
Closed
Posted
Paid on delivery
We need an independent third-party penetration test of our production SaaS platform to satisfy a SOC 2 control. We're looking for an experienced, certified penetration tester (OSCP / OSWE / GWAPT / CREST or equivalent) who can start immediately and deliver a professional, audit-ready report. TIMELINE — TIME-SENSITIVE: We need the testing performed and the final report delivered within 1 week of kickoff. Please only bid if you have current availability. ABOUT THE SYSTEM (full details and credentials shared under NDA with the selected tester): - Customer-facing web application: [login to view URL] / React / TypeScript - Backend: Python / Django / Django REST Framework API - Authentication: Keycloak (OIDC) — username/password, social login, TOTP/MFA - Two supporting Python/Django microservices - Hosted on AWS (ECS Fargate, ALB + WAF, RDS PostgreSQL) - Role-based access with two primary roles (organization admin + end user) SCOPE: - External web application penetration test (OWASP Web Security Testing Guide) - API penetration test (OWASP API Security Top 10) - Authenticated testing across both user roles, with emphasis on authorization / access-control / IDOR / privilege escalation - Authentication & session security review (OIDC flows, token handling, MFA) - We'll align with you on whether to test a production-mirrored staging environment or production directly. OUT OF SCOPE (unless you flag something as essential): source-code audit, full cloud-configuration audit, social engineering, physical security, and DDoS testing. REQUIRED DELIVERABLES: 1. Formal penetration test report suitable for a SOC 2 audit — executive summary, scope, methodology, findings with CVSS severity ratings, proof-of-concept / reproduction steps, and prioritized remediation guidance. 2. A retest / verification of remediated findings after we fix them. 3. A signed attestation / summary letter we can share with our auditor (stating an independent test was performed, plus the period and scope). INDEPENDENCE: You must be independent from our company (no prior development relationship). This is required for the SOC 2 control. BUDGET: Open — please submit your best fixed-price bid for the full engagement (testing + report + one retest + attestation letter). Fixed-price proposals only. TO BE CONSIDERED, PLEASE INCLUDE IN YOUR PROPOSAL: 1. A redacted sample penetration test report (so we can assess report quality). 2. Your relevant certifications and a brief note on similar SOC 2 engagements. 3. Your earliest start date and the turnaround time you can commit to. 4. Your fixed price for the scope above. what should I add
Project ID: 40505507
142 proposals
Remote project
Active 21 secs ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
142 freelancers are bidding on average $541 USD for this job

Hi I can handle the independent third-party penetration test for your SaaS platform and provide a SOC 2 audit-ready report with clear evidence, CVSS ratings, reproduction steps, and remediation guidance. My focus will be on OWASP WSTG, OWASP API Top 10, authenticated role-based testing, IDOR, privilege escalation, Keycloak/OIDC session security, MFA behavior, token handling, and API authorization across Django/DRF services. A key risk in this stack is broken object-level authorization between organization admin and end-user roles, especially across APIs and microservices, so I will test access boundaries carefully with mapped test cases and documented proof. I can also provide one retest after remediation and a signed attestation letter confirming the independent testing period, scope, and methodology. Thanks, Hercules
$500 USD in 7 days
6.5
6.5

With over a decade of experience in the software development field, Web Crest, led by me, Mubeen, is your top choice for the task at hand. Specializing in SaaS platforms and having expertise in Python and Software Architecture, we can guarantee a comprehensive and professional penetration test for your production SaaS platform. To ensure an audit-ready report that satisfies SOC 2 control, precision is key. We have carried out similar SOC 2 engagements and have pertinent certifications (OsCP / OSWE / GWAPT / CREST equivalent) that validate our prowess in the tasks you require. Our team's platform development skills include Python / Django / Django REST Framework API as mentioned in your project description, providing us with the needed know-how to execute the job effectively.
$300 USD in 5 days
6.6
6.6

Hi, Thank you for the detailed brief. We've reviewed the requirements and have a clear understanding of the objective: conducting an independent, SOC 2-ready penetration test of your SaaS platform covering the web application, API, authentication flows, and role-based access controls, with a formal audit-ready report, retest, and signed attestation letter delivered within one week. We particularly appreciate the clarity around independence and deliverable requirements. In our view, the most critical part of this engagement is the authorization and access control testing across both user roles, since IDOR and privilege escalation vulnerabilities are the most common findings on Django REST Framework APIs with RBAC implementations. Based on the information provided, we can cover an OWASP WSTG-aligned web application test, OWASP API Security Top 10 assessment, authenticated testing across organization admin and end user roles, Keycloak OIDC and MFA session security review, a formal report with CVSS ratings and remediation guidance, one retest of fixed findings, and a signed attestation letter suitable for your SOC 2 auditor. Kind regards, Houssame
$500 USD in 7 days
6.5
6.5

