Perform 5-Day Comprehensive Security Review

Employer not named by the sourceRemote

Cyber SecurityFull StackFreelance and contract gigs

Apply on the company’s site

Frontier is not the employer and does not collect applications.

About this role

PHP, Web Security, Testing / QA, MySQL, Mobile App Testing, Encryption, API Testing, Security Auditing · Security Audit – Website & iOS/Android Apps

We are looking for a developer/security specialist to perform a 5-day security review and manual testing of our website, backend and iOS/Android apps.

The work includes:

* Review and test Stripe integration, API keys, webhooks, payments, refunds, chargebacks, MobilePay and Apple Pay. * Review GDPR/security of personal data, access control, encryption, storage and deletion. * Manual review based on OWASP Top 10, including SQL Injection, XSS, CSRF, authentication, authorization and exposed API endpoints. * Test iOS and Android apps, including installation, login, backend communication, payments and data. * Review server/app logs, monitoring, PHP and other system versions. * Identify and report security risks and provide recommendations.

Important requirements:

* All sensitive credentials must be reviewed and, where required, changed/rotated and secured, including API keys, secret keys, webhook secrets, passwords and database credentials. * On Day 1, the freelancer must identify and inform us of all credentials/services that he cannot access and that we need to change or provide access to ourselves. * Access will initially be provided t