Web App Phishing Analysis

Job ID: 40356117

Budget: $250 – $750 USD

I need a seasoned cybersecurity professional to perform a focused threat-analysis of the phishing risks facing our public-facing web applications. The goal is to understand how attackers might spoof pages, harvest credentials, or abuse session-handling logic, and then lay out clear, prioritised counter-measures I can hand straight to my dev team.

Scope
• Map the current web-app attack surface, including login, forgotten-password and payment flows.
• Identify realistic phishing scenarios (brand impersonation, rogue sub-domains, look-alike URLs, etc.).
• Analyse existing controls such as SPF/DKIM/DMARC on transactional emails that originate from the app, inline content-security policies, and user-journey signage.
• Produce an evidence-based risk rating for each scenario and recommend practical mitigations—security headers, 2FA enforcement points, anti-phishing landing pages, browser-side protections and user-awareness hooks.

Deliverables
1. Threat-model report (PDF) with diagrams, exploited paths and likelihood/impact scores.
2. Remediation checklist mapped to OWASP, NIST SP 800-63 and CIS controls.
3. 30-minute walkthrough call to clarify findings with my engineers.

Acceptance criteria
• All findings reproducible on latest production build.
• Recommendations ranked by high, medium, low effort and cost.
• Executive summary understandable by non-technical leadership.

Primary focus is web apps, but if time permits we can optionally discuss extending the same methodology to email systems and internal comms in a follow-on phase.

Tools you’re free to leverage include Burp Suite, OWASP ZAP, phishing-simulation platforms, or any custom scripts, as long as you respect our agreed testing window and provide full proof-of-concept details.

I’m ready to supply architecture docs and a staging URL once we kick off. Let me know your preferred start date and any artefacts you need up front.