Hi, I can perform an independent, audit-ready penetration test for your SaaS platform within the requested timeline, covering the external web application, Django/DRF APIs, authenticated role-based testing, OIDC/Keycloak flows, MFA/session handling, authorization, IDOR, privilege escalation, and OWASP Web/API Top 10 areas. My approach would begin with a short kickoff to confirm scope, test environment, rules of engagement, credentials, rate limits, and reporting expectations. I would then perform manual testing supported by industry-standard tools, document findings with CVSS severity, business impact, reproduction steps, evidence, and prioritized remediation guidance. Deliverables would include: Formal SOC 2-ready penetration test report Executive summary and technical findings OWASP WSTG/API methodology coverage CVSS-rated vulnerabilities Proof-of-concept and remediation steps One retest of remediated findings Signed attestation/summary letter for your auditor I understand independence is required and confirm no prior development relationship with your company. Critical findings would be reported immediately, before the final report. I can provide a redacted sample report, certification details, similar SOC 2 engagement experience, earliest start date, committed turnaround, and fixed-price bid for testing, reporting, retest, and attestation.
$500 USD in 7 days
5.8
5.8

Drawing from my extensive 7+ years of experience as a penetration tester, I believe that my skill set aligns perfectly with the requirements that your crucial project demands. My focus lies in thinking like an attacker rather than merely fulfilling checkboxes - a quality that sets me apart from the rest. I've built a reputation by identifying security gaps before they become costly incidents for my clients, and this is precisely what your platform needs. Having undertook numerous web app and API penetration tests in the past, I am well-versed with the tenets of OWASP and beyond, which is bound to serve you tremendously in your SaaS platform's testing needs. My expertise goes beyond mere penetration testing to encompass red teaming and adversary simulations as well. In addition, I am skilled in vulnerability assessments using leading tools such as Invicti, Nessus, Nmap, and Qualys. My certifications, including OSCP and CISSP reflect my commitment to providing only top-notch services. Notably, I've also conducted similar SOC 2 engagements in the past and provide reports suitable for audit reviews. Lastly, given the time-sensitive nature of your project, I assure you promptness and efficiency in delivering quality results
$700 USD in 7 days
5.6
5.6

I have relevant skills and experience as a penetration tester that align perfectly with your project requirements. Currently, I hold an OSCP certification, which demonstrates my deep understanding of web application security, and the OSWE and GWAPT certifications for API security. My track record of delivering professional penetration testing reports that are both honest and constructive would be of great value in your project. I adhere to the OWASP guidelines extensively in my tests, which aligns with your scope and expectations. The fact that you need an independent third party to conduct these tests plays into my strengths; I have no prior development relationship with your company ensuring complete objectivity. Moreover, I’ve worked on similar SOC 2 engagements before where independence was vital to compliance; this makes me familiar with the requisites of such projects and speeds up any procedural hiccups. Timelines are my forte as I follow an agile and reliable execution approach. Starting immediately upon hire, I can commit to conducting comprehensive testing, providing a detailed report with prioritized remediation guidance within one week. To further assure you of my quality of work and its pertinent nature to your project, I will include a redacted sample penetration test report in my bid.
$300 USD in 6 days
5.2
5.2

Certified AWS Solutions Architect – Professional Certified AWS Solutions Architect – Associate CISA Certified Security Expert 16+ Years of Industry Experience in Cybersecurity, Cloud & Compliance Hi, I'm excited about the opportunity to perform an independent third-party penetration test of your SaaS platform for SOC 2 compliance. With 16+ years of experience conducting web application, API, cloud, and authentication security assessments, I have helped organizations meet SOC 2, ISO 27001, PCI DSS, and regulatory requirements through comprehensive, audit-ready penetration testing engagements. My assessment will cover OWASP WSTG, OWASP API Security Top 10, authentication and session security, RBAC validation, IDOR testing, privilege escalation scenarios, and business logic vulnerabilities across both user roles. Deliverables will include a detailed executive report, CVSS-rated findings, remediation guidance, retest validation, and an auditor-ready attestation letter. I can start immediately and commit to the requested timeline. Budget can be finalized after reviewing the detailed scope and environment complexity. Best Regards, SHD
$700 USD in 7 days
5.3
5.3

