
Closed
Posted
Paid on delivery
I’m looking to bring an experienced cyber-security professional on board to review and strengthen the security posture of a web-based application that is already in production. My main need is expert-level security consulting focused squarely on application security—everything from architecture review and threat modelling to practical, step-by-step remediation guidance that my development team can implement right away. Here’s what I’d like to walk away with: • A thorough, hands-on assessment of the current application (code, configurations, third-party integrations, and deployment pipeline). • A concise report outlining discovered issues, their severity, and clear proof-of-concept evidence where relevant. • A prioritized remediation roadmap my developers can follow, complete with recommended controls, secure coding practices, and any tooling you think will speed adoption. I work in an agile environment, so regular check-ins over Slack or similar are welcome, and I’m happy to provide staging credentials and architecture diagrams as soon as we kick off. If you have a proven track record delivering security consulting specifically for web or mobile applications and can translate findings into actionable steps, I’d love to collaborate.
Project ID: 40669278
10 proposals
Remote project
Active 8 hours ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
10 freelancers are bidding on average ₹3,650 INR for this job

Hello, I can help assess and strengthen your production web application with a practical, developer-focused security review. I’ll cover **architecture/threat modeling, authentication & authorization, OWASP risks, API/web security, configurations, third-party integrations, and deployment security**. You’ll receive a clear report with **severity, evidence/PoC where appropriate, root cause, and prioritized remediation steps** your developers can implement immediately. I’m also comfortable working in Agile environments with regular Slack check-ins. I’m ready to review your staging environment and architecture details and get started immediately.
₹3,000 INR in 2 days
2.6
2.6

Hi, Thanks for sharing your project. Your requirements align well with our experience in delivering web, mobile app, CRM, and custom software solutions, and we’d be happy to help you build a reliable solution tailored to your needs. Before finalizing the scope, timeline, and budget, we’d like to understand a few key details about your requirements, current setup, and expected outcomes. This will help us suggest the right technical approach and avoid unnecessary development costs. Let’s discuss the project through Freelancer chat. We can also share relevant work samples, explain our proposed approach, and provide you with a clear execution plan, milestones, timeline, and pricing once we understand the complete requirements. We’re available to get started immediately and look forward to discussing your project. Best regards, Royal IT Services
₹1,000 INR in 7 days
0.0
0.0

Hi, You're asking for architecture review, threat modelling and remediation your developers can act on immediately — that's a scoping-first engagement, not a scan-and-dump. How I'd run it: 1. A 60-minute walkthrough of the application, stack and deployment pipeline so I understand the business logic before I touch anything. 2. STRIDE threat model against your real data flows, trust boundaries and third-party integrations. 3. Manual review mapped to OWASP ASVS and the Top 10 — authentication, session handling, access control and IDOR, input validation, secrets in config and CI. 4. A report where every finding has severity, reproduction steps and proof-of-concept evidence, plus a fix your devs can apply directly. 5. A prioritised remediation roadmap, then a free retest of whatever you patch. Background: 8 years in software QA across manual and automation, including API and SQL validation, now working in application security — web pentest labs, bug bounty research and secure code review. That QA background is exactly why my findings come with clean reproduction steps instead of raw scanner output your team has to triage. Two questions so I can scope this properly: what framework and stack is the application on, and is it single-tenant or multi-tenant? Multi-tenancy changes where I focus the access-control testing. Happy to start with a short call this week. Durgesh
₹600 INR in 7 days
0.0
0.0

Hi, I’d be interested in helping assess and strengthen the security of your production web application. My core expertise is hands-on web application security and manual VAPT, including attack-surface/endpoint mapping, authentication and session management, authorization/BOLA/IDOR, XSS, injection, API security, business-logic testing, and manual validation of findings. For this engagement, I can provide: • Web/API security assessment • Authentication, authorization & session testing • Architecture and threat-modeling review • Configuration and third-party integration review • CVSS/CWE-based severity classification • Reproducible PoC evidence for validated findings • Clear, developer-focused remediation guidance • Prioritized remediation roadmap and retesting recommendations I focus on actionable, manually validated findings rather than simply providing automated scanner output. Findings can include affected endpoints, reproduction steps, impact, severity, evidence, root cause where determinable, and practical remediation. I’m comfortable working with staging credentials, architecture diagrams, API documentation, and development teams in an agile environment. Before starting, I’d like to confirm the application scope, technology stack, endpoints/roles, integrations, and available source-code or deployment access so the assessment can be appropriately scoped. I’d be happy to discuss your application and begin with the initial assessment. Best regards, Neel
₹1,500 INR in 5 days
0.0
0.0

I have experience with security/pen testing of web apps, dealing with safety and optimization of db queries, pbac/rbac systems, route level securities, etc. I would love to help with your web application.
₹1,000 INR in 3 days
0.0
0.0

With 7+ yrs exp & 500+ apps tested, I offer proven expertise. Black‑Box (Prod) – 7 days, INR 25,000; Grey‑Box (UAT/Pre‑Prod, 1 role) – 10 days, INR 40,000. +2 days for report, walkthrough & 1 retest. If same env, Grey‑Box covers all BB—no need to pay for BB.
₹25,000 INR in 7 days
0.0
0.0

You need an actionable security decision document, not a generic scanner dump. I will review the application architecture, authentication and authorization, configuration, third-party integrations, and deployment pipeline; verify high-risk findings with safe proof-of-concept evidence; and deliver a severity-ranked remediation roadmap your developers can implement. At the listed budget, this bid covers a focused initial assessment of the highest-risk application paths and a concise prioritized report. I will confirm exact coverage after reviewing the stack and codebase size, before work begins. Please share the technology stack, deployment model, architecture diagram, and staging access.
₹1,500 INR in 3 days
0.0
0.0

Guwahati, India
Member since Aug 25, 2026
₹12500-37500 INR
₹12500-37500 INR
€250-750 EUR
$10-100000 USD
₹600-1500 INR
£250-750 GBP
₹600-1500 INR
$250-750 USD
₹12500-37500 INR
₹37500-75000 INR
$15-25 USD / hour
$15-25 USD / hour
$250-750 USD
$15-25 USD / hour
₹400-750 INR / hour
$15-25 USD / hour
₹600-1500 INR
₹150000-250000 INR
$30-250 USD
$30-250 USD