I ncorporate static analysis tools such as Semgrep or CodeQL into the review workflow. * W ork independently from initial architecture through to deployment. Requirements: * 5 + years of full-stack ...
I ncorporate static analysis tools such as Semgrep or CodeQL into the review workflow. * W ork independently from initial architecture through to deployment. Requirements: * 5 + years of full-stack ...
... static analysis pipeline, pull request webhook integration, review dashboard, and Docker-based deployment. - Integrate LLM APIs such as OpenAI GPT-4 or Anthropic Claude into production systems ...
... static analysis pipeline, pull request webhook integration, review dashboard, and Docker-based deployment. - Integrate LLM APIs such as OpenAI GPT-4 or Anthropic Claude into production systems ...
D evelop a hybrid analysis pipeline combining LLM reasoning with static analysis for bug detection, security vulnerability identification, and code quality enforcement. * C reate a configurable rule ...
D evelop a hybrid analysis pipeline combining LLM reasoning with static analysis for bug detection, security vulnerability identification, and code quality enforcement. * C reate a configurable rule ...
... with static analysis for bug detection, security vulnerability identification, and code quality enforcement. - Create a configurable rule engine allowing per-repository custom review policies ...
... with static analysis for bug detection, security vulnerability identification, and code quality enforcement. - Create a configurable rule engine allowing per-repository custom review policies ...
... combining LLMs and static analysis tools. - Implement custom rule configuration for code reviews. - Develop a review dashboard for users. - Ensure Docker-based deployment of the solution.
... combining LLMs and static analysis tools. - Implement custom rule configuration for code reviews. - Develop a review dashboard for users. - Ensure Docker-based deployment of the solution.
B uild a hybrid review engine combining LLMs and static analysis tools. * I mplement custom rule configuration for code reviews. * D evelop a review dashboard for users. * E nsure Docker-based ...
B uild a hybrid review engine combining LLMs and static analysis tools. * I mplement custom rule configuration for code reviews. * D evelop a review dashboard for users. * E nsure Docker-based ...
... Static analysis, code review, and compliance checks. o Configure static analysis, unit test frameworks, and continuous integration pipelines. • Traceability analysis (requirements ↔ design ↔ ...
... Static analysis, code review, and compliance checks. o Configure static analysis, unit test frameworks, and continuous integration pipelines. • Traceability analysis (requirements ↔ design ↔ ...
Research Intern - Firmware Security
Redmond, WA · On-site
$6.8K - $13K/mo
You'll explore techniques that combine traditional static analysis outputs with LLM reasoning , including approaches that correlate findings across multiple tools, deduplicate results, and help ...
New
Research Intern - Firmware Security
Redmond, WA · On-site
$6.8K - $13K/mo
You'll explore techniques that combine traditional static analysis outputs with LLM reasoning , including approaches that correlate findings across multiple tools, deduplicate results, and help ...
New
Research Intern - Firmware Security
Redmond, WA · On-site
$6.8K - $13K/mo
You'll explore techniques that combine traditional static analysis outputs with LLM reasoning , including approaches that correlate findings across multiple tools, deduplicate results, and help ...
New
Research Intern - Firmware Security
Redmond, WA · On-site
$6.8K - $13K/mo
You'll explore techniques that combine traditional static analysis outputs with LLM reasoning , including approaches that correlate findings across multiple tools, deduplicate results, and help ...
New
... Static analysis, code review, and compliance checks. o Configure static analysis, unit test frameworks, and continuous integration pipelines. • Traceability analysis (requirements ↔ design ↔ ...
... Static analysis, code review, and compliance checks. o Configure static analysis, unit test frameworks, and continuous integration pipelines. • Traceability analysis (requirements ↔ design ↔ ...
$130 - $190/hr
As AI-assisted coding grows, the need for deep, static code analysis is more critical than ever. In this role, you'll join our Qodana Core team to expand our static analysis engine and design new ...
New
$130 - $190/hr
As AI-assisted coding grows, the need for deep, static code analysis is more critical than ever. In this role, you'll join our Qodana Core team to expand our static analysis engine and design new ...
New
DUTIES As a successful candidate for the Reverse Engineer III role, you will perform technical analysis of malicious binaries through controlled execution and/or static analysis of assembly code ...
DUTIES As a successful candidate for the Reverse Engineer III role, you will perform technical analysis of malicious binaries through controlled execution and/or static analysis of assembly code ...
... like Static Analysis and Test Coverage Experience in virtualization environment Strong communication skills (written and verbal) including ability to write clear and concise procedure documents ...
... like Static Analysis and Test Coverage Experience in virtualization environment Strong communication skills (written and verbal) including ability to write clear and concise procedure documents ...
C++ SOFTWARE DEVELOPER
$47 - $63.50/hr
POSITION DESCRIPTION The C++ Software Developer will push the boundaries of traditional static analysis tools with new and innovate and techniques for source code analysis and transformation. Your ...
C++ SOFTWARE DEVELOPER
$47 - $63.50/hr
POSITION DESCRIPTION The C++ Software Developer will push the boundaries of traditional static analysis tools with new and innovate and techniques for source code analysis and transformation. Your ...
C++ SOFTWARE DEVELOPER
Atlanta, GA · On-site
$47 - $63.50/hr
POSITION DESCRIPTION The C++ Software Developer will push the boundaries of traditional static analysis tools with new and innovate and techniques for source code analysis and transformation. Your ...
