Full Web App Security Audit

Job ID: 40176480

Budget: ₹1,250 – ₹2,500 INR

I’m ready to bring in an experienced ethical hacker to run a thorough security audit of our production web application. You’ll have gray-box access—enough credentials and limited architecture notes to work efficiently, but not full source code.

Key focus areas are clear:
• Robustness of user authentication and authorization flows
• Protection of data at rest and in transit
• Security posture of every third-party integration we rely on

I expect a blend of manual and automated testing (Kali Linux, Burp Suite, OWASP ZAP or similar) aimed at uncovering the full OWASP Top 10 spectrum. A secure-configuration review of servers, middleware, and relevant cloud services should run in parallel. Where you discover a critical issue, please include an exploit proof-of-concept so we can replicate and validate the risk internally.

Deliverables, all compiled in a single engagement report:
1. Executive summary highlighting overall risk level
2. Detailed vulnerability list with CVSS scores, affected endpoints, and reproducible steps
3. Screenshots or PoCs for confirmed high-impact findings
4. Concrete, prioritized remediation recommendations

The audit is strictly for lawful, ethical purposes and will be covered by a mutual NDA. I’m available to answer environment questions and schedule test windows to avoid production disruption. Let’s lock down this app.