Independent penetration test with remediation retest, report for enterprise vendor risk review

Posted last week

Only freelancers located in the U.S. may apply.U.S. located freelancers only

Summary

Type: Fixed price We need an independent penetration test of a small production environment. The report will be submitted to enterprise third-party risk teams, so report quality and the retest matter as much as the testing itself. Scope: One public IP on AWS External network testing on that host Authenticated grey-box testing of the web application and its API. We provide credentials for each role, architecture documentation and an asset inventory so you are not billing for reconnaissance Out of scope: internal network, social engineering, source code review, cloud configuration review This is a deliberately small scope. We are buying manual application testing depth, not IP count. Please quote tester-days rather than pricing it as a trivial job. Required in the base price: Draft report review window, with our written management response included in the final report Remediation retest after we fix findings, with a written retest confirmation stating which findings are closed Both the full technical report and a standalone executive summary suitable for a third-party risk file Report to state scope, methodology, test window, tester certification, findings with severity ratings and evidence, and remediation guidance. We expect OWASP or PTES methodology, or equivalent recognised guidance Timeline: engagement this week, testing the following week, initial report within two weeks of engagement, retest within one week of us confirming remediation. Please say so upfront if that is not achievable. Required: OSCP, CREST or GPEN certified tester performing the work Prior reports accepted by large enterprise or Big Four vendor risk assessments Professional liability or errors and omissions cover, or the ability to explain how you handle that Please attach a redacted sample report and a redacted sample retest letter. Proposals without a sample report will not be considered.

  • Less than 30 hrs/week
    Hourly
  • < 1 month
    Duration
  • Intermediate
    Experience Level
  • Remote Job
  • One-time project
    Project Type

Contract-to-hire opportunity

This lets talent know that this job could become full time.
Learn more
Skills and Expertise
Mandatory skills
Vulnerability Assessment
Activity on this job
  • Proposals:Less than 5
  • Last viewed by client:3 days ago
  • Interviewing:
    2
  • Invites sent:
    0
  • Unanswered invites:
    0
About the client
Member since Aug 8, 2026
  • United States
    5:08 PM

Explore similar jobs on Upwork

Penetration Testing NeededHourly‐ Posted 3 weeks ago
Penetration Testing
Vulnerability Assessment
Information Security
Network Security
Ethical Hacking
Senior Physical Security ConsultantHourly‐ Renewed 1 month ago
ISO 27001
Vulnerability Assessment
Network Security

How it works

  • Post a job icon
    Create your free profile
    Highlight your skills and experience, show your portfolio, and set your ideal pay rate.
  • Talent comes to you icon
    Work the way you want
    Apply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
  • Payment simplified icon
    Get paid securely
    From contract to payment, we help you work safely and get paid securely.
Want to get started? Create a profile

About Upwork

  • Rating is 4.9 out of 5.
    4.9/5
    (Average rating of clients by professionals)
  • G2 2021
    #1 freelance platform
  • 49,000+
    Signed contract every week
  • $2.3B
    Freelancers earned on Upwork in 2020

Find the best freelance jobs

Growing your career is as easy as creating a free profile and finding work like this that fits your skills.

Trusted by

  • Microsoft Logo
  • Airbnb Logo
  • Bissell Logo
  • GoDaddy Logo