
Closed
Posted
Paid on delivery
is seeking an experienced web application security specialist to address specific vulnerabilities identified in our recent penetration testing assessment. As a healthcare technology company specializing in innovative oral health monitoring solutions, we prioritize robust security standards and regulatory compliance. This is a focused, short-term engagement to remediate six specific security findings in our web application infrastructure. We need an independent contractor who can take full ownership of implementing these security fixes efficiently and professionally. Scope of Work - Specific Vulnerability Remediations Based on our completed Web Penetration Testing assessment, you will address the following security findings: 1.-n/a 2. Server Version Disclosure Prevention • Task Type: Server configuration • Requirement: Remove/mask server version information from HTTP responses • Scope: • HTTP response headers (Server, X-Powered-By, framework headers) • Error pages and default framework responses • API endpoints • Validation: Confirm remediation using security scanning tools 3. Vulnerable Framework/Component Upgrade • Task Type: Dependency management and testing • Requirement: Identify and upgrade vulnerable frameworks/libraries to secure versions • Process: • Audit current dependency versions • Plan upgrade path ensuring backward compatibility • Implement upgrades with thorough regression testing • Document all changes and migration steps 4. SSL/TLS Security Hardening • Task Type: Infrastructure configuration • Requirement: Strengthen TLS configuration and eliminate weak ciphers • Scope: • Disable TLS 1.0/1.1 and weak cipher suites • Implement strong, current best-practice cipher configurations • Configure secure SSL/TLS settings on load balancers/web servers • Validation: SSL Labs assessment showing improved security grade 5. Admin Portal Access Control (OPTIONL) • Task Type: Network security implementation • Requirement: Secure admin portal access behind VPN or equivalent protection • Options: • VPN implementation (OpenVPN, WireGuard, or cloud-native solutions) • IP allowlisting with proper access controls • Zero-trust network access implementation • Deliverable: Secure access solution with documented procedures 6. Open Ports Security Audit • Task Type: Network security assessment and hardening • Requirement: Review and secure network port exposure • Process: • Comprehensive port scan and service audit • Close unnecessary open ports • Implement proper firewall rules and security group configurations • Document justified open ports with security rationale Required Qualifications Essential Experience: • in web application security and DevOps/infrastructure security • Proven track record with penetration testing remediation projects • Strong understanding of OWASP security principles • Experience with secure session management and authentication systems • SSL/TLS configuration and certificate management expertise • Network security implementation (firewalls, VPNs, access controls) • Healthcare sector experience strongly preferred Soft Skills: • Ability to work independently with minimal supervision • Clear communication for technical documentation and progress updates • Understanding of healthcare compliance requirements (HIPAA awareness beneficial) Deliverables Technical Implementation: • All security fixes implemented and tested in staging environment • Code changes submitted via pull requests with comprehensive documentation • Infrastructure configuration changes documented and version-controlled Documentation Package: • Detailed remediation report for each vulnerability • Technical documentation of all changes implemented • Updated operational procedures for secure admin access • Security testing evidence and validation reports Knowledge Transfer: • Brief handover session with our development team • Best practices documentation for maintaining security standards • Recommendations for ongoing security monitoring Timeline and Budget • Start Date: Immediate • Engagement Type: Fixed-price contract What We Provide · Complete penetration testing report with detailed findings · Access to staging environment and source code repository · Direct communication with our CTO and DevOps team · Necessary infrastructure access through secure channels · Clear requirements and prompt feedback on deliverables
Project ID: 40223959
21 proposals
Remote project
Active 1 mo ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
21 freelancers are bidding on average ₹12,846 INR for this job

Hi there, I’ve reviewed your security testing needs and would be glad to assist. With 10+ years of experience in VAPT, vulnerability assessment, and web/app security testing, I help identify and fix critical security flaws before they become threats. You’ll get a detailed report, practical remediation steps, and complete confidentiality — following OWASP and industry best practices. Let’s connect to secure your application the right way! Best, Bhargav Security Specialist | VAPT & AppSec | 10+ Years Experience
₹7,000 INR in 7 days
6.5
6.5

Hi, I have 10 years of experience and knowledge as system administrator setup and management of different Linux Web Hosting Servers, AWS servers,Cloud Servers, GPU Servers, Server Monitoring, Server Security, Server Optimisation, Mailing Servers, Email Marketing, SSL, DNS, Apache, Nginx, etc with Cpanel, Plesk, Virtualmin or other panels. Services such as cPanel/WHM, Plesk, Virtualmin LAMP Stack, Tomcat, MySQL/MariaDB, Zimbra, Postfix mail server, Mailenable, smarter mail, MS SQL,AWS , etc. Please discuss to start. Thank you
₹8,800 INR in 1 day
6.0
6.0

