
Closed
Posted
Paid on delivery
I’m preparing Land Connect Hub—a MERN-based application running on AWS—for production and need a thorough security health-check before launch. The system stores highly sensitive data: user profiles, identity-verification documents, land and genealogy records, service requests, subscription details and, soon, payments through the Bank of the Cook Islands TakuEcom gateway. Because of that breadth, I want an independent professional to combine penetration testing with a full architectural review. What I expect you to cover • Front-end React app, Node/Express APIs and MongoDB queries • Identity workflows, role management and administrator privileges • File handling in S3, object-level permissions, encryption at rest/in transit • TakuEcom payment flow and webhook handling • IAM policies, network configuration, logging, monitoring, backup and recovery strategies Please follow recognised standards such as OWASP Top 10, ASVS and relevant CIS Benchmarks, blending automated scans with manual exploitation techniques to surface logic flaws. Testing must be non-destructive and coordinated so my staging environment remains stable. Deliverables • Executive summary for non-technical stakeholders • Detailed technical report: findings, CVSS rating, reproducible proof-of-concept steps and concrete remediation guidance • Prioritised remediation roadmap • Optional retest after fixes (quote separately) Add a brief outline of your methodology, sample report pages and realistic turnaround time when you reply. I’ll provide staging credentials and a signed NDA before work starts.
Project ID: 40664822
103 proposals
Remote project
Active 1 day ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
103 freelancers are bidding on average $2,210 AUD for this job

Hi — Elias here from Miami. I understand this is a pre-production security review for a sensitive MERN/AWS platform, so the goal is not just finding obvious vulnerabilities but validating the full trust model around identities, documents, permissions, payments, and cloud infrastructure. What usually matters most here is combining application testing with architecture review. I’d assess React/Node/MongoDB flows against OWASP Top 10 and ASVS, then review RBAC, admin escalation paths, IDOR, file uploads, S3 object access, IAM, encryption, secrets, logging, backups, and network exposure. TakuEcom would be reviewed separately for server-side verification, webhook authentication, replay protection, and idempotency. My methodology would combine code/config review, automated scanning, manual API testing, authorization testing, business-logic abuse cases, and non-destructive validation in staging. Findings would include CVSS severity, evidence, reproducible steps, impact, and specific remediation guidance. I’ve worked with MERN, AWS, S3/IAM, payment integrations, RBAC, secure APIs, and production hardening. A few questions to better understand the scope: Q1 – Is infrastructure managed through Terraform/CloudFormation or manually? Q2 – Will source-code access be included, or black-box testing only? Q3 – Is TakuEcom already integrated in staging? I can also provide sample report pages and quote the retest as a separate milestone. Looking forward to hearing from you.
$2,250 AUD in 7 days
7.6
7.6

I am a cybersecurity professional with extensive experience in performing penetration tests and architectural reviews for web applications and APIs, particularly those using AWS and the MERN stack. I specialize in identifying vulnerabilities within complex systems, ensuring highly sensitive data remains secure. My background includes working with payment systems and identity verification workflows. I have conducted comprehensive security assessments utilizing tools such as Burp Suite, Metasploit, and Nmap, alongside manual techniques aligned with OWASP Top 10 and ASVS standards. My proficiency extends to evaluating IAM policies, S3 configurations, and encrypted communication protocols. I have prior success in securing applications with similar data sensitivity and complexity, which I can demonstrate through fully-documented case studies. I would like to discuss your requirements further to tailor a precise action plan and methodology fit to your needs. Could you share any specific concerns or past security incidents that might guide our focus during the assessment? I am open to providing sample report excerpts and a detailed timeline for this engagement.
$3,000 AUD in 20 days
6.7
6.7

Hi, — this is a production-readiness security review on a MERN application in AWS with sensitive identity and land records, so the work is less about running scanners and more about validating trust boundaries end to end. The real engineering risk is authorization drift across identity workflows, object access, and payment state changes, where a system can look secure at the perimeter but still fail at record-level controls and webhook handling. I usually structure reviews like this by separating application logic, storage exposure, and cloud control-plane concerns, then tracing how data moves through React, Node/Express APIs, MongoDB access patterns, and S3-backed document flows. That approach is what keeps findings actionable instead of producing a generic vulnerability dump. The closest work in my background is Custom Feature Development & Integration, where I stepped into an existing live codebase, performed a technical walkthrough, and mapped database and core-function risks before implementation. Squarespace Checkout Streamlining for Meal Service -- 2 is also relevant on transaction-flow validation and failure-path control. I would start by sketching the authz matrix, object access model, and payment event lifecycle so testing stays non-destructive and staging remains stable. Thanks, Hercules
$2,250 AUD in 7 days
6.4
6.4

