App & Cloud Security Consultant
Budget: ₹750 – ₹1,250 INR
I need an experienced security engineer to harden our multi-tenant SaaS product, prepare us for HIPAA and SOC 2 Type II audits, and stay on call for incident response. The stack runs primarily on AWS, Azure or GCP, with containerised workloads orchestrated by Kubernetes. Day-to-day you will probe our web apps and APIs with Burp Suite and OWASP ZAP, script automation in Bash, and guide the team as we fold security controls into an established Git-based CI/CD pipeline.
Key objectives
• Run a full penetration test against the platform, documenting exploitable findings against the OWASP Top 10 and cloud-specific misconfigurations.
• Configure vulnerability scanning (Nessus, Snyk, Trivy) and wire SAST, DAST and dependency checks into our build pipelines.
• Implement and verify HIPAA technical safeguards—AES-256 encryption in transit and at rest, granular IAM, audit logging, MFA and alerting.
• Assemble evidence for our upcoming SOC 2 Type II assessment and coach engineers on policy alignment.
• Advise on secure architecture patterns for a multi-tenant AWS/Azure deployment, with special attention to container and Kubernetes hardening.
• Establish monitoring and an incident-response runbook the on-call team can follow.
Acceptance criteria
– A written penetration-testing report with reproducible steps and severity scoring.
– Passing vulnerability scans integrated into CI/CD gates.
– HIPAA safeguard checklist signed off by both sides.
– Complete SOC 2 evidence folder mapped to controls.
– Playbooks and diagrams covering secure architecture and IR workflow.
Preferred profile
OSCP, CEH or CISSP certified; proven record with HIPAA or SOC 2 environments; deep familiarity with AWS and Azure security services; expert user of Burp Suite, OWASP ZAP and container security tooling; strong Bash automation skills.
I’m ready to start as soon as we agree on milestones and timelines. If this fits your expertise, let’s secure the platform together.
Key objectives
• Run a full penetration test against the platform, documenting exploitable findings against the OWASP Top 10 and cloud-specific misconfigurations.
• Configure vulnerability scanning (Nessus, Snyk, Trivy) and wire SAST, DAST and dependency checks into our build pipelines.
• Implement and verify HIPAA technical safeguards—AES-256 encryption in transit and at rest, granular IAM, audit logging, MFA and alerting.
• Assemble evidence for our upcoming SOC 2 Type II assessment and coach engineers on policy alignment.
• Advise on secure architecture patterns for a multi-tenant AWS/Azure deployment, with special attention to container and Kubernetes hardening.
• Establish monitoring and an incident-response runbook the on-call team can follow.
Acceptance criteria
– A written penetration-testing report with reproducible steps and severity scoring.
– Passing vulnerability scans integrated into CI/CD gates.
– HIPAA safeguard checklist signed off by both sides.
– Complete SOC 2 evidence folder mapped to controls.
– Playbooks and diagrams covering secure architecture and IR workflow.
Preferred profile
OSCP, CEH or CISSP certified; proven record with HIPAA or SOC 2 environments; deep familiarity with AWS and Azure security services; expert user of Burp Suite, OWASP ZAP and container security tooling; strong Bash automation skills.
I’m ready to start as soon as we agree on milestones and timelines. If this fits your expertise, let’s secure the platform together.