Invadel

Senior Penetration Tester (Web and API), Contract

United StatesREMOTEFREELANCE
Publi茅e le 15 septembre 2026Candidature trait茅e sur le site de l鈥檈ntreprise
DeveloperSenior-Penetration-TesterSenior-Security-Testing-EngineerPenetration-Testing-JobsSecurity-Testing-EngineerPenetration-Tester

Invadel is a New York City penetration testing firm. Every engagement is fixed-scope and fixed-price, agreed in writing, with public prices at invadel.com/pricing and a free retest. This is a contract role, remote within the United States, paid per engagement; a typical engagement is five to ten testing days plus a retest, scheduled around your availability. What you will do: lead manual web application and API penetration tests across every user role (authorization, authentication and sessions, injection, business logic, SSRF, file handling and deserialization); confirm or discard every automated result by hand and chain findings to prove impact safely; escalate critical findings the day they are confirmed; write the report (executive summary, findings with reproduction steps and CVSS scores, prioritized remediation, framework mapping); retest remediated findings. What we need: five or more years of hands-on application penetration testing, mostly web and API; depth on at least one modern stack (single-page applications, GraphQL, OAuth and OIDC, multi-tenant SaaS); based in the United States with authorization to work here; reports written for engineers and auditors, with a redacted sample report as part of the application; two professional references. Nice to have: mobile (MASVS and MASTG) or cloud testing on AWS, Azure or GCP; published research, tooling or disclosed vulnerabilities. An offensive security certification is welcome; it does not replace a verifiable engagement record. Full description, pay range and application: Originally posted on Himalayas