Hi, I'm Denis, and I understand you're looking for a thorough security review of Land Connect Hub before its production launch. Given the sensitivity of the data—user profiles, identity documents, land records, and soon payment data through TakuEcom—I’ll focus on both penetration testing and architectural review to uncover vulnerabilities while keeping the staging environment stable. My approach blends automated OWASP ASVS-aligned scans with manual exploitation to test logic flaws in the MERN stack, particularly around role-based access, S3 permissions, and IAM configurations. For the payment flow, I’ll examine the TakuEcom integration, webhook handling, and data transmission security. The goal is a non-destructive assessment that provides actionable remediation steps, prioritized by risk, along with a clear executive summary. I’ve worked on similar systems where sensitive data required strict access controls and seamless third-party integrations, ensuring both security and operational reliability. I can start working right away. Let's connect and discuss the details. Thanks, Denis.
$1,500 AUD in 15 days
5.8
5.8

Upon reviewing the requirements for your Land Connect Hub application security health-check, I am well-equipped with MERN stack development, AWS architecture, and security best practices to conduct a comprehensive assessment. Using recognized standards such as OWASP Top 10 and CIS Benchmarks, I will cover all critical aspects including front-end, APIs, MongoDB, identity workflows, file handling, payment flow, and IAM policies. I will follow a systematic approach involving vulnerability scanning, penetration testing, and architectural review to provide you with an executive summary, technical report with CVSS ratings, remediation guidance, and a prioritized roadmap. Testing will be non-destructive to maintain staging environment stability. Delivering actionable insights and continuous support, I aim to establish a strong security posture for your application. I am open to a retest after fixes for a long-term partnership. Once you provide staging credentials and NDA, we can initiate the security assessment process promptly. Your trust is appreciated, and I am eager to contribute to the success of your Land Connect Hub project.
$2,700 AUD in 5 days
5.9
5.9

Hi, The priority here is establishing whether Land Connect Hub is genuinely production-ready, not simply producing an automated vulnerability scan. I can perform a coordinated, non-destructive assessment across the React frontend, Node/Express APIs, MongoDB access patterns and AWS environment, using OWASP Top 10/ASVS and relevant CIS guidance. I would pay particular attention to authentication and authorization boundaries, admin privilege escalation, IDOR/API access control, S3 document exposure, IAM, secrets, encryption, webhook trust and payment-flow manipulation. I’ll combine automated discovery with manual validation and business-logic testing against staging, with agreed testing windows and safeguards to avoid disrupting the environment. You’ll receive an executive summary plus a technical report containing severity/CVSS, reproducible evidence, remediation guidance and a prioritized remediation roadmap. I can also provide sample report pages before award/NDA where appropriate. I can start after NDA, written authorization, scope confirmation and staging access.
$2,400 AUD in 7 days
5.7
5.7

You're building Independent AWS, MERN Web Application and API Cybersecurity Penetration Test, where the real delivery risk is usually in the workflow details, not just the feature list. I've handled similar builds involving Linux, Cloud Computing, Azure, Amazon Web Services, usually where the important part was translating the brief into a reliable working system. My approach would be to first audit the current pages for trust, hierarchy, navigation, and conversion friction, then provide prioritized fixes that can be applied without unnecessary rebuilds. For this project, I would focus especially on: - Page hierarchy, trust signals, navigation clarity, and visual consistency - Typography, spacing, color usage, and modern UI patterns - Practical redesign recommendations ranked by effort and impact If helpful, I can start with a short audit of the homepage and key trust issues before any redesign work. Best, Dr. Syafiq
$2,250 AUD in 21 days
5.9
5.9

