Secure Delivery Pipeline & Application Reviewer
Job Description
Work at IXO
Apply your experience in application security and DevSecOps to paid work at IXO. You will develop realistic evaluation examples and review AI responses for technical correctness, clear reasoning and practical usefulness. The work calls for explanations that identify the actual defect or trade-off and show how a better answer would address it.
Responsibilities
• Evaluate secure coding and threat models against relevant OWASP risks.
• Review SAST, DAST and related integrations with Snyk, Semgrep, CodeQL or ZAP, alongside SBOMs, dependency checks, SLSA and Sigstore controls.
• Assess secrets management, signing and CI/CD gates, and explain input-validation, deserialisation, SSRF or IDOR flaws in authorised evaluation examples.
• Record the assumptions, supporting evidence and corrections needed for another specialist to follow your review.
Experience and expertise
• 5• years in application security, DevSecOps, or security engineering.
• Practical depth in OWASP Top 10 and modern web/API attack classes.
• A thorough understanding of SAST, DAST, IAST, and software composition analysis tools.
• Experience designing secure CI/CD pipelines and supply-chain controls.
• Ability to work confidently with at least one offensive-security background (CTFs, bug bounty, internal red team).
• Familiarity with cloud-native security (CSPM, CWPP) and zero-trust patterns is an advantage.
Working arrangements and pay
Remote work in these eligible locations: USA, UK, Canada, Germany, Netherlands. Planning availability: Flexible, 10-25 hours/week. IXO will confirm the actual start and schedule before acceptance. Compensation is $100 • $160/hr USD. The agreed rate, delivery requirements and review criteria are confirmed before work begins.