Hi there, I understand the critical nature of securing healthcare technology platforms and am confident in addressing the six specific vulnerabilities identified in your recent penetration test. With over 7 years of experience in web application and infrastructure security, especially within regulated environments, I will ensure robust remediation aligning with OWASP principles and compliance needs. - Remove/mask server version details from all HTTP responses and validate using security scanners - Audit and upgrade vulnerable frameworks/components with regression testing - Harden SSL/TLS configurations, eliminating weak ciphers and verifying through SSL Labs - Implement secure access controls for admin portals, including VPN or zero-trust solutions if opted - Conduct thorough network port audit, close unnecessary ports, and enforce firewall policies - Deliver comprehensive documentation, reports, and knowledge transfer sessions **Skills:** ✅ Web application & infrastructure security remediation ✅ OWASP vulnerability management & SSL/TLS hardening ✅ VPN, firewall, and network security implementations ✅ Penetration testing follow-up and secure DevOps practices ✅ Documentation & technical knowledge transfer with team enablement **Certificates:** ✅ Microsoft® Certified: MCSA | MCSE | MCT ✅ cPanel® & WHM Certified CWSA-2 I’m ready to start immediately and deliver secure, compliant results within your timeline. Which staging environment and testing tools do you currently use t
₹7,600 INR in 14 days
5.2
5.2

Hi, I can remediate the vulnerabilities from your penetration test and deliver a documented security hardening package. Planned work • Remove server/version disclosure from headers, APIs and error pages • Audit and upgrade vulnerable frameworks and dependencies • Harden SSL/TLS (disable weak protocols & ciphers, modern configs) • Improve SSL Labs score and validate fixes • Perform port audit and implement firewall/security group hardening • Secure admin access via VPN/IP allowlisting (if required) Deliverables • Fixes implemented and tested in staging • PRs and infrastructure changes fully documented • Remediation report + validation evidence • Handover session and best-practice notes I work regularly on DevOps and infrastructure security, including TLS hardening and penetration test remediation. Timeline: 5 days Bid: ₹9,500 Happy to start immediately. Regards, Yeswanth
₹9,500 INR in 5 days
1.7
1.7

Hello, I appreciate the opportunity to work with your healthcare technology company on enhancing the security of your web application. It seems you're looking for a specialist to address specific vulnerabilities highlighted in your recent penetration testing assessment. My approach would involve thoroughly analyzing each finding and prioritizing the remediation tasks—from improving server configurations to securing your admin portal access. With my background in web application security and experience in the healthcare sector, I understand the importance of both compliance and robust security measures. I have a proven track record in successfully implementing security fixes while ensuring minimal disruption to ongoing operations. I’m ready to collaborate closely with your CTO and DevOps team to deliver comprehensive documentation and training to help maintain security standards. Best regards, Mustafa Imtiaz
₹7,000 INR in 7 days
0.0
0.0

With over 4 years of dedicated experience in the cybersecurity realm, particularly in web and network security, I'm confident that my skills align perfectly with your requirements. My expertise spans across a range of essential areas including vulnerability assessments, threat hunting, as well as robust authentication systems - all of which are key to resolving the security challenges you face. Having meticulously reviewed and resolved countless security findings throughout my career, I fully understand the importance of comprehensive diligence and proactive identification and eradication of vulnerabilities. By implementing resilient SSL/TLS configurations and eliminating weak ciphers, safeguarding your sensitive data will be prioritized. Furthermore, my detailed-centric nature would lend itself well to documenting all changes made to your framework and ensuring thorough regression testing is executed. Additionally, my knowledge extends beyond solely technical aspects; appreciating the nuances of compliance, such as HIPAA, is an area I've engaged with extensively during my tenure in securing cloud infrastructure. Embedding this understanding within a comprehensive remediation report for each vulnerability, providing relevant documentation on code-changes implemented as well as updated operational procedures for secure admin access would be my guarantee. Let's collaboratively leverage my skills to fortify your web-application infrastructure!
₹6,666 INR in 7 days
0.0
0.0

Hi! With 1.8 years as a VAPT tester, I’ve securely tested 45+ web apps, spotting vulnerabilities like a pro. CEH certified and currently at Qseap Info Tech Pvt Ltd. I’ll deliver a thorough pentest report with clear fixes. Let’s chat to kick this off!
₹10,000 INR in 7 days
0.0
0.0

