Invadel is a New York City penetration testing firm. Every engagement is fixed-scope and fixed-price, agreed in writing, with public prices at invadel.com/pricing and a free retest. This is a contract role, remote within the United States, paid per engagement; a review is typically four to eight days on a defined set of repositories, followed by a retest of the fixes.
What you will do: triage static analysis output and remove false positives before a client sees them; manually review authentication, authorization, input handling, cryptography, secrets management and third-party dependency use; trace data flows across services to find flaws that only appear in combination; write findings with file and line references, proof of exploitability where safe, and remediation code where it helps; retest fixes and update the report.
What we need: four or more years split between software engineering and application security, with production code review as a regular part of the work; reading fluency in at least three of JavaScript and TypeScript, Python, Java or Kotlin, C#, Go, PHP, Ruby, Swift; based in the United States with authorization to work here; reports written for engineers and auditors, with a redacted sample report as part of the application; two professional references.
Nice to have: SAST tooling at scale and reviewing AI-generated code; mobile codebases or infrastructure as code; contributions to open-source security tooling.
Full description, pay range and application:
Invadel is a New York City-based penetration testing firm that provides fixed-scope, fixed-price security testing engagements with public pricing and complimentary retests. The company specializes in manual web application, API, and cloud infrastructure penetration testing, as well as source code security reviews across multiple programming languages. Invadel conducts comprehensive security assessments including authorization testing, vulnerability validation, privilege escalation attempts, and compliance mapping against standards like CIS Foundations, SOC 2, PCI DSS, and HIPAA. Each engagement delivers detailed reports with CVSS-scored findings, prioritized remediation recommendations, and verification of fixes through retesting.