
Closed
Posted
Paid on delivery
is seeking an experienced web application security specialist to address specific vulnerabilities identified in our recent penetration testing assessment. As a healthcare technology company specializing in innovative oral health monitoring solutions, we prioritize robust security standards and regulatory compliance. This is a focused, short-term engagement to remediate six specific security findings in our web application infrastructure. We need an independent contractor who can take full ownership of implementing these security fixes efficiently and professionally. Scope of Work - Specific Vulnerability Remediations Based on our completed Web Penetration Testing assessment, you will address the following security findings: 1. Concurrent Login Management Implementation • Task Type: Application code modification • Requirement: Implement session management mechanism to control concurrent user logins • Options to consider: • Invalidate previous sessions upon new login • Limit active sessions per user account with admin controls • Provide configurable session policies • Deliverable: Production-ready code with comprehensive testing 2. Server Version Disclosure Prevention • Task Type: Server configuration • Requirement: Remove/mask server version information from HTTP responses • Scope: • HTTP response headers (Server, X-Powered-By, framework headers) • Error pages and default framework responses • API endpoints • Validation: Confirm remediation using security scanning tools 3. Vulnerable Framework/Component Upgrade • Task Type: Dependency management and testing • Requirement: Identify and upgrade vulnerable frameworks/libraries to secure versions • Process: • Audit current dependency versions • Plan upgrade path ensuring backward compatibility • Implement upgrades with thorough regression testing • Document all changes and migration steps 4. SSL/TLS Security Hardening • Task Type: Infrastructure configuration • Requirement: Strengthen TLS configuration and eliminate weak ciphers • Scope: • Disable TLS 1.0/1.1 and weak cipher suites • Implement strong, current best-practice cipher configurations • Configure secure SSL/TLS settings on load balancers/web servers • Validation: SSL Labs assessment showing improved security grade 5. Admin Portal Access Control • Task Type: Network security implementation • Requirement: Secure admin portal access behind VPN or equivalent protection • Options: • VPN implementation (OpenVPN, WireGuard, or cloud-native solutions) • IP allowlisting with proper access controls • Zero-trust network access implementation • Deliverable: Secure access solution with documented procedures 6. Open Ports Security Audit • Task Type: Network security assessment and hardening • Requirement: Review and secure network port exposure • Process: • Comprehensive port scan and service audit • Close unnecessary open ports • Implement proper firewall rules and security group configurations • Document justified open ports with security rationale Required Qualifications Essential Experience: • 3+ years in web application security and DevOps/infrastructure security • Proven track record with penetration testing remediation projects • Strong understanding of OWASP security principles • Experience with secure session management and authentication systems • SSL/TLS configuration and certificate management expertise • Network security implementation (firewalls, VPNs, access controls) • Healthcare sector experience strongly preferred Soft Skills: • Ability to work independently with minimal supervision • Clear communication for technical documentation and progress updates • Understanding of healthcare compliance requirements (HIPAA awareness beneficial) Deliverables Technical Implementation: • All security fixes implemented and tested in staging environment • Code changes submitted via pull requests with comprehensive documentation • Infrastructure configuration changes documented and version-controlled Documentation Package: • Detailed remediation report for each vulnerability • Technical documentation of all changes implemented • Updated operational procedures for secure admin access • Security testing evidence and validation reports Knowledge Transfer: • Brief handover session with our development team • Best practices documentation for maintaining security standards • Recommendations for ongoing security monitoring Timeline and Budget • Start Date: Immediate • Engagement Type: Fixed-price contract What We Provide · Complete penetration testing report with detailed findings · Access to staging environment and source code repository · Direct communication with our CTO and DevOps team · Necessary infrastructure access through secure channels · Clear requirements and prompt feedback on deliverables
Project ID: 40188197
11 proposals
Remote project
Active 2 mos ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
11 freelancers are bidding on average ₹14,818 INR for this job

Hi there, I’ve reviewed your security testing needs and would be glad to assist. With 10+ years of experience in VAPT, vulnerability assessment, and web/app security testing, I help identify and fix critical security flaws before they become threats. You’ll get a detailed report, practical remediation steps, and complete confidentiality — following OWASP and industry best practices. Let’s connect to secure your application the right way! Best, Bhargav Security Specialist | VAPT & AppSec | 10+ Years Experience
₹12,000 INR in 3 days
6.4
6.4