Being an AWS-certified professional with a track record of over five years, I believe I possess the necessary skillset to take on your crucial project. My proficiency in backend development including Node.js, Python, and PHP aligns perfectly with your MERN stack. Additionally, my expertise in security and compliance with frameworks such as HIPAA, PCI-DSS ensures that your highly sensitive Land Connect Hub data is protected at all times, as outlined in the project description. Drawing from my extensive knowledge of AWS and Kubernetes orchestration, I can not only carry out penetration testing but also provide you with actionable remediation guidance. Furthermore, my experience in utilizing both automated scans and manual exploitation techniques effectively analyzes system vulnerabilities while maintaining the stability of your staging environment impeccably. In terms of reporting, you can expect a comprehensive executive summary for non-technical stakeholders along with a detailed technical report that includes findings, CVSS rating, reproducible proof-of-concept steps and a prioritized remediation roadmap. If needed, I'm open to conducting a retest after fixes (provided separately). As an independent professional familiar with working under stringent confidentiality conditions, rest assured that I will respect your NDA terms. So let's power up your cybersecurity game using my expertise in AWS, Terraform, Docker, Kubernetes, Jenkins and more!
$3,000 AUD in 7 days
5.5
5.5

Hello! @Project@ I understand you need a comprehensive cybersecurity penetration test and architecture review for your Land Connect Hub MERN application on AWS, which handles sensitive data. @Why I'm a good fit@ With extensive expertise in penetration testing, cloud security, and full stack development including Node.js and MongoDB, I have spent the last several years addressing complex security concerns and architectural assessments in cloud environments similar to yours. I am well-versed in standards like OWASP Top 10, ASVS, CIS Benchmarks, and conducting automated as well as manual testing to uncover vulnerabilities without disrupting operations. I'm ready to start working immediately. Thanks!
$2,000 AUD in 8 days
5.2
5.2

As an experienced Full Stack Developer with specialization in MERN and Node.js, I am confident in my ability to deliver the independent professional service you need for your Land Connect Hub application. With over 5 years of experience, I have developed projects with similar backend structures utilizing Node.js and MongoDB that align with your project requirements. Moreover, my proficiency in front-end framework React.js guarantees a comprehensive penetration test of your entire application. Another key strength I bring to the table is my knowledge of system architecture and security measures, particularly on AWS. Not only have I developed applications on AWS but I also carried out security checks for many sensitive systems, adhering to industry standard guidelines such as OWASP Top 10, ASVS and relevant CIS Benchmarks. I'm keenly aware of the importance of your data protection and can assure you a non-destructive testing procedure ensuring your staging environment's stability. My past clients have lauded me for my clear communication, on-time delivery, clean code, and detailed reports. This assures you won't just receive a comprehensive report outlying the vulnerabilities but also be given concrete remediation guidance and a prioritized roadmap to address them effectively. So let's ensure the safety of your application together!
$2,250 AUD in 7 days
5.3
5.3

Land Connect Hub needs more than a scanner run before production: the MERN application, AWS architecture, sensitive identity/land records, and upcoming TakuEcom payments need an independent, non-destructive assessment. I will test the React surface, Node/Express APIs and MongoDB access paths against OWASP Top 10 and ASVS, combining authenticated automated discovery with manual checks for broken access control, IDOR, privilege escalation, session/token weaknesses, injection, rate-limit gaps, and business-logic flaws in identity and administrator workflows. I will also review S3 upload/download permissions, encryption and presigned URLs; IAM least privilege, VPC/security groups, secrets, CloudTrail/CloudWatch coverage, backups and recovery; plus TakuEcom callback signature validation, replay protection, payment-state handling and webhook authorization. Testing will be coordinated against staging with agreed boundaries, safe payloads and no destructive actions. Within 6 days of receiving NDA/access, you will receive an executive summary, detailed findings with CVSS, reproducible PoC evidence and remediation guidance, a prioritized roadmap, and redacted sample report pages showing the reporting format. A focused retest can be scoped separately after fixes. Is the TakuEcom gateway and its webhook endpoint already available in staging, or is that integration still pending? Muhammad Saad
$2,450 AUD in 6 days
6.1
6.1

Greetings, It sounds like you need a comprehensive security assessment for your MERN-based Land Connect Hub before it goes live. Given the sensitivity of the data involved, I would conduct a thorough penetration test along with a full architectural review to ensure everything is secure. My approach would integrate both automated scanning and manual testing techniques, following industry standards like OWASP Top 10 and ASVS, to uncover any vulnerabilities, especially in identity workflows, file handling, and payment processes. I will provide an executive summary for stakeholders alongside a detailed technical report that includes findings, CVSS ratings, and clear remediation steps. A prioritized roadmap will help you tackle issues efficiently. Rest assured, the testing will be non-destructive, keeping your staging environment stable throughout the process. Best regards, Saba Ehsan
$1,700 AUD in 6 days
4.7
4.7

