Penetration Tester for Online Sports Betting Platform
Worldwide
We are seeking an experienced cybersecurity professional to perform an independent penetration test of our online sports betting platform before production launch. This is a one-time security assessment focused on identifying vulnerabilities that could impact customer accounts, financial transactions, data privacy, or platform integrity. Experience with sportsbook, gaming, fintech, banking, or payment applications is highly desirable. About the Platform The platform includes: • User authentication • Wallet management • Deposits and withdrawals • Betting engine • Live betting • Promotions • Administrative interfaces • APIs • Real-time services • Sports content platform integrated with the betting platform Technology includes: • Go backend • Nuxt.js frontend • MySQL • ClickHouse • GitHub • MQTT over WebSockets • NATS JetStream • Kubernetes deployment • TLS encryption • Containerized microservices Scope of Work Perform a professional penetration test covering: Authentication • Login • Registration • Password reset • Session management • Multi-session behavior • Privilege escalation Authorization • Broken access control • Horizontal privilege escalation • Vertical privilege escalation • Administrative access API Security • Authentication • Authorization • Input validation • Rate limiting • Business logic flaws • Injection attacks Web Application Security • OWASP Top 10 • XSS • CSRF • SQL Injection • Command Injection • SSRF • File upload vulnerabilities • Directory traversal Wallet Security • Deposit manipulation • Withdrawal manipulation • Double spending • Race conditions • Balance inconsistencies Betting Security • Odds manipulation • Duplicate bet placement • Settlement manipulation • Replay attacks • Business logic abuse Infrastructure Review Where access is provided: • Kubernetes configuration • TLS implementation • Public endpoints • Security headers • Secrets exposure • Container security Additional Testing • Rate limiting • Bot protection • Denial-of-service resilience • Session timeout • Cookie security • Sensitive information disclosure Deliverables The final report should include: • Executive summary • Technical findings • Risk ratings using CVSS where appropriate • Proof of concept for each finding • Screenshots • Reproduction steps • Business impact • Recommended remediation • Re-test guidance Critical findings should be reported immediately rather than waiting until the end of the engagement. Preferred Qualifications • OSCP, OSWE, GPEN, CEH, CREST, or similar certification • Experience testing sportsbooks • Experience testing payment platforms • Experience with Kubernetes • Experience with APIs • Experience performing OWASP assessments • Strong written reporting skills Proposal Requirements Please provide: • Relevant penetration testing experience • Security certifications • Sample redacted penetration test report • Estimated project timeline • Fixed-price proposal • Availability to begin immediately
$500.00
Fixed-price- IntermediateExperience Level
- Remote Job
- One-time projectProject Type
Skills and Expertise
Activity on this job
- Proposals:20 to 50
- Interviewing:0
- Invites sent:0
- Unanswered invites:0
About the client
- USANorth East 11:13 PM
- $989 total spent7 hires, 1 active
- 177 hours
- Sales & MarketingSmall company (2-9 people)
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by