Skip to content

Open role

Application Security Engineer (Source Code Review), Contract

Run secure code reviews that pair static analysis with expert manual review, on the web, mobile and backend stacks Invadel’s clients ship. Find the authorization gaps, injection paths and logic flaws scanners miss, and explain the fix in the developer’s own terms.

Engagement
Contract, paid per engagement
Location
Remote, United States
Pay range
$155,000 to $240,000 per year
Posted
September 14, 2026

The engagement

Contract, remote within the United States, paid per engagement. A review is typically four to eight days on a defined set of repositories, followed by a retest of the fixes.

What you will do

  • Triage static analysis output and remove false positives before a client sees them.
  • Manually review authentication, authorization, input handling, cryptography, secrets management and third-party dependency use.
  • Trace data flows across services to find flaws that only appear in combination.
  • Write findings with file and line references, proof of exploitability where safe, and remediation code where it helps.
  • Retest fixes and update the report.

What we need

  • Four or more years split between software engineering and application security, with production code review as a regular part of the work.
  • Reading fluency in at least three of: JavaScript and TypeScript, Python, Java or Kotlin, C#, Go, PHP, Ruby, Swift.
  • Based in the United States with authorization to work here; engagements run on US time and clients are US companies.
  • Reports written for two readers at once: an engineer who has to fix the finding and an auditor who has to accept the evidence. A redacted sample report is part of the application.
  • Comfortable working to a fixed, written scope and saying early when something in it is wrong.
  • Two professional references from people who have seen your work on a live engagement.

Nice to have

  • Experience with SAST tooling at scale and with reviewing AI-generated code.
  • Mobile codebases (iOS and Android) or infrastructure as code.
  • Contributions to open-source security tooling.