Manual penetration test: multi-tenant authorization and access control (Laravel healthcare SaaS)

Posted 3 hours ago

Worldwide

Summary

I need a focused manual penetration test of a multi-tenant healthcare web application before a September launch. This is a targeted authorization-focused engagement, not a full-scope test. I am not looking for automated scanner output. About the application Server-rendered Laravel (PHP-FPM) on AWS: CloudFront and WAF, Application Load Balancer, ECS Fargate, RDS MariaDB, S3. No separate REST API. Roughly [X] web routes. It is a B2B SaaS platform for medical practices. Each practice is a tenant. Every patient record, note, appointment, and invoice belongs to exactly one practice, and no practice should ever see another practice's data. There are seven user roles: patient, provider, medical assistant, practice manager, billing, marketing, and admin. What I need tested, in priority order Tenant isolation. Can a user authenticated at Practice A reach any data belonging to Practice B by manipulating IDs in URLs, form parameters, or requests? Broken object level authorization within a tenant. Can a patient reach another patient's records? Can a lower-privileged role reach records they should not? Role boundary enforcement across all seven roles, including whether restrictions are enforced server-side or only hidden in the UI. Authentication and session management: login, MFA, session handling, password reset, account enumeration. File upload handling. The app accepts CSV and XLSX imports. Please test for formula injection, path traversal, malicious file content, and parser abuse. Webhook endpoints. Signature verification on inbound webhooks from payment and third-party services. Environment and access Grey box, fully authenticated. I will provide credentials for two separate test practices and for every role, against a staging environment configured like production. Staging contains synthetic test data only. No real patient data will be present at any point. Deliverables required Findings report with severity ratings (CVSS), reproduction steps, and request and response evidence for each finding Remediation guidance my developer can act on One round of retesting after fixes, included A short call or written summary walking me through the findings Timeline Code freeze is August 25. Testing can begin August 26. I need findings by roughly September 1 so there is time to remediate and retest before launch. Requirements OSCP, OSWE, or equivalent hands-on certification Demonstrated manual testing of multi-tenant SaaS authorization, not scanner-based assessments Willing to sign an NDA Please include a sanitized sample report or a description of what your report contains In your proposal, please answer: how do you test tenant isolation specifically, and what do you need from me to do it well?

  • Less than 30 hrs/week
    Hourly
  • 1-3 months
    Duration
  • Expert
    Experience Level
  • $60.00

    -

    $110.00

    Hourly
  • Remote Job
  • Ongoing project
    Project Type
Skills and Expertise
Mandatory skills
Penetration Testing
Vulnerability Assessment
Activity on this job
  • Proposals:15 to 20
  • Last viewed by client:2 hours ago
  • Interviewing:
    0
  • Invites sent:
    0
  • Unanswered invites:
    0
About the client
Member since Apr 13, 2021
  • United States
    New York7:07 PM
  • $2K total spent
    11 hires, 3 active
  • 42 hours
  • Mid-sized company (10-99 people)

Explore similar jobs on Upwork

DMO Audit EngagementHourly‐ Posted 2 months ago
Cybersecurity Management
Business Analysis
Information Technology
Governance, Risk Management & Compliance
Financial Audit
GDPR
Data Privacy
Risk Assessment
NIST SP 800-53
ISO 27001
Product Strategy
Digital Transformation
Secure SDLC
Program Management
AI Governance
ISO 9001
Change Management
IT Compliance Audit
Incident Management
Artificial Intelligence
Lead Generation
Internet Marketing
Cloud Computing
Cloud Security Framework
Network Security
Solution Architecture
Security Infrastructure
Application Security
Security Engineering

How it works

  • Post a job icon
    Create your free profile
    Highlight your skills and experience, show your portfolio, and set your ideal pay rate.
  • Talent comes to you icon
    Work the way you want
    Apply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
  • Payment simplified icon
    Get paid securely
    From contract to payment, we help you work safely and get paid securely.
Want to get started? Create a profile

About Upwork

  • Rating is 4.9 out of 5.
    4.9/5
    (Average rating of clients by professionals)
  • G2 2021
    #1 freelance platform
  • 49,000+
    Signed contract every week
  • $2.3B
    Freelancers earned on Upwork in 2020

Find the best freelance jobs

Growing your career is as easy as creating a free profile and finding work like this that fits your skills.

Trusted by

  • Microsoft Logo
  • Airbnb Logo
  • Bissell Logo
  • GoDaddy Logo