Supabase / PostgreSQL Security Engineer Needed for Pre-Launch App Audit

Posted 2 days ago

Worldwide

Summary

I’m looking for an experienced application security engineer / penetration tester to perform an independent pre-launch security review of SAFO, a community and social platform currently approaching public launch. The application is already built and functional. I am NOT looking for someone to build the application from scratch. I need an independent technical review of the existing system before launch. TECH STACK The application uses: - Supabase - PostgreSQL - Row Level Security (RLS) - Supabase Auth - Supabase Storage - server-side functions / RPCs - modern web application frontend - AI-assisted development tools, including Lovable The application contains multiple permission levels and privacy-sensitive functionality, so authorization and data isolation are particularly important. SCOPE OF THE SECURITY REVIEW I would like the review to include, where applicable: - Supabase RLS policies - PostgreSQL permissions and grants - authentication and authorization - horizontal privilege escalation / IDOR - cross-user data isolation - role and privilege escalation - API security - Supabase Storage permissions - private files and signed URL access - RPC/database functions - SECURITY DEFINER functions and views - sensitive-data exposure - location/privacy controls - messaging and user-generated content access - admin/moderator/partner permission boundaries - common OWASP web application vulnerabilities - basic client-side security review - secrets/API-key exposure - abuse cases that automated scanners may miss Manual testing is important. I am specifically NOT looking for someone who will simply run an automated vulnerability scanner and send me its output. TESTING APPROACH Ideally, you should be comfortable testing authorization using multiple accounts/roles, for example: User A → User B Member → Partner Member → Staff Partner → Staff Anonymous → Authenticated resources and testing the Supabase/PostgREST/API layer directly rather than relying only on what the frontend UI allows. DELIVERABLES I would like: 1. Independent security assessment of the existing application. 2. Findings categorized by severity (Critical / High / Medium / Low). 3. Clear explanation and reproduction steps for each confirmed vulnerability. 4. Recommended remediation. 5. Identification of false positives where relevant. 6. Short overall pre-launch security assessment. 7. Retest of Critical/High findings after remediation. Please do not make destructive changes to production data without explicit approval. TIMELINE Preferred turnaround: approximately 3–7 days. The application is approaching launch, so availability to begin soon is preferred. BUDGET This is currently planned as a fixed-price initial security audit. Please include your proposed price and explain what is included in that price. There may be an opportunity for additional paid work after the audit, including remediation, security improvements, periodic reviews, or longer-term technical collaboration if we work well together. WHEN APPLYING Please answer these questions: 1. What experience do you have specifically with Supabase security and PostgreSQL RLS? 2. How would you test whether User A can access User B's data even when the frontend does not expose that functionality? 3. How do you review SECURITY DEFINER functions/views and PostgreSQL grants for privilege-escalation risks? 4. How would you test Supabase Storage and signed URLs for unauthorized cross-user access? 5. Have you performed security reviews of production SaaS/social/community applications before? 6. What parts of the assessment would you test manually rather than with automated tools? 7. What would you deliver at the end of the audit? Please include relevant examples of previous security work if possible. ABOUT THE PROJECT SAFO is an independent community platform being built for queer women, with social, community, events and discovery functionality. Because privacy and user trust are especially important for this product, I want an independent human security review before wider public launch. Experience with privacy-sensitive platforms, social applications, Supabase or multi-role SaaS systems is a strong advantage. I am also open to working with someone who is interested in the project beyond this initial audit.

  • $700.00

    Fixed-price
  • Expert
    Experience Level
  • Remote Job
  • One-time project
    Project Type

Contract-to-hire opportunity

This lets talent know that this job could become full time.
Learn more
Skills and Expertise
Mandatory skills
Penetration Testing
Information Security
Activity on this job
  • Proposals:15 to 20
  • Last viewed by client:yesterday
  • Interviewing:
    8
  • Invites sent:
    3
  • Unanswered invites:
    0
About the client
Member since Aug 16, 2026
  • Denmark
    9:17 PM

Explore similar jobs on Upwork

Principal Security Transformation ArchitectHourly‐ Posted 2 months ago
Lead Generation
Internet Marketing
Cloud Computing
Cloud Security Framework
Network Security
Solution Architecture
Security Infrastructure
Application Security
Security Engineering
Website Security AuditHourly‐ Posted 4 weeks ago
Security Testing
Penetration Testing
Vulnerability Assessment
Website Security

How it works

  • Post a job icon
    Create your free profile
    Highlight your skills and experience, show your portfolio, and set your ideal pay rate.
  • Talent comes to you icon
    Work the way you want
    Apply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
  • Payment simplified icon
    Get paid securely
    From contract to payment, we help you work safely and get paid securely.
Want to get started? Create a profile

About Upwork

  • Rating is 4.9 out of 5.
    4.9/5
    (Average rating of clients by professionals)
  • G2 2021
    #1 freelance platform
  • 49,000+
    Signed contract every week
  • $2.3B
    Freelancers earned on Upwork in 2020

Find the best freelance jobs

Growing your career is as easy as creating a free profile and finding work like this that fits your skills.

Trusted by

  • Microsoft Logo
  • Airbnb Logo
  • Bissell Logo
  • GoDaddy Logo