GDPR/LOPD & ISO 27001 Compliance Audit + Pentesting - Next.js 15 / AWS RDS

via Freelancer ·

Budget / Salary€250–750
TypeFreelance project
LocationRemote
Posted1 hour ago
We require an elite Ethical Hacker / Cybersecurity Compliance Auditor based in Spain (strict network requirement for native Spanish residential IP testing due to government endpoint firewall constraints) to perform a comprehensive Compliance Audit and express penetration test on a containerized Docker application (ATLAS Property OS).

STRICT LEGAL & CIBERSECURITY SHIELD FOR THE HOLDING:
Before receiving any repository access, documentation, or Docker setup files, the selected candidate MUST strictly sign a comprehensive Ethical Hacking Covenant, a corporate Non-Disclosure Agreement (NDA) with international breach penalties, and a Data Processing Agreement (DPA) complying with European GDPR and Spanish LOPD-GDD regulations. All testing must be conducted within an isolated pre-production staging sandbox environment. Full audit logging and traceability of the auditor's IP actions will be active throughout the session. Absolute data privacy and trade secret protection are non-negotiable.

STACK TECH:
- Frontend/Backend: Next.js 15 (App Router)
- Database: AWS RDS PostgreSQL
- Authentication & RBAC: NextAuth.js (Session middleware enforcing multi-tier time locks)

YOUR AUDIT & COMPLIANCE TARGETS:
1. Legal & Regulatory Compliance (GDPR / LOPD-GDD): Audit the backend architecture and telemetry systems to certify that user tracking, session caching, and IP logging are 100% compliant with European GDPR and Spanish LOPD regulations. Verify that data pseudonymization (SHA-256) is properly enforced at the API layer.
2. Global Security Standard Mapping (ISO/IEC 27001): Review our cloud infrastructure blueprint mapped against AWS RDS instance configurations to validate that the deployment layout complies with ISO 27001 controls regarding data encryption at rest/in transit, access control monitoring, and log retention.
3. Logic Counter Gating & Core Flaws: Attempt to bypass server-side NextAuth.js middleware countdown restrictions (120h and 72h data locks) via frontend client manipulation, JavaScript console injection, or token spoofing.
4. Vulnerability & Anti-Scraping Assessment: Test server-side Rate Limiting mechanisms against custom automation bots attempting data extraction. Perform deep testing against SQL injections, Cross-Site Scripting (XSS), and Broken Object Level Authentication (BOLA).

DELIVERABLE:
A technical, comprehensive Penetration Test & Global Compliance Report (PDF) detailing detected vulnerabilities, threat levels, and concrete code-level remediation steps. Once vulnerabilities are patched by our developer, you will sign off our official "Security, GDPR & ISO 27001 Compliance Certificate".

Timeline: 48-72 hours once Docker container is deployed on staging this week.
Budget: Fixed Price (200€ - 300€).

Please post your verification credentials, certifications (CEH, OSCP, CISA or similar), and past auditing experience in Spain. Immediate selection.
linux computer security cloud computing audit amazon web services postgresql ubuntu penetration testing docker next.js
Apply on Freelancer →

Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.