Website User Data Penetration Test

Employer not named by the sourceRemote

Cyber Security

Apply on the company’s site

Frontier is not the employer and does not collect applications.

About this role

Web Security, Compliance, Penetration Testing, Network Security, Risk Assessment, Data Protection, API Testing, Security Auditing · I’m looking for a seasoned security tester to run a true penetration test against the parts of my site that store and expose user data—databases, profile endpoints, related APIs, and any file-storage buckets. The goal is to gauge how hard it would be for an attacker to compromise personal information, document every weakness you can reproduce, and give me clear, actionable fixes.

Scope • Only user-data storage and its access paths are in scope; payment and login flows have already been handled elsewhere. • Black-box and grey-box techniques are both acceptable as long as they remain non-destructive.

What I expect as deliverables 1. A concise executive summary that a non-technical stakeholder can absorb in minutes. 2. A technical report detailing each finding, its CVSS (or similar) score, proof-of-concept steps, screenshots or packet captures, and recommended remediation. 3. A short debrief call or written Q&A to walk through critical issues.

You’re free to use the standard toolkit—Burp Suite, OWASP ZAP, Kali Linux scripts, custom exploits—so long as you respect the site’s uptime and the data of real users. All testing must remain within legal and ethical boundarie