SaaS Security Engineer / Application Security Developer Needed
Бюджет: -
HOURLY / FULL_TIME
⭐ 4.46 (23)
United States
website-security, penetration-testing, vulnerability-assessment, application-security, information-security
Предпочтительная квалификация
- Опыт: Средний
We are looking for an experienced Application Security Engineer / Backend Security Developer to review, harden, and implement security controls for a new subscription-based SaaS/data platform.
The platform collects and processes proprietary data through automated systems, enriches that data, and distributes specific records to authorized subscribers through integrations with their CRM systems.
A major priority is protecting our data, proprietary collection methods, source information, software/IP, customer accounts, and backend infrastructure while ensuring subscribers can only access the information included within their subscriptions.
This is an implementation role—not simply a security audit. We need someone who can identify vulnerabilities and implement the necessary protections.
Primary Responsibilities
You will review the existing architecture and implement security measures including:
Authentication & authorization – secure login, session management, password policies, MFA capability, token security, and account protections.
Role-Based Access Control (RBAC) – users, administrators, developers, internal staff, and services should only have the permissions required for their roles.
Subscription/Territory Access Controls – customers must only receive or access data associated with the geographic areas/products included in their subscription.
Server-Side Enforcement – access restrictions must be enforced on the backend rather than relying on frontend/UI restrictions.
API Security – authentication, authorization, rate limiting, validation, API key management, webhook verification, and protection against unauthorized requests.
Database Security – proper permissions, encryption, isolation, backups, credential management, and prevention of unauthorized database access.
Data Exfiltration Protection – make large-scale scraping, enumeration, bulk extraction, unauthorized exporting, and automated harvesting significantly more difficult.
Secrets Management – secure storage and rotation of API keys, database credentials, tokens, webhook secrets, and third-party credentials.
Encryption – encryption in transit and appropriate encryption at rest for sensitive information.
Audit Logging – record important user/admin actions, authentication events, data access, subscription changes, API activity, and suspicious behavior.
Monitoring & Alerts – detect unusual login activity, abnormal data requests, excessive API calls, enumeration attempts, and other potentially malicious behavior.
Infrastructure Hardening – review server/cloud configuration, permissions, exposed services, firewall/network rules, production access, and deployment security.
Developer Access Controls – ensure contractors/developers cannot retain unnecessary production access, credentials, data, or administrative privileges.
Backup & Recovery – secure automated backups and appropriate recovery procedures.
Dependency Security – identify vulnerable packages/dependencies and establish a process for keeping critical components updated.
Proprietary Data / IP Protection
This platform's data pipeline and collection infrastructure are core business assets.
We specifically want the architecture reviewed so customers or unauthorized users cannot easily determine:
Where individual records originated
How the underlying collection infrastructure operates
Internal endpoints or infrastructure
Collection schedules/methodology
Backend credentials
Data belonging to other subscribers
Proprietary business logic
We also want appropriate separation between data collection systems, processing/enrichment systems, customer-facing systems, databases, and third-party integrations so compromising one component does not automatically expose the entire platform.
Customer Data Delivery
Customers do not need unrestricted access to the complete underlying database.
Data is primarily delivered into authorized customer systems through integrations/API/webhooks.
Security should therefore follow a least-privilege architecture where each customer/integration can only receive the specific records and fields it is authorized to receive.
Controls should prevent customers from simply modifying a request, customer ID, territory ID, endpoint, or other parameter to access another subscriber's information.
Security Review
As part of the project, we would like you to test for common SaaS/application vulnerabilities, including:
Broken access controls / IDOR
Authentication weaknesses
Privilege escalation
Injection vulnerabilities
API abuse
Rate-limit bypass
Cross-tenant data exposure
Enumeration
Insecure direct object references
Improper secrets exposure
Misconfigured cloud/storage resources
Vulnerable dependencies
Webhook spoofing/replay
Session/token vulnerabilities
Unauthorized bulk data extraction
Testing must be conducted only against systems and environments we explicitly authorize.
Deliverables
We expect this project to produce:
1. Security Architecture Review
Identify vulnerabilities and rank them:
Critical → High → Medium → Low
2. Remediation Plan
Explain what needs to change and the recommended architecture.
3. Implementation
Actually implement the agreed security improvements.
4. Testing
Verify that the protections work and attempt to bypass the newly implemented controls within the authorized environment.
5. Documentation
Document:
Security architecture
Access-control structure
Authentication
Permissions
Secrets management
Logging/monitoring
Backup procedures
Key security configurations
Incident/recovery procedures
Documentation should allow another qualified developer to maintain the system without weakening its security.
Ideal Candidate
Strong experience with:
SaaS application security
Backend development
API security
Cloud security
Database security
Authentication/authorization
RBAC
Multi-tenant SaaS architecture
OWASP Top 10
OWASP API Security
Encryption
Secrets management
Logging/monitoring
Rate limiting
Python and/or JavaScript
SQL/databases
AWS, GCP, Azure, or similar cloud infrastructure
Penetration testing / vulnerability assessment
Experience securing data platforms, subscription SaaS products, APIs, web scrapers/data pipelines, CRM integrations, or multi-tenant applications is particularly valuable.
Important
We are not looking for someone who simply runs an automated vulnerability scanner and sends us the report.
We need someone capable of understanding the architecture, finding weaknesses, recommending practical solutions, implementing those solutions, and verifying that they work.
When Applying
Please include:
Examples of SaaS applications you have secured.
Your backend development experience.
Your experience with multi-tenant application security.
Your experience securing APIs and webhooks.
Your experience with cloud infrastructure and databases.
Your experience implementing RBAC/authorization systems.
Whether you perform penetration testing in addition to development.
Which security tools/frameworks you typically use.
Your hourly rate.
Your weekly availability.
Please start your application with "SAAS SECURITY" so we know you read the complete posting.
Specific information regarding the platform, architecture, data sources, infrastructure, and proprietary processes will be provided to the selected developer after appropriate confidentiality agreements are in place.
Engagement
This will begin as a security review + implementation project.
For the right developer, there is potential for ongoing work reviewing new features, integrations, infrastructure changes, and security as the platform scales.
Открыть заказ
AI-черновик отклика
Короткий текст отклика для копирования в оффер: интерес + готовность работать.
Войдите, чтобы сгенерировать AI-черновик.
Войти