Web Application Penetration Tester (OWASP / OSCP) SaaS pre-launch security assessment + attestation
Rozpočet: $500.0
FIXED /
⭐ 0.00 (0)
Australia
penetration-testing, application-security, vulnerability-assessment, assessments-and-testing, web-application-security, owasp, iso-27001, soc-2-report
We are a SaaS company preparing, a web application, for launch. Before go-live we need a manual web application penetration test performed by an independent third party, delivered to a standard we can later reuse as evidence in our SOC 2 and ISO 27001 programs.
This is not an automated scan. We are looking for someone who does hands-on, manual testing following a recognized methodology and produces a professional report plus a formal attestation letter.
Scope of work
Authenticated and unauthenticated web application penetration test
Coverage of the OWASP Top 10 and testing aligned to OWASP ASVS
API / backend endpoint testing
Authentication, session management, and password/reset flows
Access-control testing between user roles, including multi-tenant data isolation (verifying one customer/tenant cannot access another's data)
Input handling: injection, XSS, SSRF, file upload, etc.
Business-logic testing (not just scanner findings)
Target environment: [staging URL / production — specify]. Tech stack: [e.g. React front end, Node/Python API, PostgreSQL, hosted on AWS]. Approx. size: [X endpoints / Y user roles].
Required deliverables
Penetration test report including: executive summary, methodology used, full scope, each finding with severity rating (CVSS), evidence/reproduction steps, and specific remediation guidance.
Formal Penetration Test Attestation Letter on your/your company letterhead, stating the application tested, the scope, the testing dates, and — after remediation — confirmation that identified issues were retested and resolved. (We will use this for internal sign-off and as evidence toward SOC 2 / ISO 27001.)
One free retest round after we remediate the findings, with an updated attestation reflecting closed items.
A redacted sample report shared during screening so we can assess report quality before hiring.
Independence note
You will perform testing only. Our own engineering team will implement the fixes — please do not include code remediation of our application in your scope, as we need to preserve tester independence for audit purposes.
Otvoriť na Upwork