Discover projects tailored to your expertise in security analysis on platforms like Upwork. Vollna enhances your search with advanced filters, real-time notifications, and comprehensive analytics, enabling you to bid smarter and win more.
Signup for free
to get access to all filter attributes and instant notifications when new jobs are posted.
Setup filter
Get access to over 30+ filter attributes, setup instant notifications, integrate with your CRM and marketing tools, and more.
Ethical Hacker / Penetration Tester Needed for Web & API Security Audit
Applied
$10 - $20
/ hr
1 hour ago
1
Ethical Hacker / Penetration Tester Needed for Web & API Security Audit
We are looking for an experienced **Ethical Hacker / Cybersecurity Expert / Penetration Tester** to audit our own web applications, APIs, servers, and related projects.
🎯 Objective
Our goal is **not to attack or damage any system**. We want a security professional who can think like an attacker, identify weaknesses in our projects, and help our development team make them more secure.
🔍 Scope of Work
Depending on the project, you may be required to test:
* Web applications
* REST APIs
* Admin panels
* User authentication & authorization
* Payment-related flows
* API endpoints
* Database security
* Server & hosting configuration
* Session management
* Access control
* File upload functionality
* Input validation
* Encryption & sensitive data exposure
* Rate limiting
* Business logic vulnerabilities
* OWASP Top 10 vulnerabilities
* Other security weaknesses
🛡️ What We Expect
We need someone who can perform **real-world security testing**, not just automated vulnerability scanning.
You should be able to:
* Identify vulnerabilities
* Verify whether vulnerabilities are actually exploitable
* Explain the security impact
* Provide a clear Proof of Concept (PoC) where appropriate
* Assign severity/risk levels
* Explain how our developers can fix the issue
* Re-test the application after fixes
📄 Deliverables
For each project, we expect a professional security report containing:
1. Vulnerability name
2. Severity – Critical / High / Medium / Low
3. Affected URL/API/component
4. Description of the vulnerability
5. Steps to reproduce
6. Proof of Concept / screenshots where applicable
7. Potential business/security impact
8. Recommended remediation
9. Retest results after fixes
👨💻 Preferred Experience
Experience with:
* Web Application Penetration Testing
* API Security Testing
* OWASP Top 10
* Burp Suite
* OWASP ZAP
* Nmap
* Linux
* API testing
* Authentication & authorization testing
* Secure coding practices
Certifications such as **OSCP, CEH, eJPT, PNPT, GPEN** or equivalent practical experience are a plus.
🔐 Important
All testing will be performed **only on systems/projects that we own or are explicitly authorized to test**.
We can provide the required test credentials, staging environments, API documentation and other information necessary for authorized testing.
An **NDA/confidentiality agreement** may be required before access is provided.
📩 When Applying
Please send:
* Your cybersecurity/penetration testing experience
* Relevant certifications (if any)
* Examples of previous security audits/pentest work
* Types of applications you have tested
* Your preferred hourly or fixed project rate
* Estimated time required for a typical web/API security audit
We are looking for someone interested in **long-term collaboration**, as we have multiple projects that require regular security assessments.
**Please do not perform any testing against our systems before a contract and written authorization are provided.**
Hourly rate:
10 - 20 USD
1 hour ago
IT & Networking, Information Security & Compliance
We are seeking a cyber security expert to help protect our systems and data. The ideal candidate will have experience in identifying vulnerabilities, implementing security measures, and responding to threats. You will work closely with our team to ensure our infrastructure remains secure and compliant. This is a part-time role with potential for long-term engagement for the right fit.
Fixed budget:
20 USD
10 hours ago
IT & Networking, Information Security & Compliance
Cybersecurity; Web Application Security Review
Applied
$10 - $40
/ hr
13 hours ago
4
Looking for an experienced web application security expert / ethical hacker to review our platform before launch. Focus on the Seller interface, Admin interface, backend/API, and landing page. We want to identify any critical security vulnerabilities, access-control issues, exposed secrets, or common OWASP vulnerabilities. Customer/Marketplace interface is excluded. Looking for a practical, hands-on review with clear recommendations. 1-2 hours work.
