Penetration Test on Corporate Email System
Budget: $250 – $750 USD
We are a small firm, mid-sized business seeking an experienced and certified Penetration Tester (Ethical Hacker) to conduct a comprehensive Vulnerability Assessment and Penetration Test (VAPT) on our corporate email system.
The primary goal is to proactively identify security weaknesses, misconfigurations, and potential attack vectors before they can be exploited by malicious actors.
Scope of Work (Deliverables)
The hired professional will perform an authorized and controlled penetration test focused on, but not limited to, the following assets:
Email Infrastructure/Platform
External Mail Flow Security: Testing public-facing records like SPF, DKIM, and DMARC configuration for robustness against spoofing.
Authentication and Account Security: Testing for weaknesses in user sign-in processes, password policies, Multi-Factor Authentication (MFA) bypasses, and unauthorized access from external endpoints.
Configuration Review: Reviewing the admin-level security configurations (e.g., mail flow rules, security policies, data loss prevention (DLP) settings) for any misconfigurations that could expose data.
Simulated Attack Vectors: Attempts to compromise email accounts or services via techniques such as:
External Network Scanning of public-facing mail services (if applicable).
Credential Stuffing simulation (using sample non-live data).
Minimum [3-5]+ years of dedicated professional penetration testing experience.
Hold at least one of the following industry-recognized, hands-on certifications: OSCP, GPEN, C|PENT, or CREST Registered Tester.
Demonstrable experience performing security assessments on modern cloud email platforms (M365/Google Workspace) or self-hosted mail servers.
Deliverables
The successful candidate will provide the following:
Final Comprehensive Report: A professionally written report detailing the testing methodology, scope, findings, and overall risk rating.
Prioritized Vulnerability List: A list of all identified vulnerabilities ranked by severity (e.g., Critical, High, Medium, Low) and their potential business impact.
Actionable Remediation Advice: Clear, technical, and non-technical recommendations for fixing each identified vulnerability.
The primary goal is to proactively identify security weaknesses, misconfigurations, and potential attack vectors before they can be exploited by malicious actors.
Scope of Work (Deliverables)
The hired professional will perform an authorized and controlled penetration test focused on, but not limited to, the following assets:
Email Infrastructure/Platform
External Mail Flow Security: Testing public-facing records like SPF, DKIM, and DMARC configuration for robustness against spoofing.
Authentication and Account Security: Testing for weaknesses in user sign-in processes, password policies, Multi-Factor Authentication (MFA) bypasses, and unauthorized access from external endpoints.
Configuration Review: Reviewing the admin-level security configurations (e.g., mail flow rules, security policies, data loss prevention (DLP) settings) for any misconfigurations that could expose data.
Simulated Attack Vectors: Attempts to compromise email accounts or services via techniques such as:
External Network Scanning of public-facing mail services (if applicable).
Credential Stuffing simulation (using sample non-live data).
Minimum [3-5]+ years of dedicated professional penetration testing experience.
Hold at least one of the following industry-recognized, hands-on certifications: OSCP, GPEN, C|PENT, or CREST Registered Tester.
Demonstrable experience performing security assessments on modern cloud email platforms (M365/Google Workspace) or self-hosted mail servers.
Deliverables
The successful candidate will provide the following:
Final Comprehensive Report: A professionally written report detailing the testing methodology, scope, findings, and overall risk rating.
Prioritized Vulnerability List: A list of all identified vulnerabilities ranked by severity (e.g., Critical, High, Medium, Low) and their potential business impact.
Actionable Remediation Advice: Clear, technical, and non-technical recommendations for fixing each identified vulnerability.