Job description
Invadel is a New York City penetration testing firm. Every engagement is fixed-scope and fixed-price, agreed in writing, with public prices at invadel.com/pricing and a free retest. This is a contract role, remote within the United States, paid per engagement; a review is typically four to eight days on a defined set of repositories, followed by a retest of the fixes.
What you will do: triage static analysis output and remove false positives before a client sees them; manually review authentication, authorization, input handling, cryptography, secrets management and third-party dependency use; trace data flows across services to find flaws that only appear in combination; write findings with file and line references, proof of exploitability where safe, and remediation code where it helps; retest fixes and update the report.
What we need: four or more years split between software engineering and application security, with production code review as a regular part of the work; reading fluency in at least three of JavaScript and TypeScript, Python, Java or Kotlin, C#, Go, PHP, Ruby, Swift; based in the United States with authorization to work here; reports written for engineers and auditors, with a redacted sample report as part of the application; two professional references.
Nice to have: SAST tooling at scale and reviewing AI-generated code; mobile codebases or infrastructure as code; contributions to open-source security tooling.
Full description, pay range and application:
Originally posted on Himalayas
Who can apply
Eligible countries: United States. Accepted UTC offsets: UTC-11, UTC-10, UTC-9.5, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC-4, UTC-3.5, UTC-3, UTC-2, UTC-1, UTC+0, UTC+1, UTC+2, UTC+3, UTC+3.5, UTC+4, UTC+4.5, UTC+5, UTC+5.5, UTC+5.75, UTC+6, UTC+6.5, UTC+7, UTC+8, UTC+8.75, UTC+9, UTC+9.5, UTC+10, UTC+10.5, UTC+11, UTC+12, UTC+12.75, UTC+13, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.