One-day penetration test - fintech API + iOS app - AU-based OSCP required

Posted yesterday

Worldwide

Summary

We need a small, tightly scoped penetration test to satisfy a contractual compliance requirement with our open banking data provider. Fixed price, one day of testing (6-8 hours) plus the report. About us: we're an Australian fintech startup (personal finance forecasting app, iOS). One Django REST API, one iOS app, AWS in the Sydney region. Small attack surface, no legacy. SCOPE (grey-box, tested from the public internet - credentials and a test account provided): 1. Production REST API - authentication, session handling, access control (multi-tenant data isolation), OWASP Top 10. 2. iOS app (TestFlight build supplied) - transport security, local data storage, auth token handling. Light review, not a full mobile audit. 3. One inbound webhook endpoint (our banking-data integration) - authentication and input handling. 4. External surface of the AWS environment behind the above (ap-southeast-2) - exposed services only. OUT OF SCOPE: social engineering, denial of service, physical security, source code review, internal network, our marketing website, and any third-party systems (including our data provider's platform). DELIVERABLE: A formal PDF report on your letterhead containing: - severity-rated findings with reproduction steps - a short summary of material issues - a statement of your qualifications (OSCP) and independence from our company No retest required. We will handle remediation ourselves. REQUIREMENTS: - Based in Australia - OSCP certified (please include your certification number) - ABN for invoicing - A sample report (redacted is fine) TIMEFRAME: within the next 2 weeks. TO APPLY, please tell us: 1. Your fixed price for the scope above 2. Your earliest available start date 3. Your OSCP number 4. A redacted sample report Please don't propose an expanded scope or an ongoing retainer - we need exactly the above, done once.

  • $900.00

    Fixed-price
  • Expert
    Experience Level
  • Remote Job
  • One-time project
    Project Type
Skills and Expertise
Mandatory skills
Penetration Testing
OSCP
Activity on this job
  • Proposals:Less than 5
  • Last viewed by client:15 hours ago
  • Interviewing:
    0
  • Invites sent:
    0
  • Unanswered invites:
    0
About the client
Member since Mar 12, 2023
  • Australia
    5:26 AM

Explore similar jobs on Upwork

Facebook Account Hacking IssueFixed-price‐ Posted 2 weeks ago
Facebook Development
Facebook
Social Media Marketing
PHP
HackedHourly‐ Posted 3 weeks ago
Malware Removal
WordPress Website Design
Information Security
Penetration Testing
Vulnerability Assessment
Network Security
CMS Development
WordPress Malware Removal
Virus Removal
Cloudflare
SSL
Ethical Hacking
cPanel
WordPress Bug Fix
WordPress Security

How it works

  • Post a job icon
    Create your free profile
    Highlight your skills and experience, show your portfolio, and set your ideal pay rate.
  • Talent comes to you icon
    Work the way you want
    Apply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
  • Payment simplified icon
    Get paid securely
    From contract to payment, we help you work safely and get paid securely.
Want to get started? Create a profile

About Upwork

  • Rating is 4.9 out of 5.
    4.9/5
    (Average rating of clients by professionals)
  • G2 2021
    #1 freelance platform
  • 49,000+
    Signed contract every week
  • $2.3B
    Freelancers earned on Upwork in 2020

Find the best freelance jobs

Growing your career is as easy as creating a free profile and finding work like this that fits your skills.

Trusted by

  • Microsoft Logo
  • Airbnb Logo
  • Bissell Logo
  • GoDaddy Logo