Build Automated Security Code Review System for ASP.NET & ASP.NET Core Applications

Job ID: 40517777

Budget: $10 – $100 USD

We are looking for an experienced Application Security / DevSecOps Engineer to help us design and implement an automated security code review solution for our applications.

We are not looking for SonarQube setup or configuration.

Instead, we need either:

A custom web application for security scanning, or
Recommendation and customization of an existing platform that meets our requirements.

The system should scan source code repositories, apply custom security rules, and generate findings whenever a rule is violated.

Technology Stack to Support

The solution must support scanning of:

ASP.NET Framework (Classic ASP.NET)
ASP.NET Core
C# source code (.cs)
Razor / CSHTML files (.cshtml)
JavaScript (.js)
CSS files (.css)
Database projects
SQL scripts
Stored Procedures (SPs)
Functions
Views
Project Requirements
Repository Scanning

The solution should:

Scan a Git repository or local source code repository
Analyze all supported file types
Execute custom security rules against the codebase
Generate findings when violations are detected
Provide severity levels (Critical, High, Medium, Low)
Show file name and line number
Display rule description and remediation guidance
Custom Security Rules

The freelancer will be responsible for creating and organizing custom security rules for vulnerabilities such as:

C# / ASP.NET Security
SQL Injection
Command Injection
Path Traversal
Insecure File Uploads
Unsafe Deserialization
Broken Authentication
Authorization Issues
Hardcoded Secrets
Weak Cryptography
Sensitive Data Exposure
Logging of confidential information
Razor / CSHTML Security
Usage of Html.Raw()
Missing anti-forgery protections
Unencoded output
Unsafe rendering patterns
Insecure forms
JavaScript Security
DOM XSS
Unsafe innerHTML
Use of eval()
Insecure client-side storage
Dangerous third-party libraries
Database Security
Dynamic SQL construction
Missing parameterized queries
Dangerous stored procedure patterns
Privilege escalation risks
Rule Engine Requirements

The custom rule system should:

Be extensible
Allow adding new rules in the future
Support versioning of rules
Enable/disable specific rules
Categorize rules by severity and technology
Scan Results Dashboard

The solution should provide:

Scan history
Findings dashboard
Filtering and searching
Export to PDF/Excel
Summary reports
CI/CD Integration (Optional)

Support integration with:

GitHub Actions
Azure DevOps
Jenkins
Deliverables
Working scanning solution or customized platform
Custom security rule library
Documentation
Setup guide
Knowledge transfer session
Sample scans and reports
Important Note

We are specifically looking for someone with hands-on experience in:

Application Security (AppSec)
Static Application Security Testing (SAST)
ASP.NET / ASP.NET Core security
Custom rule development
Security scanning engines (Semgrep or similar)

We are NOT looking for SonarQube setup services.