Enterprise-Level SAST Platform Development

via Freelancer ·

Budget / Salary₹37,500–75,000
TypeFreelance project
LocationRemote
Posted1 hour ago
Freelance SAST / Static Analysis Security Developer

We are looking for an experienced SAST / Static Analysis Security Developer to help us build an advanced, enterprise-grade Static Application Security Testing platform.

The candidate should have hands-on experience building source-code scanners, vulnerability detection engines, static-analysis tools, compiler-based analysis systems, or AppSec products.

Our goal is to develop a modern SAST platform with capabilities comparable to tools such as Semgrep, CodeQL, SonarQube, Snyk Code, Checkmarx and Veracode, using original code and legally compatible open-source technologies.

Key Responsibilities
Design and develop the complete SAST architecture and scanning engine.
Implement AST, CFG, data-flow, taint-flow, source-to-sink and interprocedural analysis.
Build customizable security rules and vulnerability detection logic.
Support multiple programming languages including Java, Python, JavaScript, TypeScript, C/C++, C#, Go, PHP and others.
Detect vulnerabilities such as SQL Injection, XSS, command injection, SSRF, XXE, insecure cryptography, hardcoded credentials, secrets, authentication flaws and insecure coding practices.
Implement dependency/SCA integration, vulnerability deduplication and false-positive reduction.
Build incremental, differential, repository and CI/CD scanning.
Integrate GitHub, GitLab, Bitbucket, Jenkins and Azure DevOps.
Develop vulnerability dashboards, reporting, policy management, RBAC and an enterprise web GUI.
Add CWE, OWASP, CVSS and compliance mappings.
Implement AI-assisted vulnerability explanation, remediation recommendations, code-fix suggestions and false-positive analysis.
Optimize the scanner for large repositories, parallel processing and enterprise environments.
Support Docker, Kubernetes, SaaS and on-premise deployment.
Follow secure coding, API security, authentication, authorization and secrets-management practices.
Preferred Experience

Experience with technologies such as:

Semgrep, CodeQL, Fortify,Tree-sitter, Joern, ANTLR, SonarQube, Code Property Graphs, compiler design, AST parsing, taint analysis and program analysis.

Preferred languages include Python, Go, Java, Rust or C++, with React/Next.js/TypeScript experience for the GUI.

Expected Deliverables

The freelancer should be capable of delivering the complete:

SAST Engine + Rule Engine + Multi-Language Analysis + APIs + Enterprise GUI + CI/CD Integrations + Reporting + Deployment + Documentation + Production-Ready Source Co
php java javascript python software development docker kubernetes ci/cd
Apply on Freelancer →

Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.