Application Security Engineer (Source Code Review), Contract

Invadelhimalayaspublished 09/15/2026
This job is no longer listed
The source has removed this listing — applying via the original link is no longer possible.
Must-have:TypeScriptJavaScriptPythonJavaKotlinC#RubySwiftPHPMobileAISecurityRemote

Invadel is a New York City penetration testing firm. Every engagement is fixed-scope and fixed-price, agreed in writing, with public prices at invadel.com/pricing and a free retest. This is a contract role, remote within the United States, paid per engagement; a review is typically four to eight days on a defined set of repositories, followed by a retest of the fixes.

What you will do:

  • triage static analysis output and remove false positives before a client sees them;
  • manually review authentication, authorization, input handling, cryptography, secrets management and third-party dependency use;
  • trace data flows across services to find flaws that only appear in combination;
  • write findings with file and line references, proof of exploitability where safe, and remediation code where it helps;
  • retest fixes and update the report.

What we need:

  • four or more years split between software engineering and application security, with production code review as a regular part of the work;
  • reading fluency in at least three of JavaScript and TypeScript, Python, Java or Kotlin, C#, Go, PHP, Ruby, Swift;
  • based in the United States with authorization to work here;
  • reports written for engineers and auditors, with a redacted sample report as part of the application;
  • two professional references.

Nice to have:

  • SAST tooling at scale and reviewing AI-generated code;
  • mobile codebases or infrastructure as code;
  • contributions to open-source security tooling.

Full description, pay range and application:

Originally posted on Himalayas