Manual penetration test needed for educational technology application.

Posted 3 weeks ago

Only freelancers located in the U.S. may apply.U.S. located freelancers only

Summary

Manual Penetration Test for EdTech SaaS Web App (Required for University Vendor Approval) Cybersecurity & Compliance / Penetration Testing One-time project Estimated Budget:** Fixed price - $3,000-$5,000 (open to discussing scope adjustments to fit budget) We're a small software company (Drawbridge Inc.) that builds Eli Review, a peer-review writing platform used by students and instructors in higher education. We need a **manual penetration test** of our web application and API, primarily to satisfy a university customer's third-party vendor security review. We are **not** looking for an automated vulnerability scan with a report attached — we need a tester who manually assesses business logic, access control between user roles, and authentication/session handling, and can produce a report suitable for submission to a university information security office. What We Need Tested - Web application (single production or staging environment — we'll provide the URL and test accounts) - REST API supporting the application - Role-based access control: our app has student, instructor, and admin roles — we specifically want testing of whether one role can improperly access another's data (e.g., a student viewing another student's peer review submissions, or cross-course data leakage) - Authentication and session management (login flow, password reset, session handling) - LTI/LMS integration points (we'll clarify exact scope with finalists) What We'll Provide - Access to a staging environment (preferred) with test accounts across all user roles - Basic architecture documentation - A point of contact for questions during testing Deliverables - Full technical findings report (scope, methodology, findings with severity ratings, proof-of-concept evidence, remediation recommendations) - **An executive summary of findings** suitable for sharing with a university vendor risk review team (this is a hard requirement - we need something we can submit externally, not just an internal-only report) - Availability for a brief call to walk through findings Ideal Candidate - Demonstrated experience with **manual** web application penetration testing (not just automated scanning) — please reference specific methodologies or tools you use for testing business logic and access control - Relevant certifications preferred (OSCP, CREST, GWAPT, or similar) - please list any you hold - Experience with SaaS/multi-tenant applications a plus - Experience producing reports for higher-education or compliance contexts (HECVAT, SOC 2 support, FERPA-relevant environments) is a strong plus given our use case, but not required - Comfortable working within a fixed timeline and fixed-scope budget Timeline Looking to start as soon as possible and have a completed report within 2 weeks of kickoff. To Apply, Please Include 1. A brief description of your manual testing methodology (what you do beyond automated scanning) 2. 1-2 examples of past web app/API pentest engagements (sanitized/redacted is fine) - ideally similar in scope to a single web app + API 3. Relevant certifications 4. A proposed fixed price and estimated turnaround time for the scope described above 5. Whether you're able to provide an executive summary format suitable for external/university submission

  • Less than 30 hrs/week
    Hourly
  • < 1 month
    Duration
  • Intermediate
    Experience Level
  • $20.00

    -

    $65.00

    Hourly
  • Remote Job
  • One-time project
    Project Type
Skills and Expertise
Mandatory skills
Penetration Testing
Activity on this job
  • Proposals:10 to 15
  • Interviewing:
    0
  • Invites sent:
    0
  • Unanswered invites:
    0
About the client
Member since Jul 29, 2026
  • United States
    12:42 PM

Explore similar jobs on Upwork

Penetration Testing
Internet Security
Information Security
Vulnerability Assessment
Ethical Hacking
Penetration Testing NeededHourly‐ Posted 3 weeks ago
Penetration Testing
Vulnerability Assessment
Information Security
Network Security
Ethical Hacking

How it works

  • Post a job icon
    Create your free profile
    Highlight your skills and experience, show your portfolio, and set your ideal pay rate.
  • Talent comes to you icon
    Work the way you want
    Apply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
  • Payment simplified icon
    Get paid securely
    From contract to payment, we help you work safely and get paid securely.
Want to get started? Create a profile

About Upwork

  • Rating is 4.9 out of 5.
    4.9/5
    (Average rating of clients by professionals)
  • G2 2021
    #1 freelance platform
  • 49,000+
    Signed contract every week
  • $2.3B
    Freelancers earned on Upwork in 2020

Find the best freelance jobs

Growing your career is as easy as creating a free profile and finding work like this that fits your skills.

Trusted by

  • Microsoft Logo
  • Airbnb Logo
  • Bissell Logo
  • GoDaddy Logo