes. * Operate and continuously improve SAST, DAST, and SCA tooling ...

... guidance on secure architecture and coding practices - Build automated, continuous security assessment capabilities that replace manual security reviews and scale across our business unit ...

This position is accountable for application-specific security controls, threat modeling, security architecture reviews, secure code practices, and security testing coordination. Responsible for ...

Secure Code Review * CI/CD Security Integration / Responsibilities The role focuses on embedding security testing, vulnerability management, and business logic validation directly into CI/CD ...

New

This position is accountable for application-specific security controls, threat modeling, security architecture reviews, secure code practices, and security testing coordination. Responsible for ...

This position is accountable for application-specific security controls, threat modeling, security architecture reviews, secure code practices, and security testing coordination. Responsible for ...

This position is accountable for application-specific security controls, threat modeling, security architecture reviews, secure code practices, and security testing coordination. Responsible for ...

This position is accountable for application-specific security controls, threat modeling, security architecture reviews, secure code practices, and security testing coordination. Responsible for ...

Sr. Application Security Engineer

$60.25 - $80.25/hr

Conduct or coordinate manual secure code review of security-sensitive components * Lead application penetration-testing cycles - scoping, managing testers, validating findings Developer Enablement

Code Review Software/Application Penetration Testing Architecture Security Analysis and Threat Modeling Secure Software Design, Architecture, and Engineering Software/Application Reverse Engineering ...

Sr. Security Engineer

Manhattan, NY · On-site

$170 - $200/hr

Lead application security reviews, threat modeling sessions, and secure code review for new features and significant product changes. * Operate and continuously improve SAST, DAST, and SCA tooling ...

Showing results 41-60

Secure Code Review information

See salary details

$29

$66

$96

How much do secure code review jobs pay per hour?

As of Aug 9, 2026, the average hourly pay for secure code review in the United States is $66.40, according to ZipRecruiter salary data. Most workers in this role earn between $56.49 and $75.48 per hour, depending on experience, location, and employer.

What is secure code review?

Secure code review is the process of systematically examining application source code to identify and remediate security vulnerabilities before software is released. This review can be performed manually or with automated tools, focusing on areas where coding errors could lead to security risks such as injection attacks, data leaks, or authentication flaws. The goal is to ensure that the code adheres to secure coding standards and best practices, ultimately reducing the risk of exploitation by malicious actors.

What are the key skills and qualifications needed to thrive as a secure code reviewer?

To thrive as a Secure Code Reviewer, you need a solid understanding of secure coding practices, programming languages (such as Java, Python, or C++), and common software vulnerabilities, often supported by relevant security certifications like CISSP or CSSLP. Familiarity with automated code analysis tools, static application security testing (SAST) platforms, and bug tracking systems is typically required. Strong analytical thinking, attention to detail, and clear communication skills set outstanding reviewers apart. These abilities are crucial for identifying, explaining, and mitigating security risks in code, ensuring robust application security.

What are some common challenges faced by professionals performing secure code reviews, and how can they be addressed?

Secure code reviewers often encounter challenges such as keeping up with evolving security threats, identifying subtle vulnerabilities in complex codebases, and maintaining effective communication with development teams. To address these, reviewers should stay updated on the latest security trends, use automated tools to assist in identifying potential issues, and foster collaborative relationships with developers to ensure that findings are understood and remediated effectively. Regular training, participating in security communities, and integrating secure code review into the software development lifecycle can also help overcome these challenges.

What is the difference between Secure Code Review vs Static Application Security Testing (SAST)?

AspectSecure Code ReviewStatic Application Security Testing (SAST)
CredentialsKnowledge of secure coding, programming languages, security standardsSecurity testing tools, programming knowledge, security certifications
Work EnvironmentManual review, developer collaboration, code analysisAutomated scanning, integration with CI/CD pipelines
Industry UsageDevelopment teams, security analysts, code auditsSecurity teams, QA, DevOps, automated security testing

Secure Code Review involves manual or semi-automated analysis of source code to identify security flaws, emphasizing developer collaboration. SAST uses automated tools to scan code for vulnerabilities during development, enabling faster detection. Both roles aim to improve code security but differ in approach: one is manual and detailed, the other automated and scalable.

More about Secure Code Review jobs
What states have the most Secure Code Review jobs? States with the most job openings for Secure Code Review jobs include:
Infographic showing various Secure Code Review job openings in the United States as of August 2026, with employment types broken down into 67% Full Time, 11% Part Time, and 22% Contract. Highlights an 67% In-person, 11% Hybrid, and 22% Remote job distribution, with an average salary of $138,117 per year, or $66.4 per hour.

Security Engineer - (VPC, VPN peering, network segmentation, IAM, secrets management)

VTekis Consulting LLP

New York, NY • On-site

Full-time

Posted 9 days ago


Job description

Company Description

We provide Recruitment and Staffing services to many industries and domain through our innovative and customized solutions and passionate commitment to research. Ability to understand the hiring strategies, availability of talent and compensation benchmarking makes us proud hiring partner for various industries. We work as trusted business partners and always strive to deliver the most value and highest return on investment for our clients. We are highly trained business professionals with strong understanding of clients need. We work closely with the leading staffing trade associations, training, and research organizations to ensure we are knowledgeable of thustry trends and technologies.

Job Description

Hard skills

AWS infrastructure security experience (VPC,​ VPN peering,​ network segmentation,​ IAM,​ secrets management)

Application security experience (threat modeling,​ dependency/supply-​chain controls,​ secure code review)

Identity and access management (SSO,​ RBAC,​ least-​privilege design) for both humans and non-​human actors

IT security (endpoint security,​ device management,​ access controls)

Compliance and auditability program experience (SOC2,​ pentest coordination,​ vulnerability management)

What we're looking for

We need an experienced security engineer with broad expertise across AWS infrastructure security, application security, and identity/access management who has owned security end-to-end as the first or sole security hire at a fast-moving startup. You should be comfortable operating with high autonomy in a small team, building security programs from scratch, and have a track record of making the secure path the easy path rather than gatekeeping. Bonus points if you have experience securing AI/agent systems or working in financial services.

What you'll do:

  • Own infrastructure security across the entire AWS environment — VPC/VPN peering, network segmentation, IAM, secrets management — designing guardrails that make the secure default also the fastest one
  • Take ownership of application security across web and desktop clients, embedding threat modeling, dependency/supply-chain controls, and secure code review into how the team designs and ships
  • Build and manage identity and access controls (SSO, RBAC, least-privilege) for both humans and AI agents, ensuring every actor reaches exactly what it needs and nothing more
  • Design audit trails and access controls that make autonomous agent activity fully reconstructable — what it did, on whose behalf, with what data, and why
  • Own IT security in partnership with the IT MSP — devices, endpoints, and access for a 12-person in-office team
  • Stand up and run compliance, auditability, bug bounty, VDP, and pentest programs that prove security posture to clients, partners, and auditors as a byproduct of how the system is built.

Regards,

Mohammed ilyas,

PH - 229-264-4024 or Text - 229-469-1455 or you can share the updated resume at Mohammed@vtekis. com

Additional Information

All your information will be kept confidential according to EEO guidelines.