Hi there, I’m confident in addressing your six critical web application security vulnerabilities based on your detailed penetration test findings. With over 7 years in web app and infrastructure security, especially for sensitive healthcare environments, I will deliver a secure, compliant remediation. - Implement robust concurrent login controls with tested, production-ready code - Harden SSL/TLS configurations and upgrade vulnerable dependencies - Secure admin portal access via VPN or zero-trust network controls - Audit and tighten network port exposure with firewall rules - Remove server version disclosures and document all changes thoroughly **Skills:** ✅ Web Application Security & OWASP standards ✅ SSL/TLS security hardening & certificate management ✅ VPN & Network Access Controls implementation ✅ DevOps workflows & Git-based code review ✅ AWS cloud & infrastructure security optimization **Certificates:** ✅ Microsoft® Certified: MCSA | MCSE | MCT ✅ cPanel® & WHM Certified CWSA-2 I’m ready to start immediately to ensure your healthcare tech platform meets the highest security standards with full documentation and knowledge transfer. Which web application frameworks and tech stack components are currently in use for your platform to plan precise upgrade paths? Best regards,
₹12,500 INR in 15 days
5.3
5.3

Certified AWS Solutions Architect Professional Certified AWS Solutions Architect Associate CISA Certified Security Expert 16+ Years of Industry Experience in Web Security, Compliance & Risk Management I’m excited about the opportunity to support your healthcare technology organization in remediating the six critical vulnerabilities identified in your recent penetration testing assessment. With 16+ years of experience in web application security, DevOps, and compliance-driven infrastructure, I specialize in delivering production-ready fixes aligned with OWASP best practices and regulatory standards. How I Can Help: I will implement secure concurrent session controls, prevent server version disclosure, upgrade vulnerable frameworks, harden SSL/TLS configurations to eliminate weak ciphers, secure your admin portal behind VPN/IP allowlisting, and conduct a full open-port security audit with firewall and security group hardening. Deliverables include tested staging implementations, pull-request based code changes, detailed remediation documentation, validation reports (SSL Labs, scanners), and a smooth knowledge transfer session with your team. Availability: 8 hours/day and available 24*7 for discussion. Looking forward to helping you strengthen your application security efficiently. SHD
₹12,500 INR in 7 days
5.2
5.2

Our skills go beyond just cybersecurity, we are conceptually sound and are certified AWS Pro Solutions Architect capable in leveraging cloud capabilities proactively. Armed with this arsenal, we are confident in addressing vulnerabilities: 1. Sitting comfortably with OWASP, we shall implement session management mechanisms (including concurrent login controls) effectively. 2. Masking HTTP response headers and undertaking API endpoint-based disclosure prevention to validate remediation drawn via security scanning tools 3. Amongst our host of proficiencies include dependency management and testing which includes framework/component upgrades. We'll provide thorough regression testing, documenting changes for seamless migration 4. HTTPS/SSH Infra Hardening is a specialization for us. Ditching the weak cipher suites, disabling older TLS versions while implementing newer SSL/TLS configs is our domain. 5. Network Security holds no mystery for us! We can flawlessly channel your Admin portal access behind VPN or equivalent protection system, ensuring precisely justified granular access determinants. 6. Our sharp eyes can scrutinize ports maintaining your firewall rules and security group configurations according to demand and document all Justified ports with complex rationale. Let's help you finally rest firmly on that impenetrable cybersecurity platform you deserve!
₹70,000 INR in 5 days
2.8
2.8

Hi, I’m a DevOps and application security engineer with 3+ years of experience remediating penetration-testing findings in production systems. I can take full ownership of fixing the six identified vulnerabilities with secure, auditable, and production-ready implementations. My approach: Implement robust concurrent session controls with configurable policies and testing Remove all server/framework version disclosures from headers, APIs, and error responses Audit and upgrade vulnerable dependencies with regression validation and documented migration steps Harden SSL/TLS by disabling weak protocols/ciphers and validating via SSL Labs Secure admin access using VPN or IP allowlisting with clear operational procedures Perform port and firewall audits, closing unused ports and documenting required exposure All fixes will be tested in staging, submitted via clean pull requests, and fully documented for audit and compliance review. I’m comfortable working independently and providing clear remediation reports, validation evidence, and a short handover session for your team. Estimated delivery: 7–10 days Proposed budget: ₹8,500 (fixed price, negotiable)
₹8,500 INR in 8 days
1.7
1.7

Hi, I am a security specialist with 4+ years in web application security and DevOps, including healthcare (HIPAA) projects. I can take full ownership of remediating your six vulnerabilities, ensuring compliance and robust protections. My approach: 1. Prioritize by risk: Admin portal access (VPN/zero-trust) and framework upgrades first. 2. Implement fixes in staging, validate with tools (SSL Labs, scanners), then deploy via your CI/CD. 3. Deliver clear documentation and a handover session. Estimated work period: 2–3 weeks for complete remediation, testing, and documentation. Key questions for you: 1. Can you share the penetration test report (redacted) and your tech stack details (frameworks, cloud provider, server OS)? 2. What is your current deployment process and staging environment setup for safe testing? 3. For the admin portal VPN, do you have a preferred solution (e.g., OpenVPN, Tailscale, cloud VPN) or existing infrastructure? I am available to start immediately and can provide references from healthcare security engagements. Let’s schedule a brief kickoff to discuss details.
₹12,000 INR in 14 days
0.0
0.0

Hey! Quick check, For concurrent logins: invalidate old sessions on new login (best UX) or strict max-active with admin override? And admin portal: WireGuard VPN tunnel or just IP allowlist + MFA? Suggestion Redis + middleware to kill old sessions on login (super clean UX) + WireGuard VPN + IP whitelist for admin zero-trust, low maintenance, HIPAA-friendly. Relevant experience - Redis session invalidation + max-concurrent limit in telehealth SaaS (HIPAA-aware) - Upgraded critical CVEs (PyPI/npm) with full regression in health-tech apps - A+ SSL Labs (TLS 1.3, ECDHE-GCM, HSTS preload) on 10+ healthcare domains - Secured admin portals with WireGuard + IP restrictions + MFA Plan Staging → reproduce 6 findings → one PR/fix with tests → ZAP/nmap/SSL Labs proof → report. let’s do a quick 10-min call to finalize approach & price. Cheers, Haseeb
₹10,000 INR in 15 days
0.0
0.0

Hello, I’m Ankur, a freelance developer with a dedicated team of professionals. I read all your requirements for website and I assure you that I will provide high-quality work at the proper time. Additionally, we also provide you 3 months of support from our side. As a Full Stack Developer, I specialize in Web and App Development, boasting a portfolio of stunning projects with top-notch UI/UX design. My expertise spans Flutter (for both Android and iOS), PHP, and WordPress, and I bring over 7 years of experience to the table. Whether it’s websites, applications, or e-commerce platforms, I’ve got you covered. But I’m not limited to just coding. My skill set extends to graphic design and logo creation, offering you a one-stop solution for all your project needs. With a track record of over 500 completed projects, I am committed to delivering nothing short of excellence. My ultimate goal is your complete satisfaction. Thank you for considering me for your project. I’m ready to transform your vision into a reality that stands out in today’s competitive landscape. Best Regards, Ankur Hardiya
₹7,000 INR in 7 days
0.0
0.0

I’ve spent the last several years doing exactly this kind of work: taking penetration test findings and turning them into clean, defensible remediations that hold up under audit and real-world scrutiny—especially in regulated environments. My approach is practical and ownership-driven. For session and concurrent login controls, I implement enforceable server-side session policies rather than cosmetic fixes. Version disclosure is handled comprehensively across headers, error handling, and framework defaults, then validated with scanners. Vulnerable libraries are upgraded with a clear compatibility plan and regression testing, not blind version bumps. On the infrastructure side, I regularly harden TLS configurations to current best practice, removing weak protocols and ciphers and validating the result with independent tooling. Admin access is something I take seriously—VPN, IP allowlisting, or zero-trust controls are implemented with operational clarity, not friction. Open ports are audited end-to-end, with unnecessary exposure closed and remaining access clearly justified and documented. I work independently, communicate clearly, and leave teams with both secure systems and confidence in how they’re operated. Happy to discuss your findings and start immediately.
₹10,000 INR in 6 days
0.0
0.0

Delhi, India
Payment method verified
Member since Oct 14, 2021
₹100-400 INR / hour
₹600-1500 INR
₹600-1500 INR
₹400-750 INR / hour
₹600-1500 INR
₹1500-12500 INR
$30-250 USD
₹600-1500 INR
$10-30 USD
$15-25 USD / hour
₹400-750 INR / hour
$250-750 USD
$3000-5000 USD
min €36 EUR / hour
$10-30 USD
₹1500-12500 INR
₹37500-75000 INR
€6-12 EUR / hour
$15-25 USD / hour
$10-80 USD
$30-250 USD
$8-15 USD / hour
₹12500-37500 INR
₹3000-30000 INR
₹12500-37500 INR