← İşler

Senior Node.js / Linux Systems-Security Architect — Bounded Architecture Review

Bütçe: $400.0 FIXED / ⭐ 0.00 (0) United Kingdom

software-architecture, node.js, linux-system-administration, security-infrastructure, network-security

Tercih edilen nitelikler

  • Deneyim: Uzman
I need a senior systems/security engineer for a tightly bounded technical architecture review. This is not a general cybersecurity audit, penetration test, website review or development engagement. We have already completed multiple architecture and independent-review cycles for a security-critical CI execution/evidence mechanism. Most controls are settled and explicitly out of scope for redesign. A small set of unresolved trust-boundary questions remains. I want an experienced human engineer to resolve those questions and provide precise architecture invariants before we continue implementation. Relevant expertise: - Node.js runtime/module-loader internals - Linux/Unix process identity, child processes and process trees/groups - PTYs / command execution / execution-session identity - sandboxing or capability-security models - secure CI/runtime architecture - append-only audit/event journals - security-sensitive lifecycle/evidence ordering The remaining questions concern: 1. execution identity and authority: correct separation/binding of application task identity, tool/PTY session identity, command-execution identity and OS process identity; 2. official-root / pre-mutation authority: what may execute before the authoritative root/marker and how arbitrary or write-capable submitted programs must be classified; 3. bootstrap / loader / capability authority: mechanically defining trusted Node bootstrap/loader policy and access to sensitive capabilities such as fs, child_process, path, url and related modules; 4. semantic-journal integrity: exact field/identity semantics, failure vocabulary and mechanically valid state transitions; 5. terminal evidence ordering: preventing a terminal certificate from claiming completion before all required evidence/manifests/checksums are durably complete; 6. adversarial coverage: ensuring the test model attacks the actual authority and identity boundaries above. DELIVERABLE One concise written architecture decision note containing: - correct typed execution/authority identity model; - official-root/pre-root invariant; - bootstrap/loader/capability invariant; - corrected semantic-journal requirements; - terminal evidence-ordering invariant; - required adversarial test cases; - any remaining issue that cannot safely be resolved under the existing constraints. Plus one short follow-up discussion/message round for clarification. NO CODE OR IMPLEMENTATION IS REQUIRED. You will receive a clinical technical evidence pack after shortlisting. You are not expected to reconstruct project history. IMPORTANT SCOPE You will NOT be asked to: - redesign the wider system; - implement the architecture; - access Production; - deploy anything; - change credentials or providers; - weaken already-established security controls; - audit unrelated application code. This should be a bounded senior architecture review, not an ongoing engagement. APPLICATION REQUIREMENT Please answer these four questions briefly. Generic applications that do not answer them will not be considered. 1. In a tool-driven command-execution system, why would a PTY/tool session identifier normally NOT be safe to treat as the OS PID or root execution authority? 2. How would you conceptually bind an application task to the OS processes actually authorised to execute on its behalf without assuming those identities are the same thing? 3. What experience do you have with Node.js loader/bootstrap security, process isolation, sandboxing or capability restriction? 4. Give one example of a system where evidence or an audit journal could incorrectly claim terminal success before the evidence required to prove that success was itself durably complete. Please include your relevant experience and confirm that you can complete the fixed deliverable for £300. Individuals only — no agencies.
Upwork'te aç

AI proposal draft

Generate a short cover letter for this job. Edit before sending.

Sign in to generate an AI proposal draft.

Giriş yap