Hourly rate:
10 - 40 USD
13 hours ago
IT & Networking, Information Security & Compliance
We are looking for a cybersecurity expert with skills in the following areas:
- Disaster Recovery
- network security configuration
- cloud security configuration
- vulnerability scanning
- baseline security hardening (OS and network)
Hourly rate:
40 - 60 USD
18 hours ago
IT & Networking, Information Security & Compliance
I am looking for an experienced WordPress security / malware specialist to investigate and permanently clean a persistent infection on a shared hosting account.
This is NOT a simple malware removal job. The websites have been compromised repeatedly despite previous restorations, password changes, WordPress/plugin updates and security measures.
Current situation:
Unknown WordPress accounts have repeatedly appeared, including accounts obtaining administrator access.
A suspicious administrator successfully logged into WordPress from a foreign IP.
A security plugin was deleted without my intervention.
My hosting provider has detected malware in the main /index.php.
The hosting provider believes a persistent backdoor may still exist.
Several WordPress installations/domains are hosted under the same hosting account.
Nginx access logs are available for investigation.
The affected websites are currently temporarily taken offline.
I need someone who can:
- Scan the entire hosting account and all WordPress installations, not only the currently infected website.
- Investigate WordPress files AND databases.
- Find and remove malware, backdoors and persistence mechanisms.
- Inspect WordPress core files, plugins, themes, uploads, PHP files and cron jobs.
- Investigate how unauthorized administrator accounts are being created.
- Analyse available access logs where useful.
- Identify the likely vulnerability / entry point responsible for the reinfections.
- Replace compromised core files with clean originals where necessary.
- Check all WordPress users and remove malicious persistence.
- Update and harden the installations after cleanup.
- Confirm that the websites are clean before bringing them back online.
- Provide a short report explaining what was found, what was compromised, what was removed and what security measures were implemented.
Important: I am specifically looking for someone experienced with persistent/recurrent WordPress infections and backdoor investigation, not someone who will simply run a malware scanner and delete the detected files.
Please explain in your proposal:
Your experience with persistent WordPress malware/backdoor infections.
How you would approach this investigation.
Whether you will inspect the entire hosting account and all WordPress installations.
Whether you will investigate the root cause of the reinfection.
Your estimated timeframe and total cost.
Please include examples of similar cases you have successfully resolved.
Hourly rate:
20 - 50 USD
19 hours ago
IT & Networking, Information Security & Compliance
My WordPress website is experiencing issues with spam emails every 5 minutes, indicating a potential malware problem. I urgently need a specialist to diagnose and resolve this issue as soon as possible. The ideal candidate will have experience in security and malware removal to ensure my site is safe and functioning properly.
IT Security Specialist for Application and Website
Applied
$200 - $500
/ hr
1 day ago
3
We are seeking an IT Security Specialist to ensure the security of our new application and website. The ideal candidate will have experience in penetration testing and security analysis to identify vulnerabilities and implement effective security measures. Familiarity with PHP and internet security is essential. The role involves conducting thorough security audits and providing recommendations for improvement.
Hourly rate:
200 - 500 USD
1 day ago
IT & Networking, Information Security & Compliance
I'm looking for a security/pentesting review of a mobile app I'm preparing for beta and wanted to see if you'd be interested.
The app is a privacy-focused personal finance/expense tracking app built with React Native/Expo, with a Node.js/Express backend and PostgreSQL.
Because it handles financial data, I'm mainly concerned with vulnerabilities that could expose one user's data to another or allow unauthorized backend access.
The main areas I'd like tested are:
- Authentication and session/token security
- API authorization and IDOR/BOLA issues
- Cross-user data isolation
- REST API endpoints
- File uploads (receipts, PDFs, bank statements)
- File storage and access permissions
- Input handling and malicious uploads
- Gmail OAuth integration and token handling
- Data exposure through the API
- Rate limiting and API abuse
- Secrets or configuration exposure
- Basic React Native client-side security (local storage, network traffic)
I'm primarily looking for manual penetration testing rather than an automated scan. For any findings, I'd like reproducible steps/PoCs, severity, and remediation guidance.
Would you be interested in this project? If so, could you let me know what scope you could reasonably cover and roughly how much time it would require?
