Software Developer- Security Code Review
Overview
Security-focused software developer onsite in Orlando, focusing on manual and automated security code reviews to identify vulnerabilities and enforce secure coding standards. You’ll partner with development teams to raise security maturity and align with OWASP, CWE, and NIST frameworks. This role blends development experience with security expertise to strengthen applications across multiple languages. A impactful position in a rapidly growing cybersecurity company, offering a hands-on role in shaping secure software practices.
Compensation / Benefitsfull benefits401(k) with matchquarterly bonuscompetitive base salaryonsite (Orlando)career growth opportunities
ResponsibilitiesPerform detailed security-focused code reviews across multiple applications and programming languagesIdentify vulnerabilities such as injection flaws, XSS, insecure deserialization, authentication weaknesses, and insecure APIsPartner with developers to promote secure coding practices and remediation strategiesEnsure adherence to security standards including OWASP Top 10, CWE, and NIST frameworksCollaborate with security, architecture, and DevSecOps teams to improve application securityUtilize security analysis tools such as SonarQube, Fortify, Checkmarx, Veracode, or similar platforms
Key requirementsBachelor’s degree in Computer Science, Cybersecurity, or a related field (or equivalent experience)5+ years of software development experienceAt least 2 years of experience in application security, secure code review, or software securityStrong understanding of Secure Software Development Lifecycle (SSDLC)Experience reviewing and securing code in languages such as C/C++, C#, Swift, Java, JavaScript, or PythonFamiliarity with security tools including SonarQube, Fortify, Checkmarx, Veracode, or similar solutionsStrong knowledge of OWASP Top 10, CWE/SANS Top 25, and CVSS scoringSecurity certifications preferred: OSCP, CSSLP, CEH, GWAPT or similarFamiliarity with threat modeling, penetration testing, red/blue team activities preferredSonarQubeFortifyCheckmarxVeracodeOWASP Top 10CWE/SANS Top 25