Description review

Senior Penetration Tester (Web and API), Contract

Invadel · United States · back to the listing

HR standards

76/100

solid

Title ↔ description

94/100

strong

Reads as

Security Engineer

89% confident

What this role officially is

ICT security administrator — ESCO, the EU occupation classification

ICT security administrators plan and carry out security measures to protect information and data from unauthorised access, deliberate attack, theft and corruption.

Also known as: network security administrator, system security administrator, ICT security administrators, IT security administrator

How others title the same work

Large employers

  • Security Risk Management Specialist Canonical Ltd.
  • Security Software Engineer Canonical Ltd.
  • Senior Security Operations Engineer Canonical Ltd.
  • Staff Security Operations Engineer Canonical Ltd.
  • Ubuntu Security Engineer Canonical Ltd.

Startups

  • Security Engineer (Bangalore, India) AiPrise
  • Security & Trust Engineer Alex
  • Elucid | Senior Security Engineer | Boston, MA | ONSITE (hybrid) | $130k–$170k Elucid
  • Factory | Security Engineer | ONSITE, San Francisco, CA | Full-Time Factory
  • Factory | Security Engineer | Onsite in San Francisco | Full-time Factory

The listing, marked up

Nothing in the wording of this listing tripped a check. The scores above still judge how complete and coherent it is.

Invadel is a New York City penetration testing firm. Every engagement is fixed-scope and fixed-price, agreed in writing, with public prices at invadel.com/pricing and a free retest. This is a contract role, remote within the United States, paid per engagement; a typical engagement is five to ten testing days plus a retest, scheduled around your availability.

What you will do: lead manual web application and API penetration tests across every user role (authorization, authentication and sessions, injection, business logic, SSRF, file handling and deserialization); confirm or discard every automated result by hand and chain findings to prove impact safely; escalate critical findings the day they are confirmed; write the report (executive summary, findings with reproduction steps and CVSS scores, prioritized remediation, framework mapping); retest remediated findings.

What we need: five or more years of hands-on application penetration testing, mostly web and API; depth on at least one modern stack (single-page applications, GraphQL, OAuth and OIDC, multi-tenant SaaS); based in the United States with authorization to work here; reports written for engineers and auditors, with a redacted sample report as part of the application; two professional references.

Nice to have: mobile (MASVS and MASTG) or cloud testing on AWS, Azure or GCP; published research, tooling or disclosed vulnerabilities. An offensive security certification is welcome; it does not replace a verifiable engagement record.

Full description, pay range and application:

Originally posted on Himalayas

How this was produced

Highlights are found by rule, not by a model: each one is a phrase matched at a known position, and every note is a template we wrote. The two scores come from a typed-decision model (Jev) that reads the listing against the official role definition and real listings for the same role, and returns probabilities rather than prose — it never writes any of the words on this page, and never chooses what to highlight.

Deterministic penalty applied to the HR score: 0 points (from 76 before penalties). Reviewed 21 Sep 2026.