Web Application Penetration Tester (OWASP / OSCP) SaaS pre-launch security assessment + attestation

Posted 11 hours ago

Worldwide

Summary

We are a SaaS company preparing, a web application, for launch. Before go-live we need a manual web application penetration test performed by an independent third party, delivered to a standard we can later reuse as evidence in our SOC 2 and ISO 27001 programs. This is not an automated scan. We are looking for someone who does hands-on, manual testing following a recognized methodology and produces a professional report plus a formal attestation letter. Scope of work Authenticated and unauthenticated web application penetration test Coverage of the OWASP Top 10 and testing aligned to OWASP ASVS API / backend endpoint testing Authentication, session management, and password/reset flows Access-control testing between user roles, including multi-tenant data isolation (verifying one customer/tenant cannot access another's data) Input handling: injection, XSS, SSRF, file upload, etc. Business-logic testing (not just scanner findings) Target environment: [staging URL / production — specify]. Tech stack: [e.g. React front end, Node/Python API, PostgreSQL, hosted on AWS]. Approx. size: [X endpoints / Y user roles]. Required deliverables Penetration test report including: executive summary, methodology used, full scope, each finding with severity rating (CVSS), evidence/reproduction steps, and specific remediation guidance. Formal Penetration Test Attestation Letter on your/your company letterhead, stating the application tested, the scope, the testing dates, and — after remediation — confirmation that identified issues were retested and resolved. (We will use this for internal sign-off and as evidence toward SOC 2 / ISO 27001.) One free retest round after we remediate the findings, with an updated attestation reflecting closed items. A redacted sample report shared during screening so we can assess report quality before hiring. Independence note You will perform testing only. Our own engineering team will implement the fixes — please do not include code remediation of our application in your scope, as we need to preserve tester independence for audit purposes.

  • $500.00

    Fixed-price
  • Expert
    Experience Level
  • Remote Job
  • Ongoing project
    Project Type
Skills and Expertise
Mandatory skills
Penetration Testing
Vulnerability Assessment
Activity on this job
  • Proposals:15 to 20
  • Last viewed by client:10 hours ago
  • Interviewing:
    3
  • Invites sent:
    7
  • Unanswered invites:
    3
About the client
Member since May 31, 2026
  • Australia
    Williams Landing4:14 AM
  • Tech & IT
    Mid-sized company (10-99 people)

Explore similar jobs on Upwork

Cybersecurity Expert for IoT and Hardware HackingFixed-price‐ Posted 2 months ago
C
C++
Internet of Things
Sales
Cold Calling
Lead Generation
Outbound Sales
B2B Marketing
Startup Company

How it works

  • Post a job icon
    Create your free profile
    Highlight your skills and experience, show your portfolio, and set your ideal pay rate.
  • Talent comes to you icon
    Work the way you want
    Apply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
  • Payment simplified icon
    Get paid securely
    From contract to payment, we help you work safely and get paid securely.
Want to get started? Create a profile

About Upwork

  • Rating is 4.9 out of 5.
    4.9/5
    (Average rating of clients by professionals)
  • G2 2021
    #1 freelance platform
  • 49,000+
    Signed contract every week
  • $2.3B
    Freelancers earned on Upwork in 2020

Find the best freelance jobs

Growing your career is as easy as creating a free profile and finding work like this that fits your skills.

Trusted by

  • Microsoft Logo
  • Airbnb Logo
  • Bissell Logo
  • GoDaddy Logo