Web App, API & CircleCI CI/CD Security and Penetration Testing Project

Job ID: 37469164

Budget: $1,500 – $3,000 AUD

Web App, API & CircleCI CI/CD Security and Penetration Testing Project

I am looking for an experienced and skilled security professional to conduct penetration penetration and security testing on my web app, API, and CircleCI CI/CD system. The goal is to identify any vulnerabilities and strengthen the security measures in place.

Specific Security Features to Test:
- Testing will be against the external side of a single web app
- There are two API's that are integral to the app that must be tested
- The application has a mobile app that is compiled and deployed to app stores via the CircleCI CI/CD tool, this process must also be included.

Existing Security Measures:
- Yes, we currently have security measures in place
- External WAF and CloudFront will disabled for the remote IP address of the Pen Tester


Timeline:
Testing must be completed before the end of December

Ideal Skills and Experience:
- Strong knowledge and experience in penetration testing domain
- High level of expertise and experience with web app security, API security, and CI/CD systems
- Experience testing Cloud Native Web Applications and Systems
- High level of Proficiency in identifying and exploiting vulnerabilities and recording evidence for reports
- Access to and a high level of proficiency with Burpsuite Pro, Nessus Professional and other commercial testing tools
- Access to and a high level of proficiency with common Open Source Penetration
- Ability to provide automated/scripted re-testing post-remediation work to provide a like-for-like re-test
- Demonstratable Experience with PTES or similar
- Ability to provide a thorough and professional report of the engagement, including an Executive summary
- Ability to analyse the testing results and make recommendations for improving security measures
- Ability to analyse the testing results and provide a risk classification

Penetration testing must include but not be limited to the scope of the OWASP WSTG - v4.2

To conduct thorough penetration testing within the given timeframe (5 Day Estimate), please submit your proposal and any questions.