Security Penetration Test + Code Review — AWS Serverless SaaS (Node/TypeScript, React)

Posted 2 weeks ago

Worldwide

Summary

We're a UK-based logistics software company (strong Upwork history) looking to establish a long-term relationship with a security specialist for our growing SaaS platform. We're shortlisting now, with the first engagement planned within the next few months - ahead of onboarding larger customers. The first project will be a full security audit of the platform: Penetration test of our development environment (web app + API) - authentication, authorization, and especially multi-tenant data isolation Application security code review (read-only access, OWASP ASVS-aligned) AWS configuration review (IAM, network exposure, S3, Cognito, RDS) A written report with severity-rated findings, remediation guidance, and a retest after we apply fixes The platform: multi-tenant B2B SaaS - React + TypeScript frontend, AWS serverless backend (~80 Lambda functions, Node.js/TypeScript), API Gateway + Cognito, PostgreSQL, S3, third-party and AI integrations. Clean, conventional, well-documented codebase (~300 source files). Beyond the first audit, we expect recurring work as the platform grows: periodic retests, security review of new features, and advisory input on our AWS setup — so we're looking for someone interested in being our security person, not a one-time scan. Logistics: NDA and authorization-to-test letter signed before any access; testing against our dev environment only (no production access, no customer data); all access read-only and time-boxed. In your proposal, please tell us: your experience with AWS serverless and multi-tenant SaaS, relevant certifications if any (OSCP/OSWE/AWS Security Specialty), a redacted sample report from a similar engagement, and an indicative fixed price for the first audit (including the retest). No immediate start required - we're selecting the right person first.

  • Less than 30 hrs/week
    Hourly
  • < 1 month
    Duration
  • Intermediate
    Experience Level
  • Remote Job
  • One-time project
    Project Type
Skills and Expertise
Mandatory skills
Penetration Testing
Vulnerability Assessment
Activity on this job
  • Proposals:20 to 50
  • Interviewing:
    0
  • Invites sent:
    0
  • Unanswered invites:
    0
About the client
Member since Jun 16, 2020
  • United Kingdom
    London5:35 AM
  • $48K total spent
    7 hires, 0 active
  • 4,707 hours
  • Supply Chain & Logistics
    Small company (2-9 people)

Explore similar jobs on Upwork

Kali Linux
Penetration Testing
Application Security
Ethical Hacking
Getting an account backHourly‐ Posted 4 weeks ago
Security Assessment & Testing
Vulnerability Assessment
Kali Linux
Application Security
Penetration Testing
Network Security
Security Infrastructure
Manual Testing
Ethical Hacking
OWASP
Windows Server
NIST SP 800-53
Internet Security
Web Application Security
Security Engineering

How it works

  • Post a job icon
    Create your free profile
    Highlight your skills and experience, show your portfolio, and set your ideal pay rate.
  • Talent comes to you icon
    Work the way you want
    Apply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
  • Payment simplified icon
    Get paid securely
    From contract to payment, we help you work safely and get paid securely.
Want to get started? Create a profile

About Upwork

  • Rating is 4.9 out of 5.
    4.9/5
    (Average rating of clients by professionals)
  • G2 2021
    #1 freelance platform
  • 49,000+
    Signed contract every week
  • $2.3B
    Freelancers earned on Upwork in 2020

Find the best freelance jobs

Growing your career is as easy as creating a free profile and finding work like this that fits your skills.

Trusted by

  • Microsoft Logo
  • Airbnb Logo
  • Bissell Logo
  • GoDaddy Logo