SaaS App Black-Box Penetration Test

Job ID: 40259142

Budget: $30 – $250 USD

This will be our very first security assessment, so I need a seasoned ethical hacker to perform a full black-box penetration test against our live SaaS platform. Because you will have no prior access or code knowledge, I expect the engagement to mirror a real-world external attack and surface anything an outsider could exploit.

Scope
Although I have not isolated individual modules yet, the test should naturally cover the usual high-risk surfaces—login and session handling, role-based access, data storage endpoints, and every API exposed to the public internet. Please probe for vulnerabilities in line with OWASP Top 10 using tooling such as Burp Suite, OWASP ZAP, Nmap, or your preferred equivalents, followed by thorough manual verification.

Deliverables
• A written report that ranks each finding by severity, explains the technical root cause, and provides clear remediation advice
• Proof-of-concept screenshots or request/response logs for any critical issues
• A retest plan so we can verify fixes on the same environment

Acceptance Criteria
• All unauthenticated and authenticated routes are tested from an external vantage point
• No high or critical vulnerability remains unreported or unexplained
• The final report is reproducible by my development team without special licenses beyond community editions

I can grant you a dedicated test account and will standby to whitelist your IP range once we agree on timings.