
Closed
Posted
CyberVault Solutions is preparing for an upcoming client penetration testing engagement and is seeking an experienced penetration tester to lead the external network assessment portion of the project. While the broader engagement may include internal network, web application, and API testing, the immediate focus will be on conducting a thorough assessment of the client’s external-facing environment. What we are looking for: Comprehensive vulnerability discovery and validation Accurate identification of legitimate findings and reduction of false positives Controlled exploitation techniques to safely demonstrate impact without disrupting production services Clear risk prioritization aligned to NIST and CMMC-related security considerations Professional reporting with actionable remediation guidance Retesting and validation support after remediation activities are completed The selected resource should be comfortable working with common penetration testing and security assessment tools such as: Nmap Nessus Burp Suite Metasploit Custom scripts/tooling You are expected to provide and operate your own testing tools and licenses necessary to perform the engagement. Expected Deliverables: Testing methodology and assessment approach aligned to the Rules of Engagement (ROE) Raw and parsed scan output Proof-of-concept evidence for validated findings (screenshots, logs, or session captures) Executive summary and detailed technical findings report with risk ratings and remediation guidance Mapping of findings to relevant NIST and/or CMMC security considerations where applicable Remediation validation and retest results Additional Information: Final scope, timelines, and asset counts will be confirmed once the client finalizes authorization and scoping documentation. Target kickoff is within the next two weeks. Strong communication and documentation skills are required. Ability to collaborate in real-time via Microsoft Teams or Slack is preferred. Prior enterprise or consulting experience is highly preferred. When responding, please include: Relevant penetration testing experience Certifications (OSCP, PNPT, CEH, CISSP, etc.) Sample sanitized reports (if available) Availability and estimated hourly rate Brief overview of your testing methodology Additional Requirements: * All work performed must remain confidential and may require execution of an NDA prior to engagement. * Tester must maintain detailed notes and evidence throughout the assessment. * Preference will be given to candidates with prior experience supporting regulated or compliance-driven environments. * Ability to distinguish between automated scan findings and manually validated vulnerabilities is critical. * Clear communication during testing windows is required, especially for any high-risk or potentially impactful findings. Preferred Experience: * CMMC / NIST 800-171 environments * Microsoft Azure / Entra ID environments * Defender / Sentinel familiarity * API security testing * Active Directory enumeration and privilege escalation * Report writing for executive and technical audiences Important: This is not a simple vulnerability scan engagement. We are looking for an experienced tester capable of performing thoughtful validation, controlled exploitation, and high-quality reporting suitable for professional client delivery.
Project ID: 40435527
12 proposals
Remote project
Active 21 secs ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
12 freelancers are bidding on average $40 USD/hour for this job

Hello, Thank you for the detailed scope. This aligns closely with my experience in enterprise-grade external penetration testing and compliance-focused assessments. I’m Md Shofiur, a Certified Ethical Hacker with 10+ years of experience conducting penetration tests for SaaS platforms, enterprise infrastructure, APIs, and regulated environments. I have performed thousands of assessments globally and specialize in manually validated testing with professional client-ready reporting. Certifications & Experience: CEH (Certified Ethical Hacker) API Security & Web Application Penetration Testing Extensive experience with NIST-aligned assessments Methodology: External reconnaissance & attack surface mapping Vulnerability discovery using Nmap/Nessus plus manual validation Controlled exploitation with Burp Suite, Metasploit, and custom tooling Risk prioritization aligned to NIST/CMMC concepts Detailed evidence collection and remediation guidance Retesting after remediation I focus heavily on distinguishing false positives from legitimate exploitable findings and maintaining safe testing practices during production assessments. Tools: Nmap, Nessus, Burp Suite Pro, Metasploit, custom scripts, Kali Linux toolsets. I’m comfortable collaborating through Teams or Slack and working under NDA/confidential engagements. Availability: Immediate Estimated Rate: $40–$75/hr depending on scope and asset count. A sanitized sample report can be shared upon request. Best regards, Md Shofiur
$50 USD in 40 days
7.0
7.0

With my in-depth experience of over 5 years, I have not only honed my skills but built a commendable reputation working on complex projects like the one you have at CyberVault Solutions. I possess a strong hold over Nmap, Nessusand other tools that align with your requirements coupled with a great deal of expertise in writing concise, action-oriented reports that can be seamlessly integrated into your remediation procedures. I believe that my experience would allow me to carry out comprehensive vulnerability scanning and clearly identify true positives encompassing vulnerability assessments and penetration testing as per your specific needs. As you've expressed your preference for around-the-clock collaboration, I assure you of my ability to maintain reliable communication and fast response times. Be it Slack or Teams, you can count on me! Moreover, owing to my extensive practical experience in network security, software testing, and quality assurance,I am well-versed with the methodology and tools essential for conducting external penetration testing. Rest Assured!
$47.33 USD in 100 days
4.8
4.8

Hello, I'm Rudra Kumar, a seasoned Senior QA Engineer with a strong focus on Quality Assurance and Software Testing. I specialize in conducting comprehensive assessments that include Manual, Automation, API, and Performance testing. Given my vast experience in penetration testing for Websites, Mobile Applications, and Games, I can bring a unique perspective to this project. With the tools you've mentioned such as Nmap, Nessus, Burp Suite, Metasploit, and my understanding of Ethical Hacking principles gained from securing applications across different domains and working on enterprise systems, I'm confident in my ability to discover legitimate vulnerabilities while minimizing false positives. Another key strength is my ability to communicate complex security concepts in clear business terms. This skill is crucial when it comes to preparing accurate reports that not only highlight risk priorities but also provide detailed remediation guidance. My experience working within NIST and CMMR-related security frameworks makes me a great fit for this role. Lastly, I am well-versed in Microsoft Teams and Slack for real-time collaboration during the testing process.
$25 USD in 40 days
4.8
4.8

Arlington, United States
Payment method verified
Member since May 11, 2026
₹600-1500 INR
₹100-400 INR / hour
$250-750 USD
$30-250 USD
₹12500-37500 INR
₹750-1250 INR / hour
₹1500-12500 INR
$8-15 USD / hour
$30-250 CAD
$10-30 CAD
₹12500-37500 INR
$10-100 USD / hour
₹1500-12500 INR
₹12500-37500 INR
$15-25 USD / hour
$10-30 USD
$30-250 USD
$2-8 USD / hour
$2-8 USD / hour
₹100-400 INR / hour