Cloud App Pen Test Needed

Job ID: 40317556

Budget: $2 – $8 USD

We are looking for an experienced penetration tester/application security expert to perform a security assessment of our cloud-based web application.

Our application stack includes:

Backend: .NET Core
Database: Azure SQL
Frontend: ReactJS
Hosting Environment: Microsoft Azure

The goal is to identify security vulnerabilities, misconfigurations, and potential risks across the application, APIs, database access, authentication flow, and Azure environment.

Scope of Work:

Perform penetration testing on the web application
Test frontend and backend security
Review API security and authentication/authorization controls
Check for common vulnerabilities such as:
SQL Injection
Cross-Site Scripting (XSS)
Cross-Site Request Forgery (CSRF)
Broken Authentication / Session Management
Insecure Direct Object References (IDOR)
Privilege Escalation
Security misconfigurations
Sensitive data exposure
OWASP Top 10 issues
Review Azure-related security risks and configuration weaknesses
Validate input handling, file upload security, API endpoints, and user role access
Provide a detailed report with:
Vulnerabilities found
Severity level
Steps to reproduce
Screenshots / proof of concept where applicable
Recommendations for remediation

Deliverables:

Detailed penetration testing report
Executive summary of key risks
Technical remediation recommendations
Optional re-test after fixes are applied

Required Experience:

Proven experience in web application penetration testing
Strong knowledge of .NET Core, ReactJS, and Azure environments
Experience with Azure SQL security testing
Good understanding of OWASP Top 10
Ability to provide professional and actionable security reports

Preferred:

Relevant cybersecurity certifications such as OSCP, CEH, GPEN, or similar
Experience testing SaaS / cloud-hosted business applications
Experience with authenticated and role-based application testing