Hi there! I am a web security specialist with extensive experience in penetration testing remediation and DevOps infrastructure. I understand the high stakes of healthcare technology and am ready to take full ownership of these six security findings to ensure your oral health monitoring platform meets the highest standards. My Approach to Your Scope: Server & TLS Hardening: I will mask server disclosures and disable legacy protocols (TLS 1.0/1.1) to achieve an A+ SSL Labs rating. Safe Dependency Upgrades: I will audit your vulnerable frameworks and implement a staged upgrade path with thorough regression testing to ensure backward compatibility. Network Security: I’ll conduct a fresh Nmap audit to close unnecessary ports and can implement a WireGuard VPN or Zero-Trust solution for your Admin Portal. Documentation: Every fix will be delivered via documented Pull Requests with a final remediation report suitable for HIPAA/regulatory auditing. Why Me: Healthcare Experience: I prioritize data integrity and system availability. Clear Communication: I provide concise technical documentation for your CTO and DevOps team. Immediate Availability: I can start today and finish within 3–4 business days. I’m ready to review your pen-test report and secure your infrastructure. Best regards, Fonki
₹7,000 INR in 4 days
0.0
0.0

Hi there, I can remediate the 6 specific security findings identified in your penetration test. Since this is a healthcare application, I will ensure the fixes meet strict compliance standards. My Remediation Plan: Server Disclosure: I will configure the web server (Nginx/Apache) to hide version headers (server_tokens off) and suppress X-Powered-By responses. SSL Hardening: I will disable weak TLS 1.0/1.1 protocols and enforce strong cipher suites to achieve an 'A+' rating on SSL Labs. Admin Access: I will implement strict IP allowlisting or set up a lightweight WireGuard VPN to secure the admin portal. Dependency Patching: I will upgrade the vulnerable libraries/frameworks to their latest secure versions ensuring no breaking changes. I am ready to implement these fixes and provide a post-remediation report. Best, Sheikh Alamin
₹7,000 INR in 7 days
0.0
0.0

Hi, Im a cybersecurity specialist. I have 6 years of background working as a senior application security engineer in multiple companies (such as mercadolibre, wildlife studios, onapsis and Lemon). My day to day is to identify vulnerabilities and fix them, so I'm able to solve this for you. If you would like to discuss more in depth about the findings, please send me a DM (my profile is https://www.freelancer.com/u/brianre ). Hope to receive your message soon!
₹17,500 INR in 10 days
0.0
0.0

I can help you everything. I work smoothly, quickly, and efficiently. I am very good at what I do. I'll get everything done within a few days time.
₹90,696 INR in 2 days
0.0
0.0

Hello, This engagement aligns well with my background in offensive security and remediation focused infrastructure hardening. I have 8+ years of experience in web application security, penetration testing, and secure configuration across cloud and on premise environments. I specialize in translating penetration testing findings into structured, production safe fixes. For server version disclosure, I will implement header hardening at the web server and framework level and validate via automated scanning. For vulnerable dependencies, I conduct controlled upgrade planning with compatibility review and regression testing to ensure stability. For TLS hardening, I configure modern protocol standards, disable weak ciphers, and validate using SSL Labs to achieve a strong security grade. I also have experience implementing VPN based admin access controls, IP allowlisting, and zero trust style segmentation where appropriate. Open port exposure will be reviewed through structured service auditing, firewall rule tightening, and documented justification of required services. All changes will be delivered via documented pull requests, version controlled infrastructure updates, and a detailed remediation report with validation evidence. I am comfortable working independently and coordinating directly with CTO and DevOps stakeholders, including healthcare compliance considerations. I am available to begin immediately. Pranav
₹7,000 INR in 7 days
0.0
0.0

Hi, I am interested in helping you remediate the security findings identified in your web penetration testing assessment. I have solid experience in web application security, infrastructure hardening, and penetration-testing remediation, and I can independently implement the required fixes in a structured and professional manner. My approach focuses on practical, secure, and well-documented remediation aligned with OWASP best practices. I will address server version disclosure, upgrade vulnerable frameworks and dependencies with proper testing, harden SSL/TLS configurations by removing weak protocols and ciphers, and perform an open-port review to reduce attack surface through proper firewall and access controls. I can also support securing admin portal access via VPN or controlled network access if needed. Deliverables include tested fixes in the staging environment, clean pull requests with clear documentation, tracked infrastructure changes, validation results from security tools, and a remediation report for each finding. I will also provide knowledge transfer and best-practice recommendations to support long-term security. I work independently, communicate clearly, and focus on reliable, measurable security improvements. I am available to start immediately and collaborate directly with your CTO and DevOps team. Best regards, Mohamed
₹6,500 INR in 7 days
0.0
0.0

