Enterprise-Level SAST Platform Development
Budget / Salary₹37,500–75,000
TypeFreelance project
LocationRemote
Posted2 hours ago
Freelance SAST / Static Analysis Security Developer
We are looking for an experienced SAST / Static Analysis Security Developer to help us build an advanced, enterprise-grade Static Application Security Testing platform.
The candidate should have hands-on experience building source-code scanners, vulnerability detection engines, static-analysis tools, compiler-based analysis systems, or AppSec products.
Our goal is to develop a modern SAST platform with capabilities comparable to tools such as Semgrep, CodeQL, SonarQube, Snyk Code, Checkmarx and Veracode, using original code and legally compatible open-source technologies.
Key Responsibilities
Design and develop the complete SAST architecture and scanning engine.
Implement AST, CFG, data-flow, taint-flow, source-to-sink and interprocedural analysis.
Build customizable security rules and vulnerability detection logic.
Support multiple programming languages including Java, Python, JavaScript, TypeScript, C/C++, C#, Go, PHP and others.
Detect vulnerabilities such as SQL Injection, XSS, command injection, SSRF, XXE, insecure cryptography, hardcoded credentials, secrets, authentication flaws and insecure coding practices.
Implement dependency/SCA integration, vulnerability deduplication and false-positive reduction.
Build incremental, differential, repository and CI/CD scanning.
Integrate GitHub, GitLab, Bitbucket, Jenkins and Azure DevOps.
Develop vulnerability dashboards, reporting, policy management, RBAC and an enterprise web GUI.
Add CWE, OWASP, CVSS and compliance mappings.
Implement AI-assisted vulnerability explanation, remediation recommendations, code-fix suggestions and false-positive analysis.
Optimize the scanner for large repositories, parallel processing and enterprise environments.
Support Docker, Kubernetes, SaaS and on-premise deployment.
Follow secure coding, API security, authentication, authorization and secrets-management practices.
Preferred Experience
Experience with technologies such as:
Semgrep, CodeQL, Fortify,Tree-sitter, Joern, ANTLR, SonarQube, Code Property Graphs, compiler design, AST parsing, taint analysis and program analysis.
Preferred languages include Python, Go, Java, Rust or C++, with React/Next.js/TypeScript experience for the GUI.
Expected Deliverables
The freelancer should be capable of delivering the complete:
SAST Engine + Rule Engine + Multi-Language Analysis + APIs + Enterprise GUI + CI/CD Integrations + Reporting + Deployment + Documentation + Production-Ready Source Co
We are looking for an experienced SAST / Static Analysis Security Developer to help us build an advanced, enterprise-grade Static Application Security Testing platform.
The candidate should have hands-on experience building source-code scanners, vulnerability detection engines, static-analysis tools, compiler-based analysis systems, or AppSec products.
Our goal is to develop a modern SAST platform with capabilities comparable to tools such as Semgrep, CodeQL, SonarQube, Snyk Code, Checkmarx and Veracode, using original code and legally compatible open-source technologies.
Key Responsibilities
Design and develop the complete SAST architecture and scanning engine.
Implement AST, CFG, data-flow, taint-flow, source-to-sink and interprocedural analysis.
Build customizable security rules and vulnerability detection logic.
Support multiple programming languages including Java, Python, JavaScript, TypeScript, C/C++, C#, Go, PHP and others.
Detect vulnerabilities such as SQL Injection, XSS, command injection, SSRF, XXE, insecure cryptography, hardcoded credentials, secrets, authentication flaws and insecure coding practices.
Implement dependency/SCA integration, vulnerability deduplication and false-positive reduction.
Build incremental, differential, repository and CI/CD scanning.
Integrate GitHub, GitLab, Bitbucket, Jenkins and Azure DevOps.
Develop vulnerability dashboards, reporting, policy management, RBAC and an enterprise web GUI.
Add CWE, OWASP, CVSS and compliance mappings.
Implement AI-assisted vulnerability explanation, remediation recommendations, code-fix suggestions and false-positive analysis.
Optimize the scanner for large repositories, parallel processing and enterprise environments.
Support Docker, Kubernetes, SaaS and on-premise deployment.
Follow secure coding, API security, authentication, authorization and secrets-management practices.
Preferred Experience
Experience with technologies such as:
Semgrep, CodeQL, Fortify,Tree-sitter, Joern, ANTLR, SonarQube, Code Property Graphs, compiler design, AST parsing, taint analysis and program analysis.
Preferred languages include Python, Go, Java, Rust or C++, with React/Next.js/TypeScript experience for the GUI.
Expected Deliverables
The freelancer should be capable of delivering the complete:
SAST Engine + Rule Engine + Multi-Language Analysis + APIs + Enterprise GUI + CI/CD Integrations + Reporting + Deployment + Documentation + Production-Ready Source Co
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.