Budget:
not specified
1 day ago
IT & Networking, Information Security & Compliance
We are seeking a hands on server security consultant to review our production LAMP environment (Apache, PHP, MySQL on Linux). The focus is abusive and scraping traffic against public pages, and how we detect and block that traffic at the origin. The ideal candidate will assess our current approach, recommend a practical hardening and blocking path, and join a short call with our CEO and CTO to discuss findings and next steps. This is a small consulting engagement, and we may extend to a short written plan and optional implementation help if it is a good fit.
Budget:
not specified
1 day ago
IT & Networking, Information Security & Compliance
Penetration Testing Expert Needed for Security Assessment
Applied
$20 - $50
/ hr
1 day ago
5
We are looking for a qualified independent penetration testing firm or experienced security
professional who can begin immediately and complete a comprehensive grey-box penetration test as
soon as possible.
This assessment is required for an enterprise third-party security review, so fast turnaround is
important. Please apply only if you have near-term availability and can provide a professional,
compliance-ready penetration testing report.
Scope
The penetration test must cover the full product environment, including:
• Web application
• APIs and API endpoints
• Authentication and authorization
• User roles and privilege boundaries
• Business logic
• Session management
• Data storage and transmission
• Relevant third-party integrations
• Connections to downstream systems
• Systems where Amazon Data or Amazon metadata is stored, processed, or transmitted
• Cloud hosting environment, including relevant AWS, Azure, GCP, or other infrastructure
• Internet-facing infrastructure associated with the product
• OWASP Top 10 and OWASP API Security risks
The assessment must be grey-box in nature. We can provide test accounts, documentation,
architecture information, API details, and other reasonable access required for testing.
Automated vulnerability scanning alone is not sufficient. Manual penetration testing is required.
Required Report
The final penetration testing report must be minimally redacted and suitable for submission to an
enterprise security/compliance team.
For each finding, the report must clearly include:
• Severity: Critical, High, Medium, Low, or Informational
• CVE, where applicable
• CVSS score, where applicable
• Technical description
• Evidence
• Security/business impact
• Recommended remediation
• Resolution/remediation status
The report should also include:
• Executive summary
• Testing methodology
• Testing dates
• Full scope tested
• Systems/APIs/infrastructure assessed
• Overall conclusion
Remediation Validation
For any Critical or High findings, we require:
• Remediation by our team
• Independent retesting by the penetration testing provider
• Written validation confirming successful remediation
• Updated/final report reflecting the remediation status
For Medium and Low findings, remediation recommendations must be provided so that resolution can
be planned within 60 days or less post-launch.
Please specify whether remediation retesting is included in your quoted price.
Timing — IMPORTANT
We need this engagement completed ASAP.
Please provide:
• Earliest date you can begin
• Estimated number of business days required for testing
• Estimated date for delivery of the initial report
• Estimated turnaround for remediation retesting
• Confirmation that you can prioritize this engagement
Applicants who can start immediately or within the next few days will be prioritized.
Qualifications
Preferred qualifications include:
• OSCP / OSEP / OSCE
• CREST
• GPEN / GWAPT / GXPN
• CISSP
• Comparable recognized penetration-testing credentials
You should have demonstrated experience with:
• SaaS penetration testing
• Web application penetration testing
• API penetration testing
• AWS/Azure/GCP security assessments
• OWASP testing methodology
• Enterprise vendor security assessments
• Preparing professional penetration test reports for security/compliance reviews
Experience supporting Amazon vendor/security reviews or similar large-enterprise security
assessments is highly desirable.
Please Include With Your Proposal
Please begin your application with “GREY BOX” and provide:
1. Your earliest available start date
2. Expected testing duration
3. Expected report delivery date
4. Your fixed-price estimate or hourly estimate
5. Relevant certifications
6. Brief examples of comparable engagements
7. A sample redacted penetration-testing report, if available
8. Your testing methodology
9. Confirmation that manual testing will be performed
10. Confirmation that you can test the application, APIs, downstream connections, and relevant
cloud environment
11. Confirmation that you provide independent remediation validation for Critical and High findings
12. Number of remediation/retesting rounds included
Priority will be given to qualified applicants who can start immediately and provide a fast turnaround
without compromising the quality of the assessment.
