1

Secure Code Review Jobs (NOW HIRING)

$180K - $220K/yr

Conduct threat modeling, security architecture reviews, and secure code reviews for new services, infrastructure changes, and product features. * Design, deploy, and maintain security tooling across ...

Conduct secure code reviews, threat modeling, and security assessments for new features, architectural changes and legacy components. * Implement and maintain secure storage mechanisms, encryption ...

Provide deep expertise in secure coding practices, threat modeling, design reviews, and static/dynamic analysis to Engineering teams delivering core user-facing functionality. * Serve as a security ...

... secure code review, and AI safety controls. • Partner with product, architecture, security, operations, data, and platform teams to translate broad goals into technical roadmaps, tradeoff decisions ...

Being a security subject-matter expert, guide engineering teams in end-to-end secure system design and implementation. * Conducting threat modeling, architecture review, security code review ...

Sr. Application Security Engineer

Montvale, NJ · On-site

$61.50 - $82/hr

... • Secure code review experience using automated toolsets • Software Engineering career experience • Following Certifications: CISSP, CEH, GWAPT, GPEN, OSCP • Thorough understanding of ...

Staff Application Security Engineer

$60.25 - $80.25/hr

Run our secure code review program, including the design of review playbooks, the hardest reviews yourself, and coaching engineers to catch issues earlier. * Operate and tune our AppSec tooling stack ...

Secure code review experience (any major language). * Familiarity with CI/CD and modern SDLC security. * Offensive security certifications (OSCP, GWAPT, etc.

... and secure code review or remediation practices Required Qualifications React: Building modern, component-based UIs (as indicated by the need for Node/NPM in the README) - 4 Years JavaScript ...

next page

Showing results 1-20

Secure Code Review information

See salary details

$29

$66

$96

How much do secure code review jobs pay per hour?

As of May 31, 2026, the average hourly pay for secure code review in the United States is $66.40, according to ZipRecruiter salary data. Most workers in this role earn between $56.49 and $75.48 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Secure Code Reviewer, and why are they important?

To thrive as a Secure Code Reviewer, you need a solid understanding of secure coding practices, programming languages (such as Java, Python, or C++), and common software vulnerabilities, often supported by relevant security certifications like CISSP or CSSLP. Familiarity with automated code analysis tools, static application security testing (SAST) platforms, and bug tracking systems is typically required. Strong analytical thinking, attention to detail, and clear communication skills set outstanding reviewers apart. These abilities are crucial for identifying, explaining, and mitigating security risks in code, ensuring robust application security.

What are some common challenges faced by professionals performing secure code reviews, and how can they be addressed?

Secure code reviewers often encounter challenges such as keeping up with evolving security threats, identifying subtle vulnerabilities in complex codebases, and maintaining effective communication with development teams. To address these, reviewers should stay updated on the latest security trends, use automated tools to assist in identifying potential issues, and foster collaborative relationships with developers to ensure that findings are understood and remediated effectively. Regular training, participating in security communities, and integrating secure code review into the software development lifecycle can also help overcome these challenges.

What is secure code review?

Secure code review is the process of systematically examining application source code to identify and remediate security vulnerabilities before software is released. This review can be performed manually or with automated tools, focusing on areas where coding errors could lead to security risks such as injection attacks, data leaks, or authentication flaws. The goal is to ensure that the code adheres to secure coding standards and best practices, ultimately reducing the risk of exploitation by malicious actors.

What is the difference between Secure Code Review vs Static Application Security Testing (SAST)?

AspectSecure Code ReviewStatic Application Security Testing (SAST)
CredentialsKnowledge of secure coding, programming languages, security standardsSecurity testing tools, programming knowledge, security certifications
Work EnvironmentManual review, developer collaboration, code analysisAutomated scanning, integration with CI/CD pipelines
Industry UsageDevelopment teams, security analysts, code auditsSecurity teams, QA, DevOps, automated security testing

Secure Code Review involves manual or semi-automated analysis of source code to identify security flaws, emphasizing developer collaboration. SAST uses automated tools to scan code for vulnerabilities during development, enabling faster detection. Both roles aim to improve code security but differ in approach: one is manual and detailed, the other automated and scalable.

More about Secure Code Review jobs
What states have the most Secure Code Review jobs? States with the most job openings for Secure Code Review jobs include:
Infographic showing various Secure Code Review job openings in the United States as of May 2026, with employment types broken down into 87% Full Time, and 13% Contract. Highlights an 74% In-person, 13% Hybrid, and 13% Remote job distribution, with an average salary of $138,117 per year, or $66.4 per hour.

Sr. Application Security Engineer

Bridge Tech

Cherry Hills Village, CO

$58.50 - $78/hr

Full-time

Posted 12 days ago


Job description

Job Description
We need a resource who has experience working within a Vulnerability Management Program that understands Application Security with 5-7 years of security experience.
Experience with any of the following commercial application scanning tools such as Acunetix, IBM's AppScan, Client's WebInspect, NTOSpider, Cenzic's Hailstorm, Burp Suite Professional
Understanding of Web Services technologies such as XML, SOAP, and AJAX
Understanding of various web application frameworks such as ASP.NET, J2EE, Zend
Web Server configuration knowledge: Microsoft IIS, Apache HTTP Server, Apache Tomcat
Experience in application level attacks, bypassing firewalls, evading intrusion detection
Experience building automated tool sets or expanding existing toolset libraries
Secure code review experience using automated toolsets
Software Engineering career experience
Following Certifications: CISSP, CEH, GWAPT, GPEN, OSCP
Thorough understanding of software vulnerabilities
Knowledge of OWASP Top 10, SANS Top 25, CWE, WASC
Ability to demonstrate understanding of vulnerability remediation
Familiarity with malicious code identification and common hacker attack techniques
Ability to research and reproduce vulnerability exploitation
Understanding of advanced cryptographic concepts.
Ability to demonstrate manual testing experience including all of OWASP Top 10.
Qualifications
Skills Required
Excellent problem solving and analytical skills
Superior oral and technical writing communication skills
Independence, self-managed, and motivated
Knowledge of the Software Development Lifecycle in an enterprise environment
Programming experience in two of the following languages: C#, Java, Python, Ruby
Additional Information

All your information will be kept confidential according to EEO guidelines.