Application Security Engineer (Source Code Review), Contract
- Status
- Open
- Remote policy
- Remote
- Employment type
- Not stated
- Salary
- Not stated
- Categories
- Application-Security-Engineer, Senior-Application-Security-Engineer, Software-Security-Engineer, AppSec-Engineer, Security-Engineer
- Source
- himalayas
- First observed
- 2026-09-15 06:00 UTC
- Last seen
- 2026-09-15 06:00 UTC
- Source claims posted
- 2026-09-15 04:26 UTC
- Consecutive misses
- 0 of 10
What the posting says
Invadel is a New York City penetration testing firm. Every engagement is fixed-scope and fixed-price, agreed in writing, with public prices at invadel.com/pricing and a free retest. This is a contract role, remote within the United States, paid per engagement; a review is typically four to eight days on a defined set of repositories, followed by a retest of the fixes.
What you will do: triage static analysis output and remove false positives before a client sees them; manually review authentication, authorization, input handling, cryptography, secrets management and third-party dependency use; trace data flows across services to find flaws that only appear in combination; write findings with file and line references, proof of exploitability where safe, and remediation code where it helps; retest fixes and update the report.
What we need: four or more years split between software engineering and application security, with production code review as a regular part of the work; reading fluency in at least three of JavaScript and TypeScript, Python, Java or Kotlin, C#, Go, PHP, Ruby, Swift; based in the United States with authorization to work here; reports written for engineers and auditors, with a redacted sample report as part of the application; two professional references.
Nice to have: SAST tooling at scale and reviewing AI-generated code; mobile codebases or infrastructure as code; contributions to open-source security tooling.
Full description, pay range and application:
Originally posted on Himalayas
Quality
- x Salary range stated weight 35%
- + Remote policy stated weight 20%
- + Location stated weight 15%
- + Organisation stated weight 15%
- + Publication date stated weight 15%
Not enough history yet to judge honesty signals.
Timeline
-
*
#761429 2026-09-15 06:00 UTCPublished