CERT-In Certified Web VAPT

Employer not named by the sourceRemote

Cyber Security

Apply on the company’s site

Frontier is not the employer and does not collect applications.

About this role

Web Security, Compliance, Risk Management, Penetration Testing, Risk Assessment, REST API, Incident Response, Security Auditing · I need a full-scope Vulnerability Assessment and Penetration Test on my custom-built web application, carried out by a CERT-In empanelled tester so that I can obtain the official certificate at the end of the engagement. The primary objective is to strengthen our overall security posture, not just tick a compliance box, so I am looking for a thorough, manual-heavy test that goes well beyond an automated scan. The application is entirely bespoke, with its own authentication flow and several sensitive business modules exposed through REST APIs. You will have access to a staging environment that mirrors production, along with test accounts and any supporting documentation you require.

To make expectations clear, I will consider the engagement complete when I receive: • A detailed VAPT report mapping findings to the latest OWASP Top 10, including reproducible PoC screenshots or request/response dumps. • A risk-rated remediation plan with practical fixes. • A final retest confirming all critical and high findings are closed. • The official CERT-In compliance certificate in my company’s name.

Please outline the methodology you follow (for example, OWASP Testing Guide, PTE