← İşler

Penetration Test for AWS Web Application

Bütçe: $20.0 - $50.0 HOURLY / PART_TIME ⭐ 2.66 (4) Canada

amazon-web-services, amazon-s3, amazon-ec2, software-qa-testing

Tercih edilen nitelikler

  • Yetenek tipi: Ajans
  • Konum: Canada
  • Deneyim: Orta
  • İngilizce: Ana dil
  • Min. kazanç: $100+
We need a Canadian-based company to perform a penetration test on a web application hosted in AWS. This is a small project for a short-term engagement, and we are not interested in individual freelancers. The work should include identifying vulnerabilities, testing security controls, and providing a clear report with findings and recommendations. Please apply only if your company is based in Canada and has experience with AWS environments. About the role Phenowise is a patient-centered health-data platform: patients and their caregivers record medical history, conditions, medications, symptoms, and daily trackers, with subscription billing and health-data provenance features. Because the product stores and shares Protected Health Information (PHI) across a multi-tenant, caregiver-delegated model, security is a first-class requirement. We're engaging a penetration tester to perform an authorized, black/grey-box assessment of our web application, public APIs, and cloud environment, and to deliver actionable, risk-ranked remediation guidance. This is hands-on offensive testing against a modern serverless AWS stack, followed by a remediation retest. What you'll be testing (technology context) Frontend: React single-page app (multiple environments: production, staging, QA). APIs: REST APIs on Amazon API Gateway backed by AWS Lambda (Node.js and Python), a mix of a legacy monolithic service and newer per-domain "router" microservices. AuthN/AuthZ: Amazon Cognito (separate end-user and administrative/console user pools); authorization enforced in application code (not at the gateway). Data: Aurora MySQL and PostgreSQL, DynamoDB, and a reference catalog DB; data reached via the RDS Data API and direct drivers. Payments: Stripe subscription billing (checkout, portal, webhooks). AI services: Python/LLM services (OpenAI/Bedrock-class models, vector search) that operate over patient-derived data. Domain features: consent ledger, record lifecycle / caregiver transfer, and a health-data "minting"/provenance flow. Key responsibilities Plan and execute a full-scope penetration test against agreed targets, following a recognized methodology (OWASP WSTG / API Security Top 10 / PTES), within documented rules of engagement. Test the web application for the OWASP Top 10 and beyond (injection, XSS, CSRF, SSRF, insecure deserialization, misconfig, sensitive-data exposure, CORS). Perform deep API security testing, with priority on broken object/function-level authorization (BOLA/IDOR) across the multi-tenant patient/caregiver model — verifying that no user can read or mutate another patient's records via object identifiers. Assess authentication & session security: Cognito token handling, JWT validation, token replay/expiry, cross–user-pool privilege escalation, password/2FA/reset flows, and account/caregiver delegation abuse. Review cloud configuration & serverless posture: IAM least-privilege (over-permissioned execution roles), API Gateway config, S3 exposure, secrets handling in Lambda environments, and function-level injection/SSRF. Test business logic: subscription/pricing manipulation and Stripe webhook integrity; consent bypass; record-lifecycle/caregiver-transfer abuse; provenance/mint signature verification and replay. Assess AI/LLM surfaces for prompt injection, cross-tenant data leakage through model context, and unsafe tool/data access. Evaluate PHI handling: data exposure in responses/logs/errors, excessive data return, and transport/storage protections relevant to HIPAA. Produce a professional report and re-test confirmed fixes. Required qualifications 4+ years of hands-on application and API penetration testing. Demonstrated expertise in authorization testing / IDOR / multi-tenant isolation — this is the single most important skill for this engagement. Strong AWS security knowledge: IAM, Cognito, Lambda, API Gateway, S3, RDS/DynamoDB; experience testing serverless architectures. Proficiency with industry tooling (e.g., Burp Suite Pro, OWASP ZAP, Postman, nuclei, ScoutSuite/Prowler or equivalent) and comfort scripting custom checks (Python/JS). Ability to read source code (Node.js and Python) to inform grey-box testing and validate findings. Experience testing systems handling regulated/sensitive data and familiarity with HIPAA privacy/security expectations. Clear written communication: risk-ranked findings (CVSS), reproducible steps, and practical remediation. Preferred / bonus Relevant certifications: OSCP, OSWE, GWAPT, eWPTXv2, CRTP/CARTP, AWS Security Specialty. Healthcare security experience (HIPAA/HITRUST/SOC 2). OAuth2/OIDC and Cognito-specific attack experience. LLM/AI security (prompt injection, data-leakage) and/or Web3/smart-contract & signature testing. Prior serverless/microservice assessment and secure code review. Deliverables Rules of Engagement and a test plan agreed before work begins. A penetration test report: executive summary, methodology, findings with CVSS scores, evidence/PoCs, business impact, and prioritized remediation. A remediation retest and an attestation letter suitable for customers/auditors. A live findings walkthrough with engineering. Engagement terms Authorized testing only, strictly within the agreed scope and windows; no denial-of-service, no destructive actions, and no exfiltration of real PHI (use provided test data/accounts). Coordinated timing to protect production; findings and any data handled under NDA + BAA; secure evidence storage and disposal. Estimated duration and rate to be finalized during scoping.
Upwork'te aç

AI proposal draft

Generate a short cover letter for this job. Edit before sending.

Sign in to generate an AI proposal draft.

Giriş yap