
Completed
Posted
Paid on delivery
We require an elite Ethical Hacker / Cybersecurity Compliance Auditor based in Spain (strict network requirement for native Spanish residential IP testing due to government endpoint firewall constraints) to perform a comprehensive Compliance Audit and express penetration test on a containerized Docker application (ATLAS Property OS). STRICT LEGAL & CIBERSECURITY SHIELD FOR THE HOLDING: Before receiving any repository access, documentation, or Docker setup files, the selected candidate MUST strictly sign a comprehensive Ethical Hacking Covenant, a corporate Non-Disclosure Agreement (NDA) with international breach penalties, and a Data Processing Agreement (DPA) complying with European GDPR and Spanish LOPD-GDD regulations. All testing must be conducted within an isolated pre-production staging sandbox environment. Full audit logging and traceability of the auditor's IP actions will be active throughout the session. Absolute data privacy and trade secret protection are non-negotiable. STACK TECH: - Frontend/Backend: [login to view URL] 15 (App Router) - Database: AWS RDS PostgreSQL - Authentication & RBAC: [login to view URL] (Session middleware enforcing multi-tier time locks) YOUR AUDIT & COMPLIANCE TARGETS: 1. Legal & Regulatory Compliance (GDPR / LOPD-GDD): Audit the backend architecture and telemetry systems to certify that user tracking, session caching, and IP logging are 100% compliant with European GDPR and Spanish LOPD regulations. Verify that data pseudonymization (SHA-256) is properly enforced at the API layer. 2. Global Security Standard Mapping (ISO/IEC 27001): Review our cloud infrastructure blueprint mapped against AWS RDS instance configurations to validate that the deployment layout complies with ISO 27001 controls regarding data encryption at rest/in transit, access control monitoring, and log retention. 3. Logic Counter Gating & Core Flaws: Attempt to bypass server-side [login to view URL] middleware countdown restrictions (120h and 72h data locks) via frontend client manipulation, JavaScript console injection, or token spoofing. 4. Vulnerability & Anti-Scraping Assessment: Test server-side Rate Limiting mechanisms against custom automation bots attempting data extraction. Perform deep testing against SQL injections, Cross-Site Scripting (XSS), and Broken Object Level Authentication (BOLA). DELIVERABLE: A technical, comprehensive Penetration Test & Global Compliance Report (PDF) detailing detected vulnerabilities, threat levels, and concrete code-level remediation steps. Once vulnerabilities are patched by our developer, you will sign off our official "Security, GDPR & ISO 27001 Compliance Certificate". Timeline: 48-72 hours once Docker container is deployed on staging this week. Budget: Fixed Price (200€ - 300€). Please post your verification credentials, certifications (CEH, OSCP, CISA or similar), and past auditing experience in Spain. Immediate selection.
Project ID: 40669741
68 proposals
Remote project
Active 2 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs

Hola. Tengo experiencia liderando proyectos de auditoría de cumplimiento y pruebas de penetración, y puedo ejecutar este con el mismo éxito. Entiendo que el requerimiento de auditoría se basa en una serie de regulaciones estrictas y la necesidad de asegurar la conformidad total con GDPR y LOPD-GDD, lo cual es fundamental para proteger los secretos comerciales. Para abordar esto, planeo realizar una auditoría integral del backend y la infraestructura en la nube, asegurando que todos los controles de seguridad estén alineados con ISO 27001 y que las vulnerabilidades se identifiquen y documentan adecuadamente. Es fundamental establecer expectativas claras sobre las pruebas y la documentación que se entregará al final del proceso. ¿Cuál es el proceso para coordinar el acceso al entorno de pruebas y asegurar que se cumplan todas las normativas antes de iniciar la auditoría? Carlos
€350 EUR in 3 days
0.0
0.0
68 freelancers are bidding on average €423 EUR for this job

✋ Hi, this engagement needs to be treated as a formal security assessment rather than a normal application review because the scope combines authorized penetration testing, GDPR/LOPD-GDD controls and ISO 27001 mapping. The technical work should include API and authorization testing around NextAuth, rate-limit and anti-scraping validation, BOLA/IDOR checks, injection and XSS testing, plus review of RDS encryption, access control, logging and retention. The final report should separate confirmed vulnerabilities from compliance observations and include reproducible evidence and code-level remediation guidance. One thing I’d like to confirm is whether you require the selected auditor to personally hold CEH, OSCP or CISA certification and be physically located in Spain for the full testing window?
€410 EUR in 5 days
2.2
2.2

