← Вакансії

Web Application Penetration Tester (OWASP / OSCP) SaaS pre-launch security assessment + attestation

Бюджет: $500.0 FIXED / ⭐ 0.00 (0) Australia

penetration-testing, application-security, vulnerability-assessment, assessments-and-testing, web-application-security, owasp, iso-27001, soc-2-report

We are a SaaS company preparing, a web application, for launch. Before go-live we need a manual web application penetration test performed by an independent third party, delivered to a standard we can later reuse as evidence in our SOC 2 and ISO 27001 programs. This is not an automated scan. We are looking for someone who does hands-on, manual testing following a recognized methodology and produces a professional report plus a formal attestation letter. Scope of work Authenticated and unauthenticated web application penetration test Coverage of the OWASP Top 10 and testing aligned to OWASP ASVS API / backend endpoint testing Authentication, session management, and password/reset flows Access-control testing between user roles, including multi-tenant data isolation (verifying one customer/tenant cannot access another's data) Input handling: injection, XSS, SSRF, file upload, etc. Business-logic testing (not just scanner findings) Target environment: [staging URL / production — specify]. Tech stack: [e.g. React front end, Node/Python API, PostgreSQL, hosted on AWS]. Approx. size: [X endpoints / Y user roles]. Required deliverables Penetration test report including: executive summary, methodology used, full scope, each finding with severity rating (CVSS), evidence/reproduction steps, and specific remediation guidance. Formal Penetration Test Attestation Letter on your/your company letterhead, stating the application tested, the scope, the testing dates, and — after remediation — confirmation that identified issues were retested and resolved. (We will use this for internal sign-off and as evidence toward SOC 2 / ISO 27001.) One free retest round after we remediate the findings, with an updated attestation reflecting closed items. A redacted sample report shared during screening so we can assess report quality before hiring. Independence note You will perform testing only. Our own engineering team will implement the fixes — please do not include code remediation of our application in your scope, as we need to preserve tester independence for audit purposes.
Відкрити на Upwork