Robust Security for Freelance Platform
Budget / Salary$10–100,000
TypeFreelance project
LocationRemote
Posted2 hours ago
I’m preparing to launch a brand-new freelancing marketplace and I want its security to be rock solid from day one. The platform will process personal details, handle payments, and store highly sensitive client files, so every layer—the data, the users, and the network itself—has to be locked down.
Here is what I need from you:
• A complete security architecture that covers end-to-end data encryption (in transit and at rest), hardened network infrastructure, and a resilient incident-response plan.
• An authentication flow that supports multiple methods—two-factor, biometrics, email or similar—so I can enable, mix, or swap them without changing core code later on.
• Secure coding guidelines or a review checklist my dev team can refer to, plus automated tests that prove the implementation is actually protecting personal, financial, and other sensitive records.
• Clear documentation that a non-security engineer can follow when we roll out updates or bring in new compliance requirements.
I’m open to your preferred stack or tools—whether you work with AWS/KMS, Azure Key Vault, HashiCorp Vault, Cloudflare, or on-prem hardware appliances—as long as you explain why your choice best fits a high-traffic marketplace.
Acceptance criteria
1. All user traffic is encrypted and any stored data is encrypted with unique keys per tenant.
2. Vulnerability scans and penetration tests return no critical or high-severity findings.
3. Authentication flow supports at least two configurable second-factor options out of the box.
4. Documentation is complete enough for my in-house team to maintain without outside help.
If you can deliver this level of protection efficiently and clearly, I’d like to hear how you plan to approach it and what timeline you foresee.
Here is what I need from you:
• A complete security architecture that covers end-to-end data encryption (in transit and at rest), hardened network infrastructure, and a resilient incident-response plan.
• An authentication flow that supports multiple methods—two-factor, biometrics, email or similar—so I can enable, mix, or swap them without changing core code later on.
• Secure coding guidelines or a review checklist my dev team can refer to, plus automated tests that prove the implementation is actually protecting personal, financial, and other sensitive records.
• Clear documentation that a non-security engineer can follow when we roll out updates or bring in new compliance requirements.
I’m open to your preferred stack or tools—whether you work with AWS/KMS, Azure Key Vault, HashiCorp Vault, Cloudflare, or on-prem hardware appliances—as long as you explain why your choice best fits a high-traffic marketplace.
Acceptance criteria
1. All user traffic is encrypted and any stored data is encrypted with unique keys per tenant.
2. Vulnerability scans and penetration tests return no critical or high-severity findings.
3. Authentication flow supports at least two configurable second-factor options out of the box.
4. Documentation is complete enough for my in-house team to maintain without outside help.
If you can deliver this level of protection efficiently and clearly, I’d like to hear how you plan to approach it and what timeline you foresee.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.