Hourly rate:
20 - 50 USD
1 day ago
IT & Networking, Information Security & Compliance
Linux Malware Investigation – Incident Response
Applied
not specified
1 day ago
4
Linux Malware Investigation – Incident Response
We are looking for a senior Linux malware analyst / incident response specialist to investigate a suspected compromise affecting our production Linux servers.
We have identified suspicious root-level ELF executables with watchdog (--guard) behavior, cron/systemd persistence, suspicious /tmp files, and local listening ports. Similar suspicious activity has been identified on multiple servers.
Scope of Work
• Identify and analyze the malware and determine its purpose.
• Investigate how the servers were compromised.
• Identify all persistence mechanisms and related malicious files/processes.
• Analyze network connections, C2 activity, and suspicious local ports.
• Determine whether multiple affected servers are related.
• Check for credential, source-code, or data compromise.
• Provide IOCs (hashes, IPs, domains, files, processes, etc.).
• Provide a forensic timeline and root-cause assessment.
• Recommend safe containment, removal, and server hardening/rebuild procedures.
• Review relevant Wazuh alerts and recommend additional detection rules.
Environment
Ubuntu/Linux, Node.js/Next.js, PM2, Apache/Nginx, MongoDB, Redis, Docker/containerd, SSH, and Wazuh.
Required Experience
Please have proven experience with:
• Linux malware analysis and incident response
• ELF reverse engineering
• Root-level Linux compromises
• Cron/systemd persistence
• Network/C2 investigation
• Ghidra/IDA/radare2, strace, lsof, etc.
• Web application and Node.js compromise investigation
This is an authorized investigation of our own infrastructure. Production systems are involved, so evidence preservation and a forensic-first approach are required.
Please briefly describe a similar Linux malware investigation you have completed and the tools you used.
Budget:
not specified
1 day ago
IT & Networking, Information Security & Compliance
Onyx Digital Security is a Boston-based managed security and compliance firm for regulated financial services and CPA/tax firms. We’re hiring a hands-on technician to deploy and manage our security stack during client onboarding and ongoing service.
Note: this is a deployment/configuration role, not a 24/7 SOC monitoring role — alert triage on our EDR platform is handled by our managed detection provider (Huntress). You’ll be acting on what they escalate, not staffing a live queue.
What you’ll do:
• Deploy and configure MFA (Duo), RMM agents (NinjaOne), email/DNS security (TitanHQ), and EDR (Huntress) during client onboarding
• Run live technical sessions directly with clients — admin access consent, email routing/MX cutover, agent deployment
• Maintain client IT documentation in our documentation platform (Hudu) during technical work
• Act on alerts and escalations from our managed EDR/MDR provider
• Support onboarding questionnaire review alongside our GRC Analyst
• Assist with the technical side of annual reviews and renewals
What we’re looking for:
• Experience with RMM platforms (NinjaOne or similar), MFA/IAM tools (Duo or similar), and email security/DNS filtering
• Comfortable running live technical sessions directly with non-technical clients — led by senior staff.
• IT/helpdesk, MSP, or systems administration background
Nice to have:
• Security+ or similar certification
• Prior MSP industry experience
• Familiarity with Huntress or similar EDR/MDR platforms
Hourly rate:
20 - 26 USD
3 days ago
IT & Networking, Information Security & Compliance
I’m facing a network security concern in my current environment and want the entire fix documented in a way that is clear, engaging, and visually appealing. In short, I need the technical know-how of network and connectivity support combined with creative services that can turn complex steps into materials my wider team will actually read and follow.
Here’s what I’m after:
• Identify and explain the root of the security issue, showing me where the vulnerability sits.
• Provide a concise remediation plan and then implement or guide me through the fix.
• Translate that plan into easy-to-digest creative assets—this could be a short illustrated guide, an infographic, or another visual format that explains the solution and any ongoing best practices.
You’re free to use whichever security-analysis tools you trust (Wireshark, Nmap, etc.) and whichever creative suite you prefer (Adobe Illustrator, Figma, Canva—your call) as long as the final deliverables are polished and usable for non-technical staff.
