
Closed
Posted
Paid on delivery
I need a CREST-certified professional to carry out a full-scale security review that covers both a vulnerability assessment and a penetration test. The scope spans our public-facing web applications and the core network infrastructure that supports them. The engagement should mirror real-world attack paths: enumerate, exploit, and then verify impact without disrupting production. Tooling is at your discretion—Burp Suite, OWASP ZAP, Nmap, Nessus, Metasploit, or any equivalent platform you prefer—so long as the final evidence is reproducible and mapped to CVSS scoring. Deliverables • Executive summary written in plain language for leadership • Technical report detailing every finding, proof-of-concept steps, screenshots or packet captures, and CVSS scores • Prioritised remediation roadmap with quick wins and longer-term fixes • Closing call or recorded walkthrough to clarify results and next actions All testing must comply with CREST methodology and ethical guidelines. I can provide a letter of authorisation and any necessary whitelisting once dates are agreed. Please outline your estimated timeline, any pre-engagement information you require, and how you prefer to coordinate live testing windows.
Project ID: 40677686
12 proposals
Remote project
Active 4 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
12 freelancers are bidding on average ₹10,292 INR for this job

Hi, I’m an experienced cybersecurity and digital forensics professional with hands-on expertise in vulnerability assessment, penetration testing, web application security, network security, and security reporting. I can conduct a structured assessment of your public-facing applications and supporting network infrastructure, following an attack-path approach while keeping production disruption to a minimum. My approach would include reconnaissance and enumeration, vulnerability identification, controlled exploitation and impact validation, evidence collection, risk assessment, and remediation guidance. I’m comfortable working with tools such as Burp Suite, OWASP ZAP, Nmap, Nessus, Metasploit and equivalent tooling, selecting the right tools based on the environment. Deliverables: Executive-level security summary Detailed technical VAPT report with reproducible evidence, screenshots/traffic evidence and CVSS scoring Prioritised remediation roadmap covering immediate and strategic fixes Final walkthrough/call to discuss findings and remediation Estimated timeline: typically 5–10 business days depending on the number of applications, hosts, and complexity of the infrastructure. I’m available to discuss the scope and provide a clear testing plan before commencement. Best regards, Kajal
₹15,000 INR in 7 days
5.6
5.6

Hello, I can assist with the web application security assessment and reporting side of this project, including vulnerability validation, reproducible findings, CVSS-based prioritisation, and remediation guidance. However, I would not claim CREST certification if it is a strict requirement. If CREST certification is mandatory, I recommend working with a CREST-certified security professional, and I can support the technical implementation/reporting where appropriate. abdullahchandio
₹1,500 INR in 2 days
1.1
1.1

Hi, I’m an experienced penetration tester specialized in network and web application security. I can perform both public web application and internal network security testing, with detailed PoCs where applicable and a clean report covering findings, impact, and practical remediation steps for your development team. Please share the scope and let me know whether you’re looking for a black-box or white-box assessment, and we can get started right away.
₹10,000 INR in 10 days
0.0
0.0

With 7+ yrs exp & 500+ apps tested, I offer proven expertise. Black‑Box (Prod) – 7 days, INR 25,000; Grey‑Box (UAT/Pre‑Prod, 1 role) – 10 days, INR 40,000. +2 days for report, walkthrough & 1 retest. If same env, Grey‑Box covers all BB—no need to pay for BB. CREST methodology guaranteed.
₹25,000 INR in 7 days
0.0
0.0

Available immediately. Text me via Freelancer chat. CEH certified with hands-on experience in full-scale pentesting following CREST methodologies.
₹12,500 INR in 15 days
0.0
0.0

