Security and compliance engineering · fixed-price first step
Security audit and penetration test
Manual and automated testing of your web application and its infrastructure against the OWASP Top 10 and beyond: authentication and authorization, injection, server-side request forgery, business-logic flaws, secrets and server configuration. I completed the Google Cybersecurity Specialization.
- Timeline
- Agreed per project after scoping
- Price
- Fixed price per scope
- Engagement
- Fixed-price
Is it a fit?
For
- SaaS companies facing their first enterprise security questionnaire
- Fintech and health products handling sensitive personal data
- Teams preparing for SOC 2 or ISO 27001 who want the technical gaps found first
Not for
- Formal certification audits: SOC 2 and ISO 27001 need an accredited auditor, and I help you get ready for one
What you get
- A scoped test plan agreed in writing, with rules of engagement
- Findings rated by severity, each with proof of concept and a fix
- An infrastructure review: IAM, network rules, TLS, headers and secrets
- A retest after your fixes, confirming what's closed
- An executive summary for customers and investors
How it runs
- 01
Scope
Agree targets, accounts, time windows and what's out of bounds, in writing.
- 02
Test
Automated scanning for breadth, then manual testing where the real risks usually hide: access control and business logic.
- 03
Report
Findings with severity, evidence and fixes, walked through with your team.
- 04
Retest
After your fixes, I confirm what's closed and update the report.
Typical stack: Burp Suite · OWASP ZAP · Nmap · sqlmap · Semgrep · Trivy · Wazuh
Questions
Will testing disrupt production?
Testing runs against staging where possible. Where it must touch production, we agree time windows and limits in advance, and destructive tests are never run there.
What does a web application audit cover?
Authentication, session handling and authorization; injection of every kind; server-side request forgery; file handling; secrets; business-logic abuse; and the server and cloud configuration around the app.
Do you offer ongoing monitoring?
Yes. I can set up intrusion detection and log alerting, and review them on a monthly retainer.
Tell me about your project.
A short brief is enough to start. I’ll reply with questions, a suggested first step and when I could begin.