If this combination of hands-on network security support and clear, creative communication sounds like your wheelhouse, I’d love to see how you’d tackle it.
We are urgently looking for an experienced Cybersecurity / Incident Response Expert to help us investigate and resolve a security incident involving a client project.
We have been working with this client for approximately 3 months. Their development server appears to have been compromised, and some API keys / credentials were publicly exposed.
We need an expert who can immediately help us:
Investigate how the server was compromised.
Identify the initial attack vector and security vulnerability.
Determine whether credentials, API keys, source code, databases, or other sensitive data were accessed.
Check server logs, authentication logs, deployment history, Git repositories, CI/CD, cloud infrastructure, and exposed credentials.
Identify any malware, backdoors, unauthorized users, persistence mechanisms, or suspicious processes.
Contain and remediate the compromise.
Secure the server and infrastructure.
Review how the keys became publicly exposed.
Recommend credential rotation, access-control, firewall, SSH, IAM, and infrastructure security improvements.
Provide a clear incident investigation report explaining what happened, how it happened, what was affected, and how to prevent it from happening again.
Ideal Experience
We are specifically looking for someone with hands-on experience in:
Cybersecurity incident response
Server compromise investigation
Digital forensics
Linux/server security
Cloud security (AWS or similar)
Credential/API key exposure
Git/GitHub security
CI/CD security
Web application security
Log analysis and attack-vector identification
This is urgent. We need someone who can start immediately, investigate the incident systematically, and communicate findings clearly to both our technical team and the client.
Please share relevant experience with server compromise investigations or incident-response cases, along with your availability to start.
Client's questions:
To avoid bots and spam, please share a quick personalized Loom video explaining how you can help us with this issue.
Hourly rate:
30 - 70 USD
4 days ago
IT & Networking, Information Security & Compliance
IT Security Analyst – Windows Server Hardening & Security Review
Applied
$30 - $70
/ hr
4 days ago
5
We are a small SaaS company running a Windows Server / IIS environment serving our customers and we are looking for an experienced IT security analyst to help us strengthen our infrastructure.
The work involves reviewing our current firewall configuration, validating our Crowd Strike Falcon endpoin setup, auditing open ports and access controls, and identifying any vulnerabilities in our environment. We also need someone to set up a web application firewall with a reverse proxy (preferably Coraza with NGINX) in front of our IIS servers.
This is a short term engagement to start, with potential for ongoing work depending on fit. Ideal candidates will have hands on experience with Windows Server security, IIS hardening, network firewall configuration, and WAF deployment.
Please include examples of similar work in your proposal.
Hourly rate:
30 - 70 USD
4 days ago
IT & Networking, Information Security & Compliance
We need an expert to review our current Cloudflare security setup and identify gaps, risks, and opportunities for improvement. The consultant will assess our configuration, recommend practical changes, and provide a clear report with prioritized actions. This is a short-term project for someone who can quickly evaluate our security posture and help strengthen our defenses.
Hourly rate:
20 - 40 USD
4 days ago
IT & Networking, Information Security & Compliance
Microsoft Sentinel Expert Needed for SIEM Implementation & Security Automation
Applied
not specified
4 days ago
5
Project Overview
We are seeking a highly experienced Microsoft Sentinel Consultant to assist with the design, implementation, optimization, and automation of a Microsoft Sentinel deployment for our managed services practice.
The ideal candidate will have hands-on experience integrating Microsoft security products and third-party solutions, developing detection rules, and implementing automated incident response workflows.
Responsibilities
Configure and optimize Microsoft Sentinel
Connect and normalize log sources from:
Microsoft 365
Entra ID (Azure AD)
Microsoft Defender XDR
Cisco Firepower FMC
Windows and Linux servers
Develop custom Analytics Rules and detection logic
Create and optimize KQL queries for threat hunting and investigations
Build automation playbooks using Logic Apps
Configure incident management workflows and alert tuning
Create dashboards, workbooks, and executive reporting
Document configurations and provide knowledge transfer
Required Experience
3+ years of Microsoft Sentinel experience
Strong Kusto Query Language (KQL) skills
Experience with Microsoft Defender XDR
Experience with Azure Monitor and Log Analytics
Experience integrating third-party security platforms (Cisco, Palo Alto, Fortinet, etc.)
