Penetration Test for AWS Web Application
Presupuesto: $20.0 - $50.0
HOURLY / PART_TIME
⭐ 2.66 (4)
Canada
amazon-web-services, amazon-s3, amazon-ec2, software-qa-testing
Cualificaciones preferidas
- Tipo de talento: Agencia
- Ubicación: Canada
- Experiencia: Intermedio
- Inglés: Nativo
- Ganancias mín.: $100+
We need a Canadian-based company to perform a penetration test on a web application hosted in AWS. This is a small project for a short-term engagement, and we are not interested in individual freelancers. The work should include identifying vulnerabilities, testing security controls, and providing a clear report with findings and recommendations. Please apply only if your company is based in Canada and has experience with AWS environments.
About the role
Phenowise is a patient-centered health-data platform: patients and their caregivers record medical history, conditions, medications, symptoms, and daily trackers, with subscription billing and health-data provenance features. Because the product stores and shares Protected Health Information (PHI) across a multi-tenant, caregiver-delegated model, security is a first-class requirement.
We're engaging a penetration tester to perform an authorized, black/grey-box assessment of our web application, public APIs, and cloud environment, and to deliver actionable, risk-ranked remediation guidance. This is hands-on offensive testing against a modern serverless AWS stack, followed by a remediation retest.
What you'll be testing (technology context)
Frontend: React single-page app (multiple environments: production, staging, QA).
APIs: REST APIs on Amazon API Gateway backed by AWS Lambda (Node.js and Python), a mix of a legacy monolithic service and newer per-domain "router" microservices.
AuthN/AuthZ: Amazon Cognito (separate end-user and administrative/console user pools); authorization enforced in application code (not at the gateway).
Data: Aurora MySQL and PostgreSQL, DynamoDB, and a reference catalog DB; data reached via the RDS Data API and direct drivers.
Payments: Stripe subscription billing (checkout, portal, webhooks).
AI services: Python/LLM services (OpenAI/Bedrock-class models, vector search) that operate over patient-derived data.
Domain features: consent ledger, record lifecycle / caregiver transfer, and a health-data "minting"/provenance flow.
Key responsibilities
Plan and execute a full-scope penetration test against agreed targets, following a recognized methodology (OWASP WSTG / API Security Top 10 / PTES), within documented rules of engagement.
Test the web application for the OWASP Top 10 and beyond (injection, XSS, CSRF, SSRF, insecure deserialization, misconfig, sensitive-data exposure, CORS).
Perform deep API security testing, with priority on broken object/function-level authorization (BOLA/IDOR) across the multi-tenant patient/caregiver model — verifying that no user can read or mutate another patient's records via object identifiers.
Assess authentication & session security: Cognito token handling, JWT validation, token replay/expiry, cross–user-pool privilege escalation, password/2FA/reset flows, and account/caregiver delegation abuse.
Review cloud configuration & serverless posture: IAM least-privilege (over-permissioned execution roles), API Gateway config, S3 exposure, secrets handling in Lambda environments, and function-level injection/SSRF.
Test business logic: subscription/pricing manipulation and Stripe webhook integrity; consent bypass; record-lifecycle/caregiver-transfer abuse; provenance/mint signature verification and replay.
Assess AI/LLM surfaces for prompt injection, cross-tenant data leakage through model context, and unsafe tool/data access.
Evaluate PHI handling: data exposure in responses/logs/errors, excessive data return, and transport/storage protections relevant to HIPAA.
Produce a professional report and re-test confirmed fixes.
Required qualifications
4+ years of hands-on application and API penetration testing.
Demonstrated expertise in authorization testing / IDOR / multi-tenant isolation — this is the single most important skill for this engagement.
Strong AWS security knowledge: IAM, Cognito, Lambda, API Gateway, S3, RDS/DynamoDB; experience testing serverless architectures.
Proficiency with industry tooling (e.g., Burp Suite Pro, OWASP ZAP, Postman, nuclei, ScoutSuite/Prowler or equivalent) and comfort scripting custom checks (Python/JS).
Ability to read source code (Node.js and Python) to inform grey-box testing and validate findings.
Experience testing systems handling regulated/sensitive data and familiarity with HIPAA privacy/security expectations.
Clear written communication: risk-ranked findings (CVSS), reproducible steps, and practical remediation.
Preferred / bonus
Relevant certifications: OSCP, OSWE, GWAPT, eWPTXv2, CRTP/CARTP, AWS Security Specialty.
Healthcare security experience (HIPAA/HITRUST/SOC 2).
OAuth2/OIDC and Cognito-specific attack experience.
LLM/AI security (prompt injection, data-leakage) and/or Web3/smart-contract & signature testing.
Prior serverless/microservice assessment and secure code review.
Deliverables
Rules of Engagement and a test plan agreed before work begins.
A penetration test report: executive summary, methodology, findings with CVSS scores, evidence/PoCs, business impact, and prioritized remediation.
A remediation retest and an attestation letter suitable for customers/auditors.
A live findings walkthrough with engineering.
Engagement terms
Authorized testing only, strictly within the agreed scope and windows; no denial-of-service, no destructive actions, and no exfiltration of real PHI (use provided test data/accounts).
Coordinated timing to protect production; findings and any data handled under NDA + BAA; secure evidence storage and disposal.
Estimated duration and rate to be finalized during scoping.
Abrir en Upwork
AI proposal draft
Generate a short cover letter for this job. Edit before sending.
Sign in to generate an AI proposal draft.
Entrar