Remote | Application Security Engineer (AppSec) — $30–$100/hour at 24-MAG in New York, New York, United States
- Company: 24-MAG
- Location: New York, New York, United States
- Posted: Sep 23, 2026
- Type: Contract
- Salary: $30–$100/hour
- Experience: 6+ years
Overview
About the job Remote | Application Security Engineer (AppSec) — $30–$100/hour We are sharing a specialised consulting opportunity for experienced Application Security Engineers with strong expertise in secure software development, backend engineering, penetration testing, vulnerability assessment, s…
Job description
- About the job Remote | Application Security Engineer (AppSec) — $30–$100/hour
- We are sharing a specialised consulting opportunity for experienced Application Security Engineers with strong expertise in secure software development, backend engineering, penetration testing, vulnerability assessment, security auditing, and code review to contribute to an advanced AI training and software-engineering evaluation project.
- Selected professionals will create realistic coding tasks involving feature implementation, bug fixing, and security-sensitive application scenarios, while developing deterministic verifiers that accept valid solutions and reject incorrect or unsafe implementations. No prior experience in AI is required.
Responsibilities
- Application Security & Secure Engineering
- Evaluate software for application-security weaknesses and unsafe implementation patterns
- Apply secure-coding practices across realistic backend engineering scenarios
- Identify vulnerabilities affecting confidentiality, integrity, or system reliability
- Assess security implications of architectural and implementation decisions
- Apply professional AppSec judgement across production-style codebases
- Penetration Testing & Security Review
- Apply experience with penetration testing, vulnerability assessment, and security audits
- Identify weaknesses aligned with common OWASP and CWE categories
- Review code for exploitable behaviour, insecure assumptions, and configuration risks
- Evaluate proposed fixes for effectiveness and unintended security consequences
- Document security findings and technical reasoning clearly
- Coding Task & Backend Development
- Design challenging coding tasks involving feature implementation and bug fixes
- Work across Java, Node.js, Go, Rust, TypeScript, Python, C++, or similar languages
- Develop and evaluate scalable backend services and APIs
- Define clear technical requirements, constraints, and expected behaviours
- Apply algorithms, data structures, and sound software-engineering principles
- Debugging, Refactoring & Performance
- Diagnose complex software defects and identify underlying root causes
- Resolve bugs and performance bottlenecks across varied codebases
- Refactor existing code to improve clarity, maintainability, and reliability
- Implement complex features within mature or large-scale applications
- Validate changes through automated testing and structured technical review
- Deterministic Verification & Code Quality
- Build deterministic verifiers for coding tasks and submitted solutions
- Ensure verification accepts reasonable valid solutions while rejecting incorrect outputs
- Develop tests covering expected behaviour, edge cases, and failure conditions
- Review code for correctness, maintainability, performance, and security
- Provide clear technical documentation supporting reproducible evaluation
Requirements
- Strong professional experience in application security, backend engineering, or cybersecurity
- Expertise in Java, Node.js, Go, Rust, TypeScript, Python, C++, or a comparable language
- Proven experience building scalable services and APIs
- Strong background in secure coding and application-security review
- Experience with penetration testing, vulnerability assessment, or security auditing
- Familiarity with OWASP, CWE, and common software-security weaknesses
- Strong debugging, automated-testing, and performance-optimisation skills
- Experience implementing complex features in production codebases
- Strong code-review instincts and attention to software quality
- Experience refactoring mature or large-scale systems
- Solid understanding of algorithms, data structures, and core computer-science concepts
- Excellent analytical, problem-solving, and technical communication skills
- Ability to work independently and apply professional judgement without outside assistance
- No prior AI-training or model-evaluation experience is required
Skills
Required
- Java
- Node.js
- Go
- Rust
- TypeScript
- Python
- C++
- Secure coding
- Application-security review
- Penetration testing
- Vulnerability assessment
- Security auditing
About 24-MAG
This opportunity is available through 24-MAG LLC. We connect experienced professionals with remote consulting opportunities across technical, evaluation, and project-based workstreams. By submitting this application, you acknowledge that your information may be processed by 24-MAG LLC for recruitment and opportunity matching in accordance with our Privacy Policy: https://www.24-mag.com/privacy-policy