Experience building Sentinel Automation Rules and Playbooks
Strong understanding of SOC operations and incident response
Preferred Qualifications
SC-200 (Microsoft Security Operations Analyst)
Microsoft Security certifications
Experience working with MSPs or MSSPs
Experience integrating Cisco Firepower Management Center (FMC)
Experience with ServiceNow integrations
Summary of your Microsoft Sentinel experience
Relevant certifications
Examples of Sentinel deployments you have completed
Experience integrating Cisco Firepower or other firewall platforms
Sample KQL queries or automation workflows you have developed
Budget:
not specified
4 days ago
IT & Networking, Information Security & Compliance
Apply the fix and remove any malicious or vulnerable code
Verify the fix works and the issue no longer appears
Confirm no related vulnerabilities were left open.
Website Security Review — Code Scan + Basic Penetration Test for Early-Stage Marketplace
Applied
$500
5 days ago
4
I'm launching marketplace website with customer/vendor accounts, messaging, and Stripe-based vendor billing (no in-app payment processing between customers and vendors). I'd like a security review before going live.
Scope:
Static code scan for common vulnerabilities (exposed secrets/API keys, insecure dependencies, known vulnerable patterns)
Basic web application penetration test covering authentication/authorization (login, account access, admin portal), input validation (forms, messaging, search), and data exposure risks (e.g., customer/vendor personal info, order data)
A written report of findings, prioritized by severity, with clear remediation guidance
Not in scope right now: load/stress testing, compliance certification (PCI/SOC2/etc.), infrastructure/network testing.
Important: I'm looking for genuine manual testing, not just results run through an automated scanning tool. I've been told automated-only scans can be unreliable and miss real vulnerabilities, so please describe your actual testing process in your proposal, and how much of it is manual versus automated.
What I'll provide: access to a staging environment (not production), relevant documentation on app structure, and availability for questions during the engagement.
Please provide a fixed-price quote based on the scope above (not hourly), along with relevant experience, certifications (OSCP, GPEN, CEH, etc. a plus but not required for this scope), and a sample redacted report if available.
Note: I'm also separately hiring for a security review of my iOS and Android apps. If you have experience with mobile app security testing as well, feel free to bid on both jobs, or mention your mobile experience here and I can discuss combining the engagements.
Fixed budget:
500 USD
5 days ago
IT & Networking, Information Security & Compliance
We are looking for an experienced VAPT / Penetration Testing Expert to perform security testing of web applications and APIs.
Responsibilities
• Conduct manual and automated VAPT of web applications and APIs.
• Identify OWASP Top 10 and API Security vulnerabilities.
• Test authentication, authorization, IDOR, SQLi, XSS, SSRF, CSRF, business logic, and other security issues.
• Use tools such as Burp Suite, Nmap, OWASP ZAP, Kali Linux, etc.
• Validate vulnerabilities and provide clear PoCs/evidence.
• Prepare a professional VAPT report with severity, impact, and remediation recommendations.
• Perform 1 retest after remediation.
Requirements
• 3+ years of hands-on VAPT/Penetration Testing experience.
• Strong knowledge of OWASP Top 10 and API security.
• Experience with manual testing and security reporting.
• Relevant certifications such as OSCP, CEH, eJPT, PNPT are a plus.
Please share relevant experience, certifications, sample/redacted reports, and your hourly/fixed rate.
Fixed budget:
200 USD
5 days ago
IT & Networking, Information Security & Compliance
I need a consultant to guide and audit my product against ISO 17024:2026 requirements. The work includes reviewing current processes, identifying gaps, and providing clear recommendations for improvement. I’m looking for someone with strong experience in certification standards and quality management, preferably based in Singapore. Please share relevant experience and how you would approach this audit.
Founding Principal Engineer — Systems, Security & Agentic Infrastructure
Applied
$5 - $35
/ hr
6 days ago
1
We are seeking a senior, hands-on systems engineer to help build an enterprise security platform for autonomous AI agents. The role spans Linux kernel and eBPF development, network and runtime telemetry, cryptographic chain-of-custody, distributed data pipelines, Kubernetes, cloud infrastructure, and identity-security integrations.
