SaaS/Application Security Penetration Tester

via Freelancer ·

Budget / Salary£250–750
TypeFreelance project
LocationRemote
Posted1 hour ago
About the project:

We are looking for an experienced **web application penetration tester** to conduct an independent security assessment of a SaaS platform.

The application is a business management platform with authenticated user accounts, document handling, portals, workflows, messaging and APIs.

Further details about the application and functionality will be provided to shortlisted candidates.

Scope:

The assessment should cover the web application and relevant APIs, including authenticated functionality.

Areas of interest include:

* Authentication and session management
* Authorisation and access controls
* Horizontal and vertical privilege escalation
* IDOR / BOLA vulnerabilities
* OWASP Top 10
* API security
* Input validation and injection vulnerabilities
* Cross-site scripting (XSS)
* CSRF
* File/document upload and handling
* Business-logic vulnerabilities
* Sensitive data exposure
* Client/tenant data isolation
* Security misconfiguration
* Account and password security
* Common SaaS/web application vulnerabilities

Testing should include **manual testing in addition to appropriate automated tooling**, with particular attention to authorisation, data isolation and business logic.

Access:

We will provide appropriate test accounts and credentials for the application.

Testing will be conducted against an agreed environment

Required deliverables:

- The primary requirement is a **professional penetration-testing report **.
- If vulnerabilities are identified and subsequently remediated, one verification/retest of fixes.

Tester requirements:

**CREST CRT certification is strongly preferred.**

Other recognised penetration-testing certifications such as OSCP are also welcome.

Please include in your proposal:

1. Your relevant certifications
2. Your experience with SaaS/web application penetration testing
3. Your experience testing APIs
4. Confirmation that you perform manual testing in addition to automated scanning
5. A **redacted example of a previous penetration-testing report**, if available
6. What will be included in your final report
7. Your proposed fixed price
8. Estimated testing duration

Important:

We are **not looking for an automated vulnerability scan or a generic security report**.

The objective is an independent, manually reviewed penetration test that can provide meaningful assurance to the company and its customers.

Please clearly state what level of testing and reporting you can provide within your proposed price.

Budget:

Target budget: £250–£500 GBP fixed price.

We are an early-stage company, so competitive pricing is important. We may consider proposals slightly outside this range where the additional scope/value is clearly justified.

We are specifically looking for a focused web application/API penetration test and professional written report, rather than ongoing security monitoring or broader consultancy services.
web security testing / qa software testing internet security penetration testing risk assessment saas security auditing
Apply on Freelancer →

Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.