远程工作雷达

应用安全工程师(源代码审查),合同制

Application Security Engineer (Source Code Review), Contract

开发工程限定地区(需当地身份)
公司Invadel
薪资$155,000 - $240,000/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Contractor
发布时间昨天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

Invadel 是一家位于纽约市的渗透测试公司。每次服务都是固定范围和固定价格,以书面形式达成一致,公开价格见 invadel.com/pricing,且提供免费重新测试。这是一个合同职位,远程办公,仅限美国境内,按项目支付报酬;通常需要四到八天时间对一组特定的代码库进行审查,之后再对修复内容进行重新测试。

你将负责:对静态分析结果进行分类,并在客户看到之前去除误报;手动审查身份验证、权限控制、输入处理、加密、密钥管理和第三方依赖使用;追踪跨服务的数据流,发现仅在组合情况下才会出现的缺陷;编写报告,包含文件和行号引用,安全的情况下提供可利用性证明,并在有帮助时提供修复代码;重新测试修复内容并更新报告。

我们需要:至少四年的工作经验分布在软件工程和应用安全领域,且定期参与生产代码审查;至少掌握 JavaScript 和 TypeScript、Python、Java 或 Kotlin、C#、Go、PHP、Ruby、Swift 中的三种语言,具备阅读能力;在美国境内工作并拥有在此工作的授权;能够为工程师和审计人员撰写报告,申请时需附上一份经过脱敏的报告样本;两名专业推荐人。

加分项:具备大规模 SAST 工具使用经验及审查 AI 生成代码的能力;有移动代码库或基础设施即代码经验;对开源安全工具做出过贡献。

完整描述、薪资范围和申请方式:
最初发布于 Himalayas

查看英文原文

Invadel is a New York City penetration testing firm. Every engagement is fixed-scope and fixed-price, agreed in writing, with public prices at invadel.com/pricing and a free retest. This is a contract role, remote within the United States, paid per engagement; a review is typically four to eight days on a defined set of repositories, followed by a retest of the fixes.
What you will do: triage static analysis output and remove false positives before a client sees them; manually review authentication, authorization, input handling, cryptography, secrets management and third-party dependency use; trace data flows across services to find flaws that only appear in combination; write findings with file and line references, proof of exploitability where safe, and remediation code where it helps; retest fixes and update the report.
What we need: four or more years split between software engineering and application security, with production code review as a regular part of the work; reading fluency in at least three of JavaScript and TypeScript, Python, Java or Kotlin, C#, Go, PHP, Ruby, Swift; based in the United States with authorization to work here; reports written for engineers and auditors, with a redacted sample report as part of the application; two professional references.
Nice to have: SAST tooling at scale and reviewing AI-generated code; mobile codebases or infrastructure as code; contributions to open-source security tooling.
Full description, pay range and application:
Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位