The ideal candidate has strong production experience with Rust, C/C++, or Go, deep knowledge of Linux internals and networking, and the ability to architect secure systems from low-level data collection through a multi-tenant SaaS control plane. Experience with IAM/NHI security, MCP or agent frameworks, applied cryptography, EDR/SIEM integrations, or high-performance security analytics is highly valuable.
This is a principal or founding-engineer position for someone who can own ambiguous technical problems, write critical production code, define the platform’s trust model, and help build the early engineering team. The initial objective is to deliver an end-to-end system that captures autonomous activity, correlates it with human and machine identity, generates independently verifiable evidence, and operates reliably across enterprise environments.
I run a small coaching platform built on Supabase (Postgres backend, React/TypeScript frontend built in Lovable). I've already done an internal security review and I'm looking for an independent specialist to verify my authorization layer and confirm I didn't misunderstand anything. This is a configuration and authorization review, not a penetration test.
Scope (pass/fail verification only):
Row-Level Security policies on all tables — confirm clients can't access each other's data, coaches only reach assigned clients, admin-only actions are locked
SECURITY DEFINER / helper functions — search_path, definer/invoker correctness
Database grants / EXECUTE privileges — confirm no path around RLS
Storage bucket policies (one public-by-design bucket, one private tenant-isolated)
Edge function authorization — callers verified server-side
Supabase Auth settings sanity check
I'll provide a detailed brief listing exactly what to verify and the intended state, the code export, and live database query outputs (or you run the read-only queries yourself — preferred).
Deliverable: a compact PASS / FAIL / NOT VERIFIABLE scorecard against the brief's items, with one or two sentences on any fail. No fixes, no redesign, no recommendations report — just verification. (If you find something and I want it fixed, that's a separate follow-up.)
Must have: strong PostgreSQL + Supabase RLS experience; comfortable reading policies, triggers, and definer functions; able to read TypeScript/Deno edge functions well enough to confirm auth. No frontend work required.
Fixed price: $200–350 depending on experience. Should be roughly 2–4 hours for someone who knows Supabase RLS well. Tell me your rate and rough time estimate when you apply.
To apply, briefly tell me: (1) your experience auditing Supabase RLS specifically, and (2) one common RLS misconfiguration you always check for. (3) When reviewing RLS, how do you confirm what's actually live versus what the migration files say?
Fixed budget:
300 USD
6 days ago
IT & Networking, Information Security & Compliance
Site was migrated from SiteGround to Crazy Domains in July 2026. During the migration, nameservers remained pointed at SiteGround. The site was subsequently compromised and the homepage was replaced with another website. The hosting/DNS issue was corrected and the legitimate site restored. Google Search Console currently reports the homepage as indexed and indexable, but the website has effectively disappeared from Google search results and my Business Profile. No Manual Actions or Security Issues are currently reported. Also, domains that redirected to our main website no longer work.
Security Audit and Code Review for SaaS LMS
Applied
$800
6 days ago
1
Security audit and code review of a production-ready SaaS Learning Management System (LMS) built with Next.js/React, Node.js, and Supabase, before launch. Looking for a developer with application security experience to identify vulnerabilities, bugs, and provide prioritized, actionable fixes.
Client's questions:
Have you worked with SaaS platforms that have multi-tenant access control (i.e., multiple organizations/roles sharing one database)?
What access do you need (read-only GitHub repo, staging environment, etc.), and do you sign NDAs before receiving it?
What's your review methodology — manual code review, automated scanning, or both?
Fixed budget:
800 USD
6 days ago
IT & Networking, Information Security & Compliance
Manual Grey-Box Pentest — Web App + API (OWASP / ASVS L2)
Applied
$3,000
6 days ago
5
Annual authenticated grey-box penetration test of our B2B SaaS web app and APIs. Results must be shareable with our enterprise customers under NDA.
**Scope** (production-identical staging)
- Web app, REST API, WebSocket endpoints. Size: ~28 pages, ~286 APIs, 1 gateway, 2 roles across 2 tenants.