C++ SOFTWARE DEVELOPER
Atlanta, GA · On-site
$47 - $63.50/hr
POSITION DESCRIPTION The C++ Software Developer will push the boundaries of traditional static analysis tools with new and innovate and techniques for source code analysis and transformation. Your ...
Static Analysis Security Testing (SAST) (Required) * Dynamic Analysis Security Testing (DAST) (Required) * Network Analysis (Required) * Reverse Engineering (e.g. IDA Pro, Ghidra, Radare, Binary ...
Quick apply
Static Analysis Security Testing (SAST) (Required) * Dynamic Analysis Security Testing (DAST) (Required) * Network Analysis (Required) * Reverse Engineering (e.g. IDA Pro, Ghidra, Radare, Binary ...
Static Analysis Security Testing (SAST) (Required) * Dynamic Analysis Security Testing (DAST) (Required) * Network Analysis (Required) * Reverse Engineering (e.g. IDA Pro, Ghidra, Radare, Binary ...
Static Analysis Security Testing (SAST) (Required) * Dynamic Analysis Security Testing (DAST) (Required) * Network Analysis (Required) * Reverse Engineering (e.g. IDA Pro, Ghidra, Radare, Binary ...
MN · On-site
Conduct static and dynamic analysis of potentially malicious Android applications APKs and SDKs * Perform reverse engineering to uncover malicious behaviours and techniques used in Android threats
Quick apply
MN · On-site
Conduct static and dynamic analysis of potentially malicious Android applications APKs and SDKs * Perform reverse engineering to uncover malicious behaviours and techniques used in Android threats
Code & Static Analysis: Review application source code for security vulnerabilities, analyze static scanning findings, separate true positives from false positives, and evaluate security architecture.
Code & Static Analysis: Review application source code for security vulnerabilities, analyze static scanning findings, separate true positives from false positives, and evaluate security architecture.
Implement and wire static analysis tools and runtime sanitizers (ASan, TSan, UBSan) seamlessly into the development workflow, ensuring full traceability across the testing pipeline. * Reproducible ...
Quick apply
Implement and wire static analysis tools and runtime sanitizers (ASan, TSan, UBSan) seamlessly into the development workflow, ensuring full traceability across the testing pipeline. * Reproducible ...
Static Analysis information
See salary details
$45.5K - $53.7K
4% of jobs
$53.7K - $61.9K
17% of jobs
$68K is the 25th percentile. Wages below this are outliers.
$61.9K - $70K
5% of jobs
$70K - $78.2K
4% of jobs
$78.2K - $86.4K
13% of jobs
The median wage is $91.2K / yr.
$86.4K - $94.6K
12% of jobs
$94.6K - $102.8K
7% of jobs
$110.5K is the 75th percentile. Wages above this are outliers.
$102.8K - $111K
14% of jobs
$111K - $119.1K
3% of jobs
$119.1K - $127.3K
12% of jobs
$127.3K - $135.5K
9% of jobs
$45.5K
$93.2K
$135.5K
How much do static analysis jobs pay per year?
What are the key skills and qualifications needed to thrive in the static analysis position, and why are they important?
To thrive in a Static Analysis role, you need a strong background in software engineering, programming languages (such as C, C++, Java, or Python), and an understanding of code security and quality principles, often supported by a relevant degree in computer science or a related field. Familiarity with static analysis tools like SonarQube, Coverity, or Fortify, as well as experience with secure coding standards and possibly certifications like CSSLP, is highly beneficial. Analytical thinking, attention to detail, and effective communication skills help in identifying vulnerabilities and explaining findings to development teams. These capabilities are vital for ensuring code reliability and security, reducing software defects, and supporting organizational compliance goals.
What does a typical day look like for someone in a static analysis position?
A typical day in a Static Analysis role involves using specialized tools to review source code for potential vulnerabilities, bugs, and deviations from security or coding standards. You’ll analyze scan results, prioritize findings, and work closely with developers to remediate issues, often participating in code reviews and team meetings. The role also includes documenting analyses, updating reports, and occasionally contributing to the development or refinement of coding guidelines. Successful static analysts balance independent investigative work with collaborative problem-solving in a dynamic, detail-oriented environment.
What is a static analysis?
A Static Analysis job involves analyzing software code without executing it to identify potential security vulnerabilities, coding errors, and performance issues. Professionals in this field use automated tools to scan source code, bytecode, or binaries to detect flaws early in the development cycle. They work closely with developers and security teams to ensure code quality, compliance with industry standards, and secure coding practices. This role is crucial in preventing security breaches and improving software reliability before deployment.

Full-time
Re-posted 9 days ago
Job description
Job Title: Senior Full-Stack Engineer (Contract)
Company Overview:
NexaFlow is developing a next-generation automated code review tool powered by large language models (LLMs). We are seeking a Senior Full-Stack Engineer to build a proof-of-concept prototype from end to end.
Key Responsibilities:
Requirements:
Contract Details:
If you are passionate about building innovative developer tools and have a strong background in full-stack engineering and LLM integration, we encourage you to apply.
About Fuku
Sourced by ZipRecruiter
Industry
Food services and drinking places
Company size
51 - 200 Employees
Headquarters location
New York, NY, US
Year founded
2015