✅✅Hi, there✅✅ As a native Spanish speaker based in Spain, I am well-equipped to conduct the necessary compliance audit and penetration test for your ATLAS Property OS Docker application. I am ready to adhere to all legal requirements, including signing the Ethical Hacking Covenant and NDA. This project aligns perfectly with my skills, and I can deliver the comprehensive report within your 48-72 hour timeline with utmost accuracy. It involves auditing for GDPR/LOPD compliance, mapping against ISO 27001 standards, and testing for vulnerabilities like SQL injections and XSS. I aim to provide you with a thorough assessment that will enhance your application's security and compliance posture. I look forward to the opportunity to collaborate closely to meet your urgent needs. Best regards, Predrag
€300 EUR in 7 days
1.9
1.9

⭐⭐⭐Hello⭐⭐⭐ I am based in Spain and fully equipped to perform the required compliance audit and penetration test on your Docker application while adhering to all legal and cybersecurity regulations. I’m ready to sign the Ethical Hacking Covenant, NDA, and DPA to ensure data privacy and trade secret protection. This project perfectly aligns with my skills, and I can deliver within your specified 48-72 hour timeframe. I have extensive experience in auditing backend architectures for GDPR and LOPD compliance, validating AWS RDS configurations against ISO 27001 controls, and testing for vulnerabilities like SQL injections and XSS. I understand you need a comprehensive report detailing vulnerabilities and remediation steps, along with a compliance certificate upon completion. I am eager to contribute to your project's success and would love to connect further to discuss how I can assist. Best regards, Sararudin
€300 EUR in 7 days
0.0
0.0

Hello, I hope you’re doing well. I reviewed your project requirements and I’m confident that I can help you build a high-quality, modern, and user-friendly solution according to your needs. GDPR-LOPD-ISO-Compliance I’m Ankur, a Full Stack Developer with 7+ years of experience in: • Custom Website Development • E-commerce Development • Mobile App Development • Flutter App Development • Android & iOS Applications • WordPress & PHP Development • UI/UX Design • Admin Panels & APIs I have successfully completed 500+ projects for startups, businesses, and individual clients worldwide. Why work with me? ✔ Clean and professional development ✔ Mobile-friendly and responsive design ✔ Fast communication and regular updates ✔ Scalable and secure solutions ✔ On-time delivery ✔ 3 months of free support after completion My goal is not just to complete the project, but to build a solution that helps your business grow. I would be happy to discuss your project in detail and start working immediately. Looking
€600 EUR in 8 days
0.2
0.2

Hi I can perform a controlled security/compliance audit of your isolated Docker staging environment, covering NextAuth/RBAC logic, API authorization, rate limiting, XSS/SQLi/BOLA, GDPR controls and AWS security mapping, with a detailed remediation report. I can work under your NDA/DPA and provide reproducible evidence and severity-ranked findings. 1. Will the staging environment include a representative test dataset and the required Spanish residential-IP testing access? 2. Do you already have an ISO 27001 control matrix and GDPR/LOPD-GDD processing documentation to use as the audit baseline? Relevant Projects I’ve Worked On: 1. Hospital ERP – full backend and frontend integration 2. Restaurant ERP – POS, order management, and reporting 3. Attendance Management Software – employee tracking and reports 4. Custom Software – tailored solutions for various business processes 5. Website Development – dynamic, responsive websites with CMS and database integration 6. AI chatbot lets connect for qaulity work - already have experience on same its my core work chat or call for more discusion (6 MONTHS EXTRA SUPPORT) lets connect - will start soon (100% satisfaction)
€500 EUR in 7 days
0.0
0.0

⭐⭐ ⭐Hi there⭐ ⭐⭐ I can perform the ATLAS security audit in your isolated staging environment, covering NextAuth bypasses, BOLA/IDOR, SQL injection, XSS, rate limiting, API security, Docker, AWS/RDS, and access controls. I’ll provide a concise PDF report with severity-rated findings, evidence, and practical remediation steps, followed by retesting after fixes. I’m comfortable with strict NDA/DPA requirements, activity logging, and controlled testing boundaries. Available within the requested 48–72 hours once staging is ready. Best regards, Victoria
€500 EUR in 7 days
0.0
0.0

Your money your rules your timeline and I can do it with good quality. Trust me if you want just try one time
€500 EUR in 7 days
0.0
0.0

A Coruña, Spain
Payment method verified
Member since Aug 16, 2026
€250-750 EUR
€750-1500 EUR
₹12500-37500 INR
$30-250 USD
₹1500-12500 INR
$3000-5000 USD
₹1500-12500 INR
min $50 USD / hour
€250-750 EUR
₹30000-80000 INR
$250-750 USD
$15-25 USD / hour
₹5000-9000 INR
$250-750 USD
$25-50 USD / hour
$250-750 AUD
$3000-5000 USD
₹12500-37500 INR
₹12500-37500 INR
$1500-3000 USD
₹1500-12500 INR
$250-750 USD