- RBAC and cross-tenant isolation (IDOR).
- AI natural-language-to-SQL feature: prompt injection, SQL injection, data exposure.
- Geocoding integration, file import/export, auth flows (SSO/MFA, password reset, tokens).
- Out of scope: DoS, social engineering, physical.
**Requirements**
- Manual testing (not scanner-only). Standards: OWASP Top 10, OWASP API Top 10, ASVS L2, NIST SP 800dash115.
- Every finding scored CVSS v3.1 with full vector. Lead tester holds OSCP/CREST/GPEN, named in report.
**Deliverables**
1. Technical report: per finding — CVSS + vector, OWASP category, affected URL/param, impact, reproduction with evidence, remediation.
2. Signed executive attestation letter (1–2 pp, your letterhead) — **no clause restricting third-party disclosure** (we share it with customers/prospects under NDA).
3. Retest letter after fixes (also externally shareable).
4. Findings export (CSV/XLSX).
**Timeline & terms**
- Results by **30 August 2026**. Draft report within 5 business days of start; retest letter within 5.
- Retest included in price. NDA before start; no retention of our data.
Client's questions:
Lead tester's certification (OSCP/CREST/GPEN) + verifiable ID/profile link?
Can you deliver a signed attestation letter we can share with customers/prospects under NDA, with no disclosure restriction?
Share a redacted sample report and a sample attestation letter.
Manual vs automated split in your testing?
Experience testing an AI / natural-language-to-SQL feature for injection — briefly?
Fixed budget:
3,000 USD
6 days ago
IT & Networking, Information Security & Compliance
Cybersecurity Expert (Ex-CISO / Security Architect) for Deep Vendor Analysis (Investment-Focused)
Applied
$100
6 days ago
5
Description:
I am looking for a highly experienced cybersecurity professional (NOT a generic financial analyst) to conduct a deep, practical comparison of leading cybersecurity vendors from a real-world deployment and effectiveness perspective.
This is NOT theoretical research. I want insights from someone who has actually worked with or evaluated these tools in enterprise environments.
Scope of Work:
You will help me understand which cybersecurity companies truly have a technical and strategic edge, based on:
* Real-world effectiveness (not marketing claims)
* Product strengths and weaknesses
* Competitive positioning in enterprise environments
* Customer stickiness and switching costs
* Innovation pace and long-term defensibility
* Which vendors are actually preferred by CISOs?
* Which companies are overhyped vs genuinely dominant?
* Where does CrowdStrike truly win or lose?
* Is Microsoft quietly dominating through bundling?
* Which companies have the strongest long-term moat?
* Hands-on experience with multiple vendors listed above
* Experience in enterprise deployments or vendor evaluations
Important:
* No generic AI summaries
* No purely academic responses
* I want blunt, experience-based insights
To Apply:
Please include:
1. Your experience with at least 3 of the vendors listed
2. Example of a deployment or evaluation you were involved in
Client's questions:
Tell me about a time you replaced one security vendor with another (e.g., CrowdStrike vs SentinelOne, or Palo Alto Networks vs Fortinet).
What specifically was failing, what metrics did you use to decide, and what changed after the switch?
Briefly describe ONE real-world cybersecurity tool deployment or evaluation you were involved in (max 5–6 lines).
Focus on what problem you were solving and what decision was made.
In your opinion, which ONE cybersecurity vendor currently has the strongest real-world product advantage, and why? (max 3 lines)
Fixed budget:
100 USD
6 days ago
IT & Networking, Information Security & Compliance
I’m looking for an experienced cybersecurity professional to assist with a confidential account-recovery and security matter involving several online services.
The selected freelancer will receive relevant information privately and will be expected to work only on accounts and systems for which I can provide appropriate authorization. The work may include reviewing account-recovery options, identifying security issues, and helping restore legitimate access through the platforms’ official procedures.
Please apply if you have demonstrated experience in cybersecurity, account security, identity verification, and legitimate account-recovery processes. Strong confidentiality and professional handling of sensitive information are required.
Further project details will be shared privately with the selected freelancer.
Fixed budget:
80 USD
6 days ago
IT & Networking, Information Security & Compliance