Hi, I'm a Cyber Security Researcher with practical experience gained through playing CTFs (Capture The Flag), engaging in Bug Bounties, and working as a Pentester. Notice: Don’t ask me to hack something u don’t OWN What I can do for you: Web/API/Android (OWASP TOP 10) Pentesting: You can also get this service from here: https://www.freelancer.com/service/web_security/web-app-penetration-test-owasp-top Lets Chat…
$500 USD in 7 days
4.8
4.8

Hi, I have experience with SaaS security, AWS infrastructure, API security testing, and authentication systems. I'm familiar with OWASP Top 10, access control validation, API security reviews, and secure cloud architectures. I’m available to start immediately and can work within your required timeline. Best regards, Shakila Naz
$300 USD in 7 days
5.1
5.1

I am excited to submit my proposal for your SaaS Platform Penetration Testing project. With extensive experience in application security and ethical hacking, I specialize in identifying vulnerabilities within web-based SaaS environments, APIs, authentication systems, and cloud-hosted infrastructures. My goal is to provide a thorough security assessment that uncovers risks before they can be exploited, helping you strengthen your platform's security posture and protect customer data. My testing methodology follows industry-recognized standards such as OWASP Top 10, OWASP API Security, and PTES. I will perform comprehensive assessments of authentication and authorization controls, session management, API endpoints, input validation, business logic vulnerabilities, privilege escalation risks, and cloud security configurations. Throughout the engagement, I maintain clear communication and provide detailed documentation of findings, including severity ratings, proof-of-concept evidence, and practical remediation recommendations.
$250 USD in 7 days
4.6
4.6

With my 14-year experience in full-stack development and expertise in Python and Django, I assure you that I have the knowledge and skillset to provide a meticulous SaaS platform penetration test. As you require a third-party tester, my independence from your company places me in an ideal position to objectively assess your platform for potential weaknesses that may expose you to security breaches and possible non-compliance with SOC 2 requirements. In terms of deliverables, rest assured that not only will you receive a comprehensive report aligning with the standards required by SOC 2 audits but also a guarantee of thorough retesting of remediated findings. Furthermore, I understand the necessity of adhering to deadlines, especially in time-sensitive projects like yours. My proposal ensures a fixed-price delivery within your specified timeline without compromising on quality. Allow me to emphasize my commitment to treating your project individually and personally, bringing tailored security measures specific to your SaaS platform's intricacies.
$700 USD in 7 days
4.5
4.5

Hi, I can assist with an independent penetration test of your SaaS platform, covering the web application, APIs, authentication flows, authorization controls, and OWASP-aligned security testing. I can provide a professional audit-ready report with detailed findings, remediation guidance, retesting, and supporting documentation for SOC 2 requirements.
$500 USD in 7 days
2.6
2.6

I understand the time-sensitive nature of this engagement and the importance of producing evidence that will withstand SOC 2 auditor scrutiny. I follow a structured, risk-based testing methodology aligned with OWASP standards and industry best practices, maintaining clear communication throughout the assessment with timely updates on any critical findings that require immediate attention. All testing activities are conducted under strict confidentiality and NDA requirements, with careful coordination to minimize disruption to your environment. Beyond identifying vulnerabilities, my focus is on delivering practical, prioritized remediation guidance that enables your team to address risks efficiently and successfully complete the compliance process.
$750 USD in 7 days
2.9
2.9

Hello, I'm Jordan from Tequlia. I understand your goal is to complete an independent penetration test of your SaaS platform and provide an audit-ready report for SOC 2 compliance within your 1-week timeline. I have experience assessing web applications, APIs, authentication systems, role-based access controls, and AWS-hosted environments. My testing approach follows OWASP Web Security Testing Guide and OWASP API Security Top 10 methodologies, with special focus on authorization flaws, IDOR vulnerabilities, privilege escalation, session management, MFA, and token security. For this engagement, I can provide: • External web application penetration testing • API security testing • Authenticated testing across both user roles • Authentication and session security review • Detailed findings with CVSS ratings • Remediation guidance • One retest after fixes • Auditor-friendly attestation letter I am available to start immediately and can commit to the required turnaround timeline. Sample reports and additional details can be shared during discussions. Best Regards, Jordan
$500 USD in 7 days
2.2
2.2

Hi, I can perform an independent penetration test of your SaaS platform aligned with OWASP Web Security Testing Guide and OWASP API Security Top 10 requirements. My approach includes authenticated testing across both user roles, authorization and access control validation, IDOR and privilege escalation testing, authentication flow review, session security analysis, and API assessment. I understand the importance of audit readiness and can provide a professional report including executive summary, methodology, CVSS rated findings, proof of concept evidence, remediation recommendations, retest validation, and an attestation letter suitable for SOC 2 documentation. I am comfortable working under NDA and can begin immediately based on access availability. I have experience assessing modern web applications built with Django, REST APIs, React based frontends, cloud hosted environments, and identity management systems. Could you confirm whether testing will be conducted against a staging environment or production, and whether test accounts for both user roles with MFA enabled will be provided? Regards, Shabahat.
$500 USD in 7 days
3.9
3.9