Hi I’m a DevOps & Security engineer with strong experience remediating real penetration-test findings for production systems, including healthcare-sensitive environments. I can take full ownership of fixing your six reported vulnerabilities and delivering verified, audit-ready results. I’ll harden headers and error responses, upgrade vulnerable dependencies safely with regression testing, enforce modern TLS configs (A+ target), secure admin access via VPN/Zero-Trust or IP controls, and perform a full port exposure audit with documented justifications. Every fix will be validated using scanners and evidence reports, with clean PRs and clear technical documentation. I work independently, communicate clearly, and focus on measurable security improvements—not assumptions. I can start immediately and complete this efficiently within your timeline.
₹7,000 INR in 7 days
0.0
0.0

Alright, let me talk straight, no smoke, no mirrors, just results. You don’t need a “security guy.” You need a closer. The kind of contractor who walks into a pentest report, fixes every finding, locks the doors, and leaves auditors with nothing to complain about. That’s me. Hi, I’m the guy you call when your app is leaking server versions, waving weak TLS flags, and exposing ports like it’s happy hour. Server headers broadcasting versions? Gone. Vulnerable frameworks? Upgraded clean with zero breakage. TLS 1.0/1.1 and weak ciphers? Buried six feet deep. Admin portal hanging out in public? I’ll tuck it behind VPN/Zero-Trust like it’s in witness protection. Open ports? If they’re not needed, they’re closed. Period. I work ownership-style. You hand me the six findings, I hand you back a hardened system, documentation, validation scans, and a security grade that makes compliance folks smile. What you get: Full dependency audit + safe upgrades Hardened SSL/TLS configs (A/A+ target on SSL Labs) Clean headers, sanitized responses Firewall rules + port lockdown Optional VPN/secure admin access Proof via scans + reports + docs Proper PRs and version-controlled infra changes I speak OWASP, DevOps, and “don’t break production.” Healthcare environment? Even better — I understand compliance and why mistakes aren’t an option. Bottom line: You focus on oral health tech. I make sure hackers get dental work instead. Let’s lock this thing down and call it a day.
₹1,500 INR in 1 day
0.0
0.0

“Hi, I am an Application Security Tester. I help startups identify OWASP Top 10 vulnerabilities before production. Let me know if you need a VAPT assessment.” Having very good experience in health, banking, Finance domains
₹25,000 INR in 2 days
0.0
0.0

Your scope is clear and well-structured, and I appreciate the focus on measurable remediation rather than advisory reporting. I have hands-on experience addressing penetration testing findings in production web environments, including server hardening, dependency upgrades, TLS configuration, access control enforcement, and network exposure reduction. I am comfortable taking full ownership of implementing and validating each remediation item in staging before release. For your specific requirements, I will: • Remove server/version disclosure at HTTP, framework, and API levels • Audit and upgrade vulnerable dependencies with regression testing and documented migration steps • Harden TLS configurations (disable legacy protocols, enforce strong cipher suites, validate via SSL Labs) • Secure admin portal access via VPN, IP allowlisting, or zero-trust approach as preferred • Conduct port/service audit and implement least-exposure firewall policies All changes will be delivered through documented pull requests, with validation evidence and a structured remediation report for compliance and audit traceability (HIPAA-aware handling included). I can begin immediately and work independently while coordinating closely with your CTO and DevOps team.
₹10,000 INR in 7 days
0.0
0.0

Delhi, India
Payment method verified
Member since Oct 14, 2021
₹400-750 INR / hour
₹12500-37500 INR
₹1500-12500 INR
₹1500-12500 INR
₹1500-12500 INR
$250-750 USD
₹12500-37500 INR
$2-8 USD / hour
$10-30 USD
$60 USD
$60 USD
$15-25 USD / hour
₹1500-12500 INR
$8-15 USD / hour
min ₹5000000 INR
₹1500-12500 INR
₹12500-37500 INR
$250-750 AUD
₹400-750 INR / hour
₹600-1500 INR
$250-750 CAD
$10-30 USD
$10-30 USD
$10-30 USD
$30-250 USD