Cybersecurity Penetration Test for Food Delivery Platform
Budget: $750 – $1,500 USD
We are seeking a seasoned cybersecurity expert to conduct a comprehensive end-to-end audit of a food delivery platform (including backend, frontend, APIs, mobile apps, admin panels, and payment flows). The goal is to identify and patch all security vulnerabilities—from infrastructure and logic flaws to external threats like DDoS or payment manipulation.
Scope of Work:
Review all codebases (Laravel, React Native, etc.) for security issues
Audit authentication, authorization, and session management flows
Test for SQL injection, XSS, CSRF, insecure direct object references, etc.
Simulate payment fraud attempts (e.g. exploiting race conditions, fake transactions)
Test for logic flaws in wallet/refund/reward/credit systems
Run penetration tests against APIs and endpoints
Evaluate AWS setup (IAM roles, S3 buckets, CloudFront, etc.)
Test mobile apps for security flaws (jailbreak/root detection, data storage, API security)
Simulate DDoS scenarios and review rate-limiting mechanisms
Provide a full report with identified vulnerabilities, severity, and remediation steps
Retest once patches are applied
Requirements:
Proven track record in offensive security / penetration testing
Experience with Laravel and React Native ecosystems
Familiarity with payment systems and fraud vectors
Solid understanding of OWASP Top 10 and beyond
Experience with AWS infrastructure security
Able to write clear, concise technical reports and explain findings
Bonus: Experience with mobile app reverse engineering
Certification Must-Have? Focus Area
ISO/IEC 27001 ✅ Yes InfoSec management
ISO/IEC 27017 ✅ Yes Cloud-specific security
ISO/IEC 27018 ✅ Yes PII protection
ISO 22301 ✅ Yes Business continuity
Scope of Work:
Review all codebases (Laravel, React Native, etc.) for security issues
Audit authentication, authorization, and session management flows
Test for SQL injection, XSS, CSRF, insecure direct object references, etc.
Simulate payment fraud attempts (e.g. exploiting race conditions, fake transactions)
Test for logic flaws in wallet/refund/reward/credit systems
Run penetration tests against APIs and endpoints
Evaluate AWS setup (IAM roles, S3 buckets, CloudFront, etc.)
Test mobile apps for security flaws (jailbreak/root detection, data storage, API security)
Simulate DDoS scenarios and review rate-limiting mechanisms
Provide a full report with identified vulnerabilities, severity, and remediation steps
Retest once patches are applied
Requirements:
Proven track record in offensive security / penetration testing
Experience with Laravel and React Native ecosystems
Familiarity with payment systems and fraud vectors
Solid understanding of OWASP Top 10 and beyond
Experience with AWS infrastructure security
Able to write clear, concise technical reports and explain findings
Bonus: Experience with mobile app reverse engineering
Certification Must-Have? Focus Area
ISO/IEC 27001 ✅ Yes InfoSec management
ISO/IEC 27017 ✅ Yes Cloud-specific security
ISO/IEC 27018 ✅ Yes PII protection
ISO 22301 ✅ Yes Business continuity