Hi there! Creating clean, separate SVG map regions requires precision so each outline remains scalable, lightweight, and easy to style or animate with CSS or JavaScript. The key is keeping paths simple and properly segmented without losing geographic clarity. I have experience working with SVG graphics, vector design, and interactive web visualizations where shapes need to be optimized for styling and scripting. I’ve created custom SVG maps and UI components used in dashboards and web applications with clean structure and reusable vector paths. My approach will be to extract or redraw the five required regions as simplified, optimized vector outlines and export each as an individual SVG file. I will ensure clean path data, proper grouping, and minimal metadata so the files are easy to integrate and manipulate with CSS/JS. I can also maintain consistent scaling and alignment across all regions for seamless use in your project. check our work https://www.freelancer.com/u/ayesha86664 Do you already have the exact five regions defined, or would you like help selecting clear geographic boundaries for consistency? Let me know if you’re interested & we can discuss it. Best Regards Ayesha
$450 USD in 6 days
2.0
2.0

Hi! This is a well-defined SOC 2-focused penetration testing engagement and aligns closely with my experience assessing modern SaaS platforms built on React, Django, Keycloak, and AWS. I can perform a comprehensive external web application and API assessment following OWASP WSTG and OWASP API Top 10 methodologies, with particular focus on authorization flaws, IDOR, privilege escalation, authentication flows, token security, and MFA controls. I understand the importance of delivering an audit-ready report, remediation validation, and an attestation letter within your required timeline. Before finalizing the fixed-price estimate, I would like to review the application scope, target count, and testing environment details to ensure complete coverage. I am available to start immediately and would welcome the opportunity to discuss the engagement further.
$250 USD in 7 days
2.0
2.0

Hi! My name is Marjan and I'm here to offer you my services as a skilled applicant with over a decade of experience working on Freelancer.com. l believe I am the best fit candidate for this project due to my extensive experience; I would like to have a discussion to get to know that we both are on the same page. Once the scope will be locked, I will start working on it right away.
$250 USD in 7 days
1.4
1.4

Hi, There. I have carefully reviewed your project requirement for an independent third-party penetration test of your production SaaS platform to meet SOC 2 control standards. With my extensive experience in conducting penetration tests and holding certifications like OSCP, I am well-equipped to deliver a professional and audit-ready report within your tight timeline. I understand the critical need to ensure the security and integrity of your customer-facing web application, backend services, and authentication mechanisms. My focus will be on identifying vulnerabilities in the web application and API, as well as conducting thorough authenticated testing across different user roles to address authorization and access control concerns. Given my track record in similar SOC 2 engagements, I am confident in my ability to provide you with a comprehensive penetration test report that meets regulatory requirements. Additionally, I can commit to delivering a scalable and responsive solution to address any security gaps identified during testing. One question I have is: Would you prefer the testing to be conducted on a production-mirrored staging environment or directly on the production system? Let's discuss this further. Thank you. Filip
$500 USD in 7 days
1.1
1.1

We provide detailed vulnerability assessment and technical review of existing security controls for all targeted systems and assets are provided with this service. in the assessment, our team will present a comprehensive vulnerability report, logical network connection drawing, complete cyber asset inventory and recommended mitigation actions. We completed SOC2 Assessnebt fir 50+ Clients. What will you get with this project? - Full assessment report with all vulnerabilities, recommendation, test cases and Observations in detail. - Kindly contact me to get a sample report. Waiting for your reply for further discussion. Thanks & Regards, Keyur
$500 USD in 7 days
0.6
0.6

Cape Town, South Africa
Payment method verified
Member since May 1, 2026
$30-250 USD
$10-30 USD
$10-30 USD
$750-1500 USD
$250-750 USD
₹12500-37500 INR
₹12500-37500 INR
$8-15 USD / hour
$10-30 USD
$30-250 USD
₹12500-37500 INR
₹1500-12500 INR
₹750-1250 INR / hour
$25-50 USD / hour
$30-250 USD
$10-30 USD
$10-30 AUD
$10-30 USD
$250-750 USD
€3000-5000 EUR
₹75000-150000 INR
₹12500-37500 INR
$10-30 USD
₹12500-37500 INR
₹1500-12500 INR