Pre-Production Security Audit of Node/React App
Budget: €30 – €250 EUR
We are looking for an experienced Security Engineer / Penetration Tester to perform a pre-production security assessment of a web application.
Tech stack
Backend: Node.js (Express)
Frontend: React
Scope
Black-box penetration testing against the live application
Identification of OWASP Top 10 issues (XSS, SQLi, CSRF, IDOR, auth/session flaws)
Authorization & RBAC testing (horizontal / vertical privilege escalation)
Dependency security review based on provided package.json files
Review of security headers, cookies, and error handling
Access Provided
Application URL(s)
Test user accounts
package.json (frontend & backend)
Deliverables
Security report with findings ranked by severity
Clear remediation recommendations
Re-test after fixes
Requirements
Proven experience securing Node.js and React applications
Familiarity with tools such as Burp Suite, OWASP ZAP, Snyk
Strong understanding of JWT, authentication, and authorization security
Previous penetration testing and SAT experience and reports examples
Tech stack
Backend: Node.js (Express)
Frontend: React
Scope
Black-box penetration testing against the live application
Identification of OWASP Top 10 issues (XSS, SQLi, CSRF, IDOR, auth/session flaws)
Authorization & RBAC testing (horizontal / vertical privilege escalation)
Dependency security review based on provided package.json files
Review of security headers, cookies, and error handling
Access Provided
Application URL(s)
Test user accounts
package.json (frontend & backend)
Deliverables
Security report with findings ranked by severity
Clear remediation recommendations
Re-test after fixes
Requirements
Proven experience securing Node.js and React applications
Familiarity with tools such as Burp Suite, OWASP ZAP, Snyk
Strong understanding of JWT, authentication, and authorization security
Previous penetration testing and SAT experience and reports examples