← Oferty

SaaS Security Engineer / Application Security Developer Needed

Budżet: - HOURLY / FULL_TIME ⭐ 4.46 (23) United States

website-security, penetration-testing, vulnerability-assessment, application-security, information-security

Preferowane kwalifikacje

  • Doświadczenie: Średniozaawansowany
We are looking for an experienced Application Security Engineer / Backend Security Developer to review, harden, and implement security controls for a new subscription-based SaaS/data platform. The platform collects and processes proprietary data through automated systems, enriches that data, and distributes specific records to authorized subscribers through integrations with their CRM systems. A major priority is protecting our data, proprietary collection methods, source information, software/IP, customer accounts, and backend infrastructure while ensuring subscribers can only access the information included within their subscriptions. This is an implementation role—not simply a security audit. We need someone who can identify vulnerabilities and implement the necessary protections. Primary Responsibilities You will review the existing architecture and implement security measures including: Authentication & authorization – secure login, session management, password policies, MFA capability, token security, and account protections. Role-Based Access Control (RBAC) – users, administrators, developers, internal staff, and services should only have the permissions required for their roles. Subscription/Territory Access Controls – customers must only receive or access data associated with the geographic areas/products included in their subscription. Server-Side Enforcement – access restrictions must be enforced on the backend rather than relying on frontend/UI restrictions. API Security – authentication, authorization, rate limiting, validation, API key management, webhook verification, and protection against unauthorized requests. Database Security – proper permissions, encryption, isolation, backups, credential management, and prevention of unauthorized database access. Data Exfiltration Protection – make large-scale scraping, enumeration, bulk extraction, unauthorized exporting, and automated harvesting significantly more difficult. Secrets Management – secure storage and rotation of API keys, database credentials, tokens, webhook secrets, and third-party credentials. Encryption – encryption in transit and appropriate encryption at rest for sensitive information. Audit Logging – record important user/admin actions, authentication events, data access, subscription changes, API activity, and suspicious behavior. Monitoring & Alerts – detect unusual login activity, abnormal data requests, excessive API calls, enumeration attempts, and other potentially malicious behavior. Infrastructure Hardening – review server/cloud configuration, permissions, exposed services, firewall/network rules, production access, and deployment security. Developer Access Controls – ensure contractors/developers cannot retain unnecessary production access, credentials, data, or administrative privileges. Backup & Recovery – secure automated backups and appropriate recovery procedures. Dependency Security – identify vulnerable packages/dependencies and establish a process for keeping critical components updated. Proprietary Data / IP Protection This platform's data pipeline and collection infrastructure are core business assets. We specifically want the architecture reviewed so customers or unauthorized users cannot easily determine: Where individual records originated How the underlying collection infrastructure operates Internal endpoints or infrastructure Collection schedules/methodology Backend credentials Data belonging to other subscribers Proprietary business logic We also want appropriate separation between data collection systems, processing/enrichment systems, customer-facing systems, databases, and third-party integrations so compromising one component does not automatically expose the entire platform. Customer Data Delivery Customers do not need unrestricted access to the complete underlying database. Data is primarily delivered into authorized customer systems through integrations/API/webhooks. Security should therefore follow a least-privilege architecture where each customer/integration can only receive the specific records and fields it is authorized to receive. Controls should prevent customers from simply modifying a request, customer ID, territory ID, endpoint, or other parameter to access another subscriber's information. Security Review As part of the project, we would like you to test for common SaaS/application vulnerabilities, including: Broken access controls / IDOR Authentication weaknesses Privilege escalation Injection vulnerabilities API abuse Rate-limit bypass Cross-tenant data exposure Enumeration Insecure direct object references Improper secrets exposure Misconfigured cloud/storage resources Vulnerable dependencies Webhook spoofing/replay Session/token vulnerabilities Unauthorized bulk data extraction Testing must be conducted only against systems and environments we explicitly authorize. Deliverables We expect this project to produce: 1. Security Architecture Review Identify vulnerabilities and rank them: Critical → High → Medium → Low 2. Remediation Plan Explain what needs to change and the recommended architecture. 3. Implementation Actually implement the agreed security improvements. 4. Testing Verify that the protections work and attempt to bypass the newly implemented controls within the authorized environment. 5. Documentation Document: Security architecture Access-control structure Authentication Permissions Secrets management Logging/monitoring Backup procedures Key security configurations Incident/recovery procedures Documentation should allow another qualified developer to maintain the system without weakening its security. Ideal Candidate Strong experience with: SaaS application security Backend development API security Cloud security Database security Authentication/authorization RBAC Multi-tenant SaaS architecture OWASP Top 10 OWASP API Security Encryption Secrets management Logging/monitoring Rate limiting Python and/or JavaScript SQL/databases AWS, GCP, Azure, or similar cloud infrastructure Penetration testing / vulnerability assessment Experience securing data platforms, subscription SaaS products, APIs, web scrapers/data pipelines, CRM integrations, or multi-tenant applications is particularly valuable. Important We are not looking for someone who simply runs an automated vulnerability scanner and sends us the report. We need someone capable of understanding the architecture, finding weaknesses, recommending practical solutions, implementing those solutions, and verifying that they work. When Applying Please include: Examples of SaaS applications you have secured. Your backend development experience. Your experience with multi-tenant application security. Your experience securing APIs and webhooks. Your experience with cloud infrastructure and databases. Your experience implementing RBAC/authorization systems. Whether you perform penetration testing in addition to development. Which security tools/frameworks you typically use. Your hourly rate. Your weekly availability. Please start your application with "SAAS SECURITY" so we know you read the complete posting. Specific information regarding the platform, architecture, data sources, infrastructure, and proprietary processes will be provided to the selected developer after appropriate confidentiality agreements are in place. Engagement This will begin as a security review + implementation project. For the right developer, there is potential for ongoing work reviewing new features, integrations, infrastructure changes, and security as the platform scales.
Otwórz na Upwork

AI proposal draft

Generate a short cover letter for this job. Edit before sending.

Sign in to generate an AI proposal draft.

Zaloguj