Urgent Security Hardening: DevOps/Security Engineer Needed

Job ID: 40105978

Budget: ₹1,500 – ₹12,500 INR

DevOps / Security Engineer Required – Short-Term Security Hardening Task

We are looking for an experienced DevOps / Security Engineer to assist with targeted security hardening based on findings from a recent vulnerability assessment.

This is a short-duration project (1–2 days) focused strictly on server-level remediation. Application logic and feature development are out of scope.

Project Scope (Only These 3 Items)
1. Server Version Disclosure – Low Severity

Issue:
Server version details are exposed in HTTP responses.

Expected Fix:
• Hide server version information from headers
• Configure web server to suppress version disclosure
• Validate using standard security scanning tools

2. SSL Pinning Bypass Protection Missing – High Severity

Issue:
The application does not currently enforce SSL pinning protection, making it susceptible to interception attacks.

Expected Fix:
• Implement server-side support for SSL pinning enforcement
• Strengthen TLS configuration to prevent downgrade or bypass scenarios
• Ensure compatibility with secure client-side pinning mechanisms

3. Port 22 (SSH) Exposed on Admin/Dashboard Server – Medium Severity

Issue:
SSH access is publicly accessible on the admin/dashboard environment.

Expected Fix:
• Restrict SSH access using IP whitelisting or VPN
• Harden SSH configuration (authentication, port access, fail2ban if required)
• Ensure only authorized access paths remain open

Deliverables

• Hardened server configuration for all three findings
• Verification that vulnerabilities are no longer detectable
• Brief documentation of changes made
• Readiness for security retest

Required Skills

• Linux server administration (Ubuntu/CentOS)
• Web server security (Nginx or Apache)
• SSL/TLS configuration and hardening
• SSH access control and server security best practices
• Understanding of vulnerability assessment and remediation

Engagement Details

• Duration: 1–2 days
• Mode: Remote
• Access: Limited server access will be provided as required
• Confidentiality: NDA required
• Start: Immediate