Your requirement for a comprehensive security assessment of your MERN stack application, Land Connect Hub, on AWS resonates strongly with my recent engagement where I identified critical vulnerabilities in a similar cloud-native financial services platform. My approach will mirror that success by combining automated scanning with deep manual analysis to uncover both known and novel threats. I will employ a multi-layered testing methodology. This includes OWASP Top 10 vulnerability scanning across your React front-end and Node/Express APIs, coupled with in-depth analysis of MongoDB queries for injection flaws. I will also conduct an architectural review of your AWS infrastructure, focusing on IAM policies, security group configurations, and S3 bucket permissions, leveraging tools like Burp Suite, Nmap, and custom scripts for targeted checks. Given the sensitive data handled by Land Connect Hub, have you established specific compliance requirements (e.g., GDPR, PCI DSS) that should guide the penetration test scope? Additionally, are there any particular areas of the application you are most concerned about from a security perspective? I'm eager to discuss how my expertise can ensure Land Connect Hub is production-ready.
$2,512 AUD in 21 days
4.7
4.7

With my extensive background in designing and building complex systems, I am confident I can provide the comprehensive security review your MERN-based application on AWS requires. Not only have I honed my skills in front-end React applications and Node/Express APIs like you utilize, but I also specialize in MongoDB queries, a crucial component for your sensitive data storage. My familiarity with major cloud services such as Azure comes as an added advantage for assessing your AWS environment. Regarding security, I adhere to industry-recognized standards like OWASP Top 10 and ASVS. My methodology embraces a blend of automated scans and manual techniques to ensure that critical logic flaws are surfaced effectively. Additionally, I am well-versed with CIS Benchmarks which will be central for addressing any architectural issues that may arise during testing. Betraying your trust and potentially damaging your staging environment is not an option for me. Hence, my approach emphasizes non-destructive testing and careful coordination throughout the process. With regard to deliverables, you can count on thorough executive summaries, detailed technical findings reports with CVSS rating, proof-of-concept demonstration and actionable remediation guidance alongside a prioritized roadmap of fixes. Let me prove I'm the right pen tester for you by granting me the opportunity to strengthen the walls of your system before launch!
$2,250 AUD in 7 days
4.8
4.8

Hi, I'm Wasif Muneer M. — 5/5 over 33 reviews, Freelancer member since 2011-12-11. I specialize in Linux, Cloud Computing, Azure, Amazon Web Services. I've delivered similar work including LammHub UAE — enterprise web platform and SIEM Solution — security monitoring and ELK stack. For your project "Independent AWS, MERN Web Application and API Cybersecurity Penetration Test", I can help with the full stack delivery using the technologies you've listed, with clear milestones and on-time delivery (98% on-time track record). A couple of questions: 1. What is your preferred tech stack/version for any legacy components? 2. What does success look like for the first milestone? Happy to discuss scope here on the platform. Looking forward to working together. Best regards, Wasif Muneer
$2,250 AUD in 7 days
4.6
4.6

Hi there, Hope you are doing well I’d be happy to conduct an independent AWS, MERN application, API, and infrastructure penetration test for Land Connect Hub before production launch. Given the sensitivity of identity documents, land/genealogy records, subscriptions, and payment integrations, I’ll combine automated security testing with manual assessment to identify both technical vulnerabilities and business-logic weaknesses. Proposed Methodology 1. Application & API Security OWASP Top 10 / API Security testing React frontend and Node.js/Express APIs Authentication, authorization and session management IDOR/BOLA, privilege escalation and business-logic testing Input validation, injection and rate-limit testing MongoDB query/security review 2. AWS & Infrastructure Review IAM roles, policies and least-privilege configuration S3 bucket/object permissions and file-upload security Encryption at rest/in transit Network/security-group configuration CloudWatch logging, monitoring and alerting Backup and recovery configuration 3. Payment Security Review TakuEcom integration Webhook authentication and validation Transaction integrity and replay/tampering scenarios Payment-status manipulation and authorization checks 4. Security Architecture Review I’ll review the overall application architecture and identify security gaps that may not be discovered through automated scanners alone. Thanks & Regards Dheeraj K.
$1,500 AUD in 15 days
5.1
5.1

For Land Connect Hub, I’d treat the review as two linked tracks: application-layer penetration testing across the MERN stack, and an AWS architecture assessment covering S3, IAM, networking, logging, backups, and recovery. The TakuEcom payment path would get separate attention for webhook authenticity, replay protection, idempotency, and privilege boundaries. My two priorities would be maintainability and integrations. I’d test React/Node/Express/MongoDB flows against OWASP Top 10 and ASVS, review role escalation and IDOR risks around identity and genealogy records, inspect S3 object permissions/encryption, and compare relevant AWS controls against CIS guidance. Findings would be ranked by CVSS and business impact so the remediation roadmap is practical, not just a scanner dump. Methodology: scope confirmation → automated reconnaissance → manual auth/business-logic testing → cloud/IAM review → payment/webhook testing → evidence validation → reporting. Testing would remain non-destructive and staging-safe. Sample report format: Executive Summary → Finding → CVSS → Evidence/PoC → Impact → Remediation → Retest Status. A relevant project is Kingmovers, where I handled webhook-driven CRM/telephony integrations, role-based workflows, WebSockets, notifications, and operational analytics across multiple external systems. Realistic turnaround: about 5-7 business days for the initial review/report, with retesting quoted separately.
$2,250 AUD in 7 days
4.5
4.5

Hi, Aashiq (Ash) here from Cape Town, South Africa. This project instantly caught my eye, so I had to reach out. I see you’re looking for a comprehensive security health-check for your MERN-based application on AWS, especially given the sensitive data involved. With extensive experience in cybersecurity, I have successfully conducted penetration tests and architectural reviews for various applications, ensuring they meet industry standards like OWASP and CIS Benchmarks. I am confident in my ability to identify vulnerabilities and provide actionable remediation strategies. Feel free to ask for samples of my previous work. Based on what you mentioned, here is how we would approach the project: • Perform thorough penetration testing on the front-end and APIs • Review IAM policies and network configurations • Conduct a detailed analysis of file handling and encryption methods • Create a prioritized remediation roadmap based on findings I prioritize clear communication and will ensure you receive a seamless, user-focused solution optimized for performance. Best Regards, Aashiq
$2,700 AUD in 7 days
4.4
4.4

Hello, "Staged OWASP Testing + AWS Architecture Review" - you need a safe pre-production security assessment. I’d test the React/Node/MongoDB attack surface first, then review IAM, S3 access, authentication/roles, webhook handling, network rules, logging and recovery controls. Testing would stay non-destructive, with findings mapped to OWASP/ASVS and CIS guidance where applicable. The report would separate business impact from technical detail, with CVSS scoring, reproducible PoC steps and clear fixes. I’d also include an executive summary and prioritised remediation roadmap, with the retest handled separately. For the sample pages, would you prefer the report formatted primarily for technical developers or for management and auditors? Looking forward to working with you. Artur Giżycki
$1,750 AUD in 5 days
3.9
3.9

I can perform an independent, non-destructive security assessment of your MERN/AWS application, combining automated security testing with manual review and exploitation techniques across the React frontend, Node/Express APIs, MongoDB, S3, IAM, and authentication/authorization workflows. My methodology would follow OWASP Top 10/ASVS and relevant CIS guidance, with particular attention to IDOR/BOLA, privilege escalation, session and identity-verification workflows, file-upload and S3 permissions, API abuse, MongoDB query security, and sensitive-data exposure. I’ll also review the TakuEcom payment integration, including webhook validation, transaction integrity, authentication, and potential replay or manipulation scenarios, while assessing AWS network configuration, IAM policies, encryption, logging, monitoring, backups, and recovery controls. Testing will be performed against staging using safe, controlled techniques designed to avoid data destruction or service disruption. Deliverables will include an executive summary, detailed findings with severity/CVSS, reproducible PoC steps, evidence, remediation guidance, and a prioritized roadmap, with a separate optional retest after remediation. For a typical MERN/AWS application of this scope, I would estimate **5–8 business days** for the initial assessment and reporting, with sample report pages and the detailed testing plan provided before testing begins.
$4,500 AUD in 16 days
4.0
4.0

Kingston, New Zealand
Payment method verified
Member since May 9, 2014
$5000-10000 AUD
$10-30 AUD
$3000-5000 AUD
$30-250 AUD
₹12500-37500 INR
$250-750 USD
$25-50 USD / hour
$250-750 USD
£18-36 GBP / hour
₹600-1500 INR
$25-50 USD / hour
₹12500-37500 INR
₹100-400 INR / hour
₹750-1250 INR / hour
€18-36 EUR / hour
₹1500-12500 INR
₹1500-12500 INR
₹1500-12500 INR
₹12500-37500 INR
$30-250 AUD
$10-30 USD
$10-100000 USD
£250-750 GBP
₹400-750 INR / hour