应用安全工程师(源代码审查),合同制
Application Security Engineer (Source Code Review), Contract
Invadel 是一家位于纽约市的渗透测试公司。每次服务都是固定范围和固定价格,以书面形式达成一致,公开价格见 invadel.com/pricing,且提供免费重新测试。这是一个合同职位,远程办公,仅限美国境内,按项目支付报酬;通常需要四到八天时间对一组特定的代码库进行审查,之后再对修复内容进行重新测试。
你将负责:对静态分析结果进行分类,并在客户看到之前去除误报;手动审查身份验证、权限控制、输入处理、加密、密钥管理和第三方依赖使用;追踪跨服务的数据流,发现仅在组合情况下才会出现的缺陷;编写报告,包含文件和行号引用,安全的情况下提供可利用性证明,并在有帮助时提供修复代码;重新测试修复内容并更新报告。
我们需要:至少四年的工作经验分布在软件工程和应用安全领域,且定期参与生产代码审查;至少掌握 JavaScript 和 TypeScript、Python、Java 或 Kotlin、C#、Go、PHP、Ruby、Swift 中的三种语言,具备阅读能力;在美国境内工作并拥有在此工作的授权;能够为工程师和审计人员撰写报告,申请时需附上一份经过脱敏的报告样本;两名专业推荐人。
加分项:具备大规模 SAST 工具使用经验及审查 AI 生成代码的能力;有移动代码库或基础设施即代码经验;对开源安全工具做出过贡献。
完整描述、薪资范围和申请方式:
最初发布于 Himalayas
查看英文原文
Invadel is a New York City penetration testing firm. Every engagement is fixed-scope and fixed-price, agreed in writing, with public prices at invadel.com/pricing and a free retest. This is a contract role, remote within the United States, paid per engagement; a review is typically four to eight days on a defined set of repositories, followed by a retest of the fixes.
What you will do: triage static analysis output and remove false positives before a client sees them; manually review authentication, authorization, input handling, cryptography, secrets management and third-party dependency use; trace data flows across services to find flaws that only appear in combination; write findings with file and line references, proof of exploitability where safe, and remediation code where it helps; retest fixes and update the report.
What we need: four or more years split between software engineering and application security, with production code review as a regular part of the work; reading fluency in at least three of JavaScript and TypeScript, Python, Java or Kotlin, C#, Go, PHP, Ruby, Swift; based in the United States with authorization to work here; reports written for engineers and auditors, with a redacted sample report as part of the application; two professional references.
Nice to have: SAST tooling at scale and reviewing AI-generated code; mobile codebases or infrastructure as code; contributions to open-source security tooling.
Full description, pay range and application:
Originally posted on Himalayas