In-Depth Security Audit for Digital Marketplace

Job ID: 39554060

Budget: $30 – $250 CAD

We are seeking a skilled Cybersecurity Expert and Web Application Penetration Tester to conduct an in-depth security audit and vulnerability assessment of our publicly accessible web application. As we approach the final phase of development before going live to production, your role will be crucial in identifying and reporting any exploitable vulnerabilities, security misconfigurations, design flaws, or weaknesses that could compromise user data or platform integrity. You will simulate real-world attacks to evaluate the security posture of the application and provide a detailed report with practical recommendations for mitigation and remediation.


Key Responsibilities:

1- Perform manual and automated penetration testing on the full web application stack, including frontend, backend, and APIs.

2- Identify critical vulnerabilities such as injection flaws, authentication/authorization issues, broken access controls, misconfigured servers, insecure session management, business logic flaws, and data exposure.

3- Conduct design-level threat modeling to uncover architectural or logic-level weaknesses.

4- Simulate attacks such as:
a)Cross-Site Scripting (XSS)
b) SQL Injection
c) Cross-Site Request Forgery (CSRF)
d) Session Hijacking
e) Broken Object-Level Authorization
f) Insecure Direct Object References (IDOR)

5) Test for OWASP Top 10 and other industry-standard security risks.

6) Assess application behavior under different permission levels (unauthenticated, authenticated, admin).

7) Analyze the security of third-party integrations, authentication flows (e.g., OAuth2, SSO), and data handling practices.

8) Provide a detailed report documenting all findings, risk levels, reproduction steps, impact, and prioritized remediation recommendations.

9) Participate in follow-up meetings to discuss findings and collaborate with the dev team on fixes or re-testing.


Required Skills and Qualifications:

- Proven experience in web application penetration testing and ethical hacking.
- Deep understanding of web technologies (HTML, JavaScript, REST APIs, authentication protocols, etc.).
- Familiarity with modern frameworks (React, Node.js, Laravel, Django, etc.).
- Experience with tools such as: Burp Suite (Pro preferred), OWASP ZAP, Nikto, Nmap, Metasploit, sqlmap, etc.
- Strong knowledge of OWASP Top 10, SANS CWE Top 25, and other security frameworks.
- Ability to create professional, executive-ready reports with both technical and non-technical summaries.
- Relevant certifications (preferred but not required): OSCP, CEH, GWAPT, CISSP, GPEN, etc.


Deliverables:

1- Comprehensive security audit report (PDF and/or Markdown)
2- List of vulnerabilities with CVSS scores, risk levels, PoCs, and recommended fixes
3- Livd demo over video conference replicating some of the attacks, vulnerabilities and flaws.