Harden SOAP API Access Control

Employer not named by the sourceRemote

Full StackCyber Security

Apply on the company’s site

Frontier is not the employer and does not collect applications.

About this role

PHP, Web Security, Computer Security, Internet Security, OAuth, Penetration Testing, Incident Response, Security Auditing · I need a security specialist to lock down my publicly facing SOAP API. Right now it is shielded only by Basic Authentication, and I am concerned this is not enough to prevent unauthorized access.

Your first task is to examine the existing endpoints, auth flow, and server configuration, identify every crack that could let an intruder in, and then propose concrete counter-measures. From there, I expect you to implement stronger mechanisms—whether that means WS-Security headers, message-level encryption, mutual TLS, moving to token-based or OAuth authentication, or another proven strategy you can justify.

Please plan to: • Deliver a concise audit report outlining current vulnerabilities. • Apply and test the agreed-upon hardening measures in a staging environment. • Provide step-by-step deployment notes and verification scripts so I can reproduce the setup in production.

I will grant access to the codebase, WSDL, and hosting console as soon as we align on a plan. Success is measured by clean security-scan results and verified denial of unauthorized requests while legitimate traffic continues to flow uninterrupted.