Back to all jobs

Application Security Engineer (Source Code Review), Contract

Invadel

RemoteUnited StatesTodayvia Himalayas

Applications for these vacancies are submitted on the employer’s own site. We prepare the documents, then hand you the link.

Job description

Invadel is a New York City penetration testing firm. Every engagement is fixed-scope and fixed-price, agreed in writing, with public prices at invadel.com/pricing and a free retest. This is a contract role, remote within the United States, paid per engagement; a review is typically four to eight days on a defined set of repositories, followed by a retest of the fixes. What you will do: triage static analysis output and remove false positives before a client sees them; manually review authentication, authorization, input handling, cryptography, secrets management and third-party dependency use; trace data flows across services to find flaws that only appear in combination; write findings with file and line references, proof of exploitability where safe, and remediation code where it helps; retest fixes and update the report. What we need: four or more years split between software engineering and application security, with production code review as a regular part of the work; reading fluency in at least three of JavaScript and TypeScript, Python, Java or Kotlin, C#, Go, PHP, Ruby, Swift; based in the United States with authorization to work here; reports written for engineers and auditors, with a redacted sample report as part of the application; two professional references. Nice to have: SAST tooling at scale and reviewing AI-generated code; mobile codebases or infrastructure as code; contributions to open-source security tooling. Full description, pay range and application: Originally posted on Himalayas
DeveloperApplication-Security-EngineerSenior-Application-Security-EngineerSoftware-Security-EngineerAppSec-EngineerSecurity-Engineer