← Back to Global Marketplace
Apply on GitHub Hiring
↗
Apply on Provider Website ↗
HIRING: Security Specialist (10h/week, Week 3)
Crashcart • Remote / Open Source • Posted 3 months ago
Salary
Not disclosed
Employment
Not specified
Remote Status
100% Remote
Trust Rating
97%
✨
AI Copilot Scoping Summary
## Rule 9: Security **REQUIREMENT**: - All user input sanitized before use (SQL, command, template injection) - Secrets in environment variables only, never in code or git history - CORS, CSRF, au...
Detected Core Stack:
hiring
security
rule-9
owasp
SQL
AI
Role Description & Requirements
## Rule 9: Security
**REQUIREMENT**:
- All user input sanitized before use (SQL, command, template injection)
- Secrets in environment variables only, never in code or git history
- CORS, CSRF, authentication, authorization verified per request
- Dependencies scanned for known vulnerabilities
- Code reviewed against OWASP Top 10
## Role Summary
Security Specialist enforces Rule 9 (OWASP compliance) and prevents security incidents.
## Responsibilities
- Security code review for every PR (injection, XSS, CSRF, auth bypass)
- Dependency scanning and vulnerability alerts
- Threat modeling for new features
- OWASP Top 10 compliance verification
- Credential management and secrets scanning
## Why Important
One security incident costs 430+ tokens (response, audit, remediation, re-test). Prevention prevents catastrophic rework. Token savings: 200-500/month.
## Timeline
Start week 3, after PM + QA baseline established.
## Reference
See `.github/HIRING_PLAN.md` for full strategic hiring plan.
See `.github/rules/universal.md` Rule 9 and `.github/rules/claude.md` Security Standards for full requirements.
**Labels**: hiring, security, rule-9, owasp
**REQUIREMENT**:
- All user input sanitized before use (SQL, command, template injection)
- Secrets in environment variables only, never in code or git history
- CORS, CSRF, authentication, authorization verified per request
- Dependencies scanned for known vulnerabilities
- Code reviewed against OWASP Top 10
## Role Summary
Security Specialist enforces Rule 9 (OWASP compliance) and prevents security incidents.
## Responsibilities
- Security code review for every PR (injection, XSS, CSRF, auth bypass)
- Dependency scanning and vulnerability alerts
- Threat modeling for new features
- OWASP Top 10 compliance verification
- Credential management and secrets scanning
## Why Important
One security incident costs 430+ tokens (response, audit, remediation, re-test). Prevention prevents catastrophic rework. Token savings: 200-500/month.
## Timeline
Start week 3, after PM + QA baseline established.
## Reference
See `.github/HIRING_PLAN.md` for full strategic hiring plan.
See `.github/rules/universal.md` Rule 9 and `.github/rules/claude.md` Security Standards for full requirements.
**Labels**: hiring, security, rule-9, owasp
Opportunity Actions
Aggregated Provider:
GitHub Hiring
Visa Sponsorship:
Not Specified
AI Recommended Top Freelancers
G
Google Verified User
Freelancer
G
Github Verified User
Freelancer
J