GDPR/LOPD & ISO 27001 Compliance Audit + Pentesting - Next.js 15 / AWS RDS
Budget / Salary€250–750
TypeFreelance project
LocationRemote
Posted1 hour ago
We require an elite Ethical Hacker / Cybersecurity Compliance Auditor based in Spain (strict network requirement for native Spanish residential IP testing due to government endpoint firewall constraints) to perform a comprehensive Compliance Audit and express penetration test on a containerized Docker application (ATLAS Property OS).
STRICT LEGAL & CIBERSECURITY SHIELD FOR THE HOLDING:
Before receiving any repository access, documentation, or Docker setup files, the selected candidate MUST strictly sign a comprehensive Ethical Hacking Covenant, a corporate Non-Disclosure Agreement (NDA) with international breach penalties, and a Data Processing Agreement (DPA) complying with European GDPR and Spanish LOPD-GDD regulations. All testing must be conducted within an isolated pre-production staging sandbox environment. Full audit logging and traceability of the auditor's IP actions will be active throughout the session. Absolute data privacy and trade secret protection are non-negotiable.
STACK TECH:
- Frontend/Backend: Next.js 15 (App Router)
- Database: AWS RDS PostgreSQL
- Authentication & RBAC: NextAuth.js (Session middleware enforcing multi-tier time locks)
YOUR AUDIT & COMPLIANCE TARGETS:
1. Legal & Regulatory Compliance (GDPR / LOPD-GDD): Audit the backend architecture and telemetry systems to certify that user tracking, session caching, and IP logging are 100% compliant with European GDPR and Spanish LOPD regulations. Verify that data pseudonymization (SHA-256) is properly enforced at the API layer.
2. Global Security Standard Mapping (ISO/IEC 27001): Review our cloud infrastructure blueprint mapped against AWS RDS instance configurations to validate that the deployment layout complies with ISO 27001 controls regarding data encryption at rest/in transit, access control monitoring, and log retention.
3. Logic Counter Gating & Core Flaws: Attempt to bypass server-side NextAuth.js middleware countdown restrictions (120h and 72h data locks) via frontend client manipulation, JavaScript console injection, or token spoofing.
4. Vulnerability & Anti-Scraping Assessment: Test server-side Rate Limiting mechanisms against custom automation bots attempting data extraction. Perform deep testing against SQL injections, Cross-Site Scripting (XSS), and Broken Object Level Authentication (BOLA).
DELIVERABLE:
A technical, comprehensive Penetration Test & Global Compliance Report (PDF) detailing detected vulnerabilities, threat levels, and concrete code-level remediation steps. Once vulnerabilities are patched by our developer, you will sign off our official "Security, GDPR & ISO 27001 Compliance Certificate".
Timeline: 48-72 hours once Docker container is deployed on staging this week.
Budget: Fixed Price (200€ - 300€).
Please post your verification credentials, certifications (CEH, OSCP, CISA or similar), and past auditing experience in Spain. Immediate selection.
STRICT LEGAL & CIBERSECURITY SHIELD FOR THE HOLDING:
Before receiving any repository access, documentation, or Docker setup files, the selected candidate MUST strictly sign a comprehensive Ethical Hacking Covenant, a corporate Non-Disclosure Agreement (NDA) with international breach penalties, and a Data Processing Agreement (DPA) complying with European GDPR and Spanish LOPD-GDD regulations. All testing must be conducted within an isolated pre-production staging sandbox environment. Full audit logging and traceability of the auditor's IP actions will be active throughout the session. Absolute data privacy and trade secret protection are non-negotiable.
STACK TECH:
- Frontend/Backend: Next.js 15 (App Router)
- Database: AWS RDS PostgreSQL
- Authentication & RBAC: NextAuth.js (Session middleware enforcing multi-tier time locks)
YOUR AUDIT & COMPLIANCE TARGETS:
1. Legal & Regulatory Compliance (GDPR / LOPD-GDD): Audit the backend architecture and telemetry systems to certify that user tracking, session caching, and IP logging are 100% compliant with European GDPR and Spanish LOPD regulations. Verify that data pseudonymization (SHA-256) is properly enforced at the API layer.
2. Global Security Standard Mapping (ISO/IEC 27001): Review our cloud infrastructure blueprint mapped against AWS RDS instance configurations to validate that the deployment layout complies with ISO 27001 controls regarding data encryption at rest/in transit, access control monitoring, and log retention.
3. Logic Counter Gating & Core Flaws: Attempt to bypass server-side NextAuth.js middleware countdown restrictions (120h and 72h data locks) via frontend client manipulation, JavaScript console injection, or token spoofing.
4. Vulnerability & Anti-Scraping Assessment: Test server-side Rate Limiting mechanisms against custom automation bots attempting data extraction. Perform deep testing against SQL injections, Cross-Site Scripting (XSS), and Broken Object Level Authentication (BOLA).
DELIVERABLE:
A technical, comprehensive Penetration Test & Global Compliance Report (PDF) detailing detected vulnerabilities, threat levels, and concrete code-level remediation steps. Once vulnerabilities are patched by our developer, you will sign off our official "Security, GDPR & ISO 27001 Compliance Certificate".
Timeline: 48-72 hours once Docker container is deployed on staging this week.
Budget: Fixed Price (200€ - 300€).
Please post your verification credentials, certifications (CEH, OSCP, CISA or similar), and past auditing experience in Spain. Immediate selection.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.