Hello, I am a cybersecurity professional currently pursuing an MSc in Computer Forensics and Cyber Security, with previous experience in a Big Four cybersecurity environment. I have hands-on knowledge of vulnerability assessment, web and network security testing, OWASP methodologies, risk assessment, and professional security reporting. I understand the importance of operating strictly under written authorization and within an agreed testing scope. I can follow a structured methodology to assess the agreed web applications and infrastructure, document validated findings, provide evidence, assign appropriate risk ratings, and recommend prioritized remediation steps. I would require written authorization, defined scope and targets, permitted testing windows, emergency contacts, and any relevant whitelisting arrangements before testing begins.
₹10,000 INR in 10 days
0.0
0.0

Hello, I have worked on many Web applications and Network Infra. You need to specify the scope in a detailed manner but I will surely get this done by 7 days. And also, I have the CREST certified CPSA certificate.
₹11,000 INR in 7 days
0.0
0.0

Hello, I am a cybersecurity professional with experience as an Assistant Manager in cybersecurity audits, having handled 100+ security audits across 15+ regulatory frameworks. I hold CEH, CHFI and ISO 27001 Lead Auditor certifications, with practical experience in security assessment requirements aligned with industry-standard penetration testing and CREST-style methodologies. I understand this engagement requires more than automated scanning. The assessment should cover reconnaissance, enumeration, vulnerability validation, controlled exploitation, impact verification, evidence collection, risk assessment and remediation, while maintaining strict scope and production safety. For web applications and supporting infrastructure, I can work with Burp Suite, Nmap, Nessus, OWASP ZAP and Metasploit as appropriate. Findings will be manually validated wherever possible and documented with reproducible evidence, business impact and CVSS scoring. Before testing, I would require the authorised scope, target inventory, exclusions, credentials where applicable, testing windows, rate limits and emergency contacts. I will coordinate testing carefully to minimise any impact on production. I would be happy to discuss the scope, methodology and timeline and align the engagement with your security requirements.
₹7,000 INR in 15 days
0.0
0.0

I’m interested in helping with your authorized security assessment. I have completed formal training in ethical hacking and can assist with a structured vulnerability assessment of your web applications and network infrastructure. I can work with tools such as Nmap, Burp Suite, OWASP ZAP, Nessus and SQLMap, with testing limited strictly to the scope and authorization you provide. My approach would cover reconnaissance, vulnerability identification, controlled validation, evidence collection, risk/CVSS assessment, and clear remediation recommendations. I can provide a professional report containing an executive summary, technical findings, supporting evidence, severity ratings, and a prioritized remediation roadmap. Before beginning, I would request the Letter of Authorization, in-scope IPs/domains, testing window, whitelisting requirements, test accounts (if required), and prohibited activities so that testing can be performed safely without disrupting production. I’m happy to discuss the scope and prepare a testing plan based on your requirements.
₹7,000 INR in 7 days
0.0
0.0

Hi, I can help with the VAPT assessment of your web applications and supporting network infrastructure. I have hands-on experience in Web, API and security testing, including vulnerability identification, validation, PoC development, CVSS-based risk assessment, and detailed security reporting. I can provide a clear executive summary, technical findings with reproducible PoCs and evidence, prioritized remediation recommendations, and a walkthrough of the results. I am also comfortable coordinating testing windows, working with whitelisting requirements, and following an authorized and non-disruptive testing approach. I’d be happy to discuss the scope, required access, and timeline before starting.
₹8,000 INR in 7 days
0.0
0.0

Bengaluru, India
Member since Oct 21, 2023
₹12500-37500 INR
₹1500-12500 INR
₹1500-12500 INR
₹12500-37500 INR
₹1500-12500 INR
₹1500-12500 INR
₹1500-12500 INR
$15-25 USD / hour
₹37500-75000 INR
₹1500-12500 INR
₹750-1250 INR / hour
$10-30 USD
₹600-1500 INR
$10-30 USD
£18-36 GBP / hour
₹12500-37500 INR
₹400-750 INR / hour
₹1500-12500 INR
$30-250 USD
₹750-1250 INR / hour
₹75000-150000 INR
₹750-1250 INR / hour
₹600-1500 INR
$250